我正在尝试将 .net 库注入托管应用程序,但在使用 ollydbg 进行一些调试后它似乎不起作用,我发现它无限循环。如果我强行退出循环,那么一切正常。我已经创建了一个解决方法(参见下面的代码),但我怀疑这是应该的方式!
执行时循环开始:hr = pClrHost->Start();
static void Main(string[] args)
//Has to be 32Bit app, not sure why yet, x86 should work in x64 apps
Process np = Process.GetProcessesByName("notepad")[0];
string dllpath = @"c:\Loader.dll";
string corepath = string.Format("{0}\\{1}", Environment.GetFolderPath(Environment.SpecialFolder.System), "mscoree.dll");
if (!File.Exists(corepath))
//No .NET
//Open Process for write access
IntPtr PID = OpenProcess(PROCESS_ALL_ACCESS, false, np.Id);
//Allocate memory
IntPtr addr = (IntPtr)VirtualAllocEx(PID, IntPtr.Zero, (uint)dllpath.Length + 1, 0x1000, 4);
if (addr == IntPtr.Zero)
//return false;
//Write DLL path into process memory
int wrote = WriteProcessMemory(PID, addr, System.Text.Encoding.ASCII.GetBytes(dllpath), (uint)dllpath.Length +1, IntPtr.Zero);
IntPtr hRemoteThread = IntPtr.Zero;
uint temp;
//Start new thread @ LoadLibraryA with path to library as parameter
hRemoteThread = CreateRemoteThread(PID, IntPtr.Zero, 0, (IntPtr)GetProcAddress(GetModuleHandle("kernel32.dll"), "LoadLibraryA"), addr, 0, out temp);
if (hRemoteThread == IntPtr.Zero)
//return false;
//Force loop to exit, Will cause the messagebox to show up
wrote = WriteProcessMemory(PID, (IntPtr)0x6D8EC91A, new byte[1]{ 0xEB}, (uint)1, IntPtr.Zero);
//Clean up
VirtualFreeEx(PID, addr, (uint)dllpath.Length + 1, FreeType.Release);
//return true;
C++ .Net 加载程序代码
#pragma comment(lib,"MSCorEE.lib")
#include <mscoree.h>
#include <metahost.h>
ICLRRuntimeHost* pClrHost = NULL;
int WINAPI DllMain(HINSTANCE hInstance, DWORD dwReason, LPVOID lpReserved)
// Get the policy object, so we can determine which runtime to use.
ICLRMetaHostPolicy* pMetaHostPolicy = NULL;
HRESULT hr = CLRCreateInstance(CLSID_CLRMetaHostPolicy, IID_ICLRMetaHostPolicy, (LPVOID*)&pMetaHostPolicy);
if (FAILED(hr))
MessageBox(NULL, L"Could not create a ICLRMetaHostPolicy object!", L"Injection - Error", MB_OK);
return 1;
ICLRRuntimeInfo* pRuntimeInfo = NULL;
// Get the runtime info object. Allow the assembly to tell US what runtime to use.
DWORD pcchVersion = 0;
DWORD dwConfigFlags = 0;
hr = pMetaHostPolicy->GetRequestedRuntime(METAHOST_POLICY_HIGHCOMPAT,
L"C:\\Test.dll", NULL,
NULL, &pcchVersion,
NULL, NULL, &dwConfigFlags,
if (FAILED(hr))
MessageBox(NULL, L"Could not create an ICLRRuntimeInfo object.", L"Injection - Error", MB_OK);
return 1;
// Allow the runtime to load .NET 2.0 mixed-mode libraries. (This covers 2.0-3.5 SP1)
hr = pRuntimeInfo->BindAsLegacyV2Runtime();
if (FAILED(hr))
MessageBox(NULL, L"Could not bind as legacy v2 runtime.", L"Injection - Error", MB_OK);
return 1;
hr = pRuntimeInfo->GetInterface(CLSID_CLRRuntimeHost, IID_ICLRRuntimeHost, (LPVOID*)&pClrHost);
if (FAILED(hr))
MessageBox(NULL, L"Could not get an instance of ICLRRuntimeHost!", L"Injection - Error", MB_OK);
return 1;
hr = pClrHost->Start();
if (FAILED(hr))
MessageBox(NULL, L"Failed to start the CLR!", L"Injection - Error", MB_OK);
return 1;
DWORD dwRet = 0;
// Execute the Main func in the domain manager, this will block indefinitely.
// (Hence why we're in our own thread!)
hr = pClrHost->ExecuteInDefaultAppDomain(
L"C:\\Test.dll", // Executable path
L"Hello World!",
if (FAILED(hr))
MessageBox(NULL, L"Failed to execute in the default app domain!", L"Injection - Error", MB_OK);
return 1;
case DLL_THREAD_ATTACH: break;
case DLL_THREAD_DETACH: break;
//FreeLibraryAndExitThread(hInstance, 0);
return true;
.Net 测试代码
public class bc
public static int InjectedMain(string args)
catch (Exception ex)
return 0;