下钩子函数:
HHOOK WINAPI SetWindowsHookEx(
_In_ int idHook,
_In_ HOOKPROC lpfn,
_In_ HINSTANCE hMod,
_In_ DWORD dwThreadId
);
钩子的过程需要在DLL内部
- dwThreadId为0时 钩子为全局钩子
- hMod就当成dll的句柄(讲道理
- lpfn就是要执行的钩子过程了= =
- idHook是触发条件
下钩子函数:
HHOOK WINAPI SetWindowsHookEx(
_In_ int idHook,
_In_ HOOKPROC lpfn,
_In_ HINSTANCE hMod,
_In_ DWORD dwThreadId
);
钩子的过程需要在DLL内部