See MSDNThe GetModuleInformation function retrieves information about the specified module in the MODULEINFO structure. BOOL GetModuleInformation( HANDLE hProcess, // handle to process HMODULE hModule, // handle to module LPMODULEINFO lpmodinfo, // information buffer DWORD cb // size of buffer );typedef struct _MODULEINFO { LPVOID lpBaseOfDll; DWORD SizeOfImage; LPVOID EntryPoint; } MODULEINFO, *LPMODULEINFO; Members
HANDLE hProcess, // handle to process
HMODULE hModule, // handle to module
LPMODULEINFO lpmodinfo, // information buffer
DWORD cb // size of buffer
);typedef struct _MODULEINFO {
LPVOID lpBaseOfDll;
DWORD SizeOfImage;
LPVOID EntryPoint;
} MODULEINFO, *LPMODULEINFO;
Members
HANDLE WINAPI CreateProcess();
for more information about the two functions ,see MSDN library.
to capture);
LPVOID pProcess =(type_cast)hProcess; //force to convert it's type