首页
社区
课程
招聘
[半原创]贴点内核态中创建用户态进程的代码
发表于: 2009-1-9 14:28 40090

[半原创]贴点内核态中创建用户态进程的代码

2009-1-9 14:28
40090
收藏
免费 7
支持
分享
最新回复 (52)
雪    币: 66
活跃值: (16)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
26
创建user process的同时是需要创建user thread的
2009-1-12 19:06
0
雪    币: 647
活跃值: (564)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
27
我去注册个 第八个男人
2009-1-12 19:48
0
雪    币: 189
活跃值: (4810)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
28
收藏!!!!!!!
2009-1-12 23:21
0
雪    币: 66
活跃值: (16)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
29
BYTE* EnvironmentStringsW={
"0x0 0x49 0x0 0x4e 0x0 0x44 0x0 0x4f 0x0 0x57"
"0x0 0x53 0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x57 0x0 0x49 0x0 0x4e 0x0 0x44 0x0 0x4f"
"0x0 0x57 0x0 0x53 0x0 0x5c 0x0 0x53 0x0 0x79"
"0x0 0x73 0x0 0x74 0x0 0x65 0x0 0x6d 0x0 0x33"
"0x0 0x32 0x0 0x5c 0x0 0x57 0x0 0x62 0x0 0x65"
"0x0 0x6d 0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72"
"0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69"
"0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x43"
"0x0 0x6f 0x0 0x6d 0x0 0x6d 0x0 0x6f 0x0 0x6e"
"0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c 0x0 0x65"
"0x0 0x73 0x0 0x5c 0x0 0x54 0x0 0x65 0x0 0x6c"
"0x0 0x65 0x0 0x63 0x0 0x61 0x0 0x20 0x0 0x53"
"0x0 0x68 0x0 0x61 0x0 0x72 0x0 0x65 0x0 0x64"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50"
"0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61"
"0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c"
"0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x4d 0x0 0x69"
"0x0 0x63 0x0 0x72 0x0 0x6f 0x0 0x73 0x0 0x6f"
"0x0 0x66 0x0 0x74 0x0 0x20 0x0 0x56 0x0 0x69"
"0x0 0x73 0x0 0x75 0x0 0x61 0x0 0x6c 0x0 0x20"
"0x0 0x53 0x0 0x74 0x0 0x75 0x0 0x64 0x0 0x69"
"0x0 0x6f 0x0 0x5c 0x0 0x43 0x0 0x6f 0x0 0x6d"
"0x0 0x6d 0x0 0x6f 0x0 0x6e 0x0 0x5c 0x0 0x54"
"0x0 0x6f 0x0 0x6f 0x0 0x6c 0x0 0x73 0x0 0x5c"
"0x0 0x57 0x0 0x69 0x0 0x6e 0x0 0x4e 0x0 0x54"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50"
"0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61"
"0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c"
"0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x4d 0x0 0x69"
"0x0 0x63 0x0 0x72 0x0 0x6f 0x0 0x73 0x0 0x6f"
"0x0 0x66 0x0 0x74 0x0 0x20 0x0 0x56 0x0 0x69"
"0x0 0x73 0x0 0x75 0x0 0x61 0x0 0x6c 0x0 0x20"
"0x0 0x53 0x0 0x74 0x0 0x75 0x0 0x64 0x0 0x69"
"0x0 0x6f 0x0 0x5c 0x0 0x43 0x0 0x6f 0x0 0x6d"
"0x0 0x6d 0x0 0x6f 0x0 0x6e 0x0 0x5c 0x0 0x4d"
"0x0 0x53 0x0 0x44 0x0 0x65 0x0 0x76 0x0 0x39"
"0x0 0x38 0x0 0x5c 0x0 0x42 0x0 0x69 0x0 0x6e"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50"
"0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61"
"0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c"
"0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x4d 0x0 0x69"
"0x0 0x63 0x0 0x72 0x0 0x6f 0x0 0x73 0x0 0x6f"
"0x0 0x66 0x0 0x74 0x0 0x20 0x0 0x56 0x0 0x69"
"0x0 0x73 0x0 0x75 0x0 0x61 0x0 0x6c 0x0 0x20"
"0x0 0x53 0x0 0x74 0x0 0x75 0x0 0x64 0x0 0x69"
"0x0 0x6f 0x0 0x5c 0x0 0x43 0x0 0x6f 0x0 0x6d"
"0x0 0x6d 0x0 0x6f 0x0 0x6e 0x0 0x5c 0x0 0x54"
"0x0 0x6f 0x0 0x6f 0x0 0x6c 0x0 0x73 0x0 0x3b"
"0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50 0x0 0x72"
"0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61 0x0 0x6d"
"0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c 0x0 0x65"
"0x0 0x73 0x0 0x5c 0x0 0x4d 0x0 0x69 0x0 0x63"
"0x0 0x72 0x0 0x6f 0x0 0x73 0x0 0x6f 0x0 0x66"
"0x0 0x74 0x0 0x20 0x0 0x56 0x0 0x69 0x0 0x73"
"0x0 0x75 0x0 0x61 0x0 0x6c 0x0 0x20 0x0 0x53"
"0x0 0x74 0x0 0x75 0x0 0x64 0x0 0x69 0x0 0x6f"
"0x0 0x5c 0x0 0x56 0x0 0x43 0x0 0x39 0x0 0x38"
"0x0 0x5c 0x0 0x62 0x0 0x69 0x0 0x6e 0x0 0x3b"
"0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50 0x0 0x72"
"0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61 0x0 0x6d"
"0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c 0x0 0x65"
"0x0 0x73 0x0 0x5c 0x0 0x53 0x0 0x74 0x0 0x6f"
"0x0 0x72 0x0 0x6d 0x0 0x49 0x0 0x49 0x0 0x5c"
"0x0 0x43 0x0 0x6f 0x0 0x64 0x0 0x65 0x0 0x63"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50"
"0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61"
"0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c"
"0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x53 0x0 0x74"
"0x0 0x6f 0x0 0x72 0x0 0x6d 0x0 0x49 0x0 0x49"
"0x0 0x0 0x0 0x50 0x0 0x41 0x0 0x54 0x0 0x48"
"0x0 0x45 0x0 0x58 0x0 0x54 0x0 0x3d 0x0 0x2e"
"0x0 0x43 0x0 0x4f 0x0 0x4d 0x0 0x3b 0x0 0x2e"
"0x0 0x45 0x0 0x58 0x0 0x45 0x0 0x3b 0x0 0x2e"
"0x0 0x42 0x0 0x41 0x0 0x54 0x0 0x3b 0x0 0x2e"
"0x0 0x43 0x0 0x4d 0x0 0x44 0x0 0x3b 0x0 0x2e"
"0x0 0x56 0x0 0x42 0x0 0x53 0x0 0x3b 0x0 0x2e"
"0x0 0x56 0x0 0x42 0x0 0x45 0x0 0x3b 0x0 0x2e"
"0x0 0x4a 0x0 0x53 0x0 0x3b 0x0 0x2e 0x0 0x4a"
"0x0 0x53 0x0 0x45 0x0 0x3b 0x0 0x2e 0x0 0x57"
"0x0 0x53 0x0 0x46 0x0 0x3b 0x0 0x2e 0x0 0x57"
"0x0 0x53 0x0 0x48 0x0 0x3b 0x0 0x2e 0x0 0x42"
"0x0 0x4f 0x0 0x58 0x0 0x0 0x0 0x50 0x0 0x52"
"0x0 0x4f 0x0 0x43 0x0 0x45 0x0 0x53 0x0 0x53"
"0x0 0x4f 0x0 0x52 0x0 0x5f 0x0 0x41 0x0 0x52"
"0x0 0x43 0x0 0x48 0x0 0x49 0x0 0x54 0x0 0x45"
"0x0 0x43 0x0 0x54 0x0 0x55 0x0 0x52 0x0 0x45"
"0x0 0x3d 0x0 0x78 0x0 0x38 0x0 0x36 0x0 0x0"
"0x0 0x50 0x0 0x52 0x0 0x4f 0x0 0x43 0x0 0x45"
"0x0 0x53 0x0 0x53 0x0 0x4f 0x0 0x52 0x0 0x5f"
"0x0 0x49 0x0 0x44 0x0 0x45 0x0 0x4e 0x0 0x54"
"0x0 0x49 0x0 0x46 0x0 0x49 0x0 0x45 0x0 0x52"
"0x0 0x3d 0x0 0x78 0x0 0x38 0x0 0x36 0x0 0x20"
"0x0 0x46 0x0 0x61 0x0 0x6d 0x0 0x69 0x0 0x6c"
"0x0 0x79 0x0 0x20 0x0 0x31 0x0 0x35 0x0 0x20"
"0x0 0x4d 0x0 0x6f 0x0 0x64 0x0 0x65 0x0 0x6c"
"0x0 0x20 0x0 0x37 0x0 0x39 0x0 0x20 0x0 0x53"
"0x0 0x74 0x0 0x65 0x0 0x70 0x0 0x70 0x0 0x69"
"0x0 0x6e 0x0 0x67 0x0 0x20 0x0 0x32 0x0 0x2c"
"0x0 0x20 0x0 0x41 0x0 0x75 0x0 0x74 0x0 0x68"
"0x0 0x65 0x0 0x6e 0x0 0x74 0x0 0x69 0x0 0x63"
"0x0 0x41 0x0 0x4d 0x0 0x44 0x0 0x0 0x0 0x50"
"0x0 0x52 0x0 0x4f 0x0 0x43 0x0 0x45 0x0 0x53"
"0x0 0x53 0x0 0x4f 0x0 0x52 0x0 0x5f 0x0 0x4c"
"0x0 0x45 0x0 0x56 0x0 0x45 0x0 0x4c 0x0 0x3d"
"0x0 0x31 0x0 0x35 0x0 0x0 0x0 0x50 0x0 0x52"
"0x0 0x4f 0x0 0x43 0x0 0x45 0x0 0x53 0x0 0x53"
"0x0 0x4f 0x0 0x52 0x0 0x5f 0x0 0x52 0x0 0x45"
"0x0 0x56 0x0 0x49 0x0 0x53 0x0 0x49 0x0 0x4f"
"0x0 0x4e 0x0 0x3d 0x0 0x34 0x0 0x66 0x0 0x30"
"0x0 0x32 0x0 0x0 0x0 0x50 0x0 0x72 0x0 0x6f"
"0x0 0x67 0x0 0x72 0x0 0x61 0x0 0x6d 0x0 0x46"
"0x0 0x69 0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x3d"
"0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50 0x0 0x72"
"0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61 0x0 0x6d"
"0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c 0x0 0x65"
"0x0 0x73 0x0 0x0 0x0 0x53 0x0 0x45 0x0 0x53"
"0x0 0x53 0x0 0x49 0x0 0x4f 0x0 0x4e 0x0 0x4e"
"0x0 0x41 0x0 0x4d 0x0 0x45 0x0 0x3d 0x0 0x43"
"0x0 0x6f 0x0 0x6e 0x0 0x73 0x0 0x6f 0x0 0x6c"
"0x0 0x65 0x0 0x0 0x0 0x53 0x0 0x79 0x0 0x73"
"0x0 0x74 0x0 0x65 0x0 0x6d 0x0 0x44 0x0 0x72"
"0x0 0x69 0x0 0x76 0x0 0x65 0x0 0x3d 0x0 0x43"
"0x0 0x3a 0x0 0x0 0x0 0x53 0x0 0x79 0x0 0x73"
"0x0 0x74 0x0 0x65 0x0 0x6d 0x0 0x52 0x0 0x6f"
"0x0 0x6f 0x0 0x74 0x0 0x3d 0x0 0x43 0x0 0x3a"
"0x0 0x5c 0x0 0x57 0x0 0x49 0x0 0x4e 0x0 0x44"
"0x0 0x4f 0x0 0x57 0x0 0x53 0x0 0x0 0x0 0x54"
"0x0 0x45 0x0 0x4d 0x0 0x50 0x0 0x3d 0x0 0x43"
"0x0 0x3a 0x0 0x5c 0x0 0x44 0x0 0x4f 0x0 0x43"
"0x0 0x55 0x0 0x4d 0x0 0x45 0x0 0x7e 0x0 0x31"
"0x0 0x5c 0x0 0x41 0x0 0x44 0x0 0x4d 0x0 0x49"
"0x0 0x4e 0x0 0x49 0x0 0x7e 0x0 0x31 0x0 0x5c"
"0x0 0x4c 0x0 0x4f 0x0 0x43 0x0 0x41 0x0 0x4c"
"0x0 0x53 0x0 0x7e 0x0 0x31 0x0 0x5c 0x0 0x54"
"0x0 0x65 0x0 0x6d 0x0 0x70 0x0 0x0 0x0 0x54"
"0x0 0x4d 0x0 0x50 0x0 0x3d 0x0 0x43 0x0 0x3a"
"0x0 0x5c 0x0 0x44 0x0 0x4f 0x0 0x43 0x0 0x55"
"0x0 0x4d 0x0 0x45 0x0 0x7e 0x0 0x31 0x0 0x5c"
"0x0 0x41 0x0 0x44 0x0 0x4d 0x0 0x49 0x0 0x4e"
"0x0 0x49 0x0 0x7e 0x0 0x31 0x0 0x5c 0x0 0x4c"
"0x0 0x4f 0x0 0x43 0x0 0x41 0x0 0x4c 0x0 0x53"
"0x0 0x7e 0x0 0x31 0x0 0x5c 0x0 0x54 0x0 0x65"
"0x0 0x6d 0x0 0x70 0x0 0x0 0x0 0x55 0x0 0x53"
"0x0 0x45 0x0 0x52 0x0 0x44 0x0 0x4f 0x0 0x4d"
"0x0 0x41 0x0 0x49 0x0 0x4e 0x0 0x3d 0x0 0x43"
"0x0 0x46 0x0 0x35 0x0 0x37 0x0 0x35 0x0 0x34"
"0x0 0x39 0x0 0x36 0x0 0x46 0x0 0x33 0x0 0x37"
"0x0 0x38 0x0 0x34 0x0 0x36 0x0 0x33 0x0 0x0"
"0x0 0x55 0x0 0x53 0x0 0x45 0x0 0x52 0x0 0x4e"
"0x0 0x41 0x0 0x4d 0x0 0x45 0x0 0x3d 0x0 0x41"
"0x0 0x64 0x0 0x6d 0x0 0x69 0x0 0x6e 0x0 0x69"
"0x0 0x73 0x0 0x74 0x0 0x72 0x0 0x61 0x0 0x74"
"0x0 0x6f 0x0 0x72 0x0 0x0 0x0 0x55 0x0 0x53"
"0x0 0x45 0x0 0x52 0x0 0x50 0x0 0x52 0x0 0x4f"
"0x0 0x46 0x0 0x49 0x0 0x4c 0x0 0x45 0x0 0x3d"
"0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x44 0x0 0x6f"
"0x0 0x63 0x0 0x75 0x0 0x6d 0x0 0x65 0x0 0x6e"
"0x0 0x74 0x0 0x73 0x0 0x20 0x0 0x61 0x0 0x6e"
"0x0 0x64 0x0 0x20 0x0 0x53 0x0 0x65 0x0 0x74"
"0x0 0x74 0x0 0x69 0x0 0x6e 0x0 0x67 0x0 0x73"
"0x0 0x5c 0x0 0x41 0x0 0x64 0x0 0x6d 0x0 0x69"
"0x0 0x6e 0x0 0x69 0x0 0x73 0x0 0x74 0x0 0x72"
"0x0 0x61 0x0 0x74 0x0 0x6f 0x0 0x72 0x0 0x0"
"0x0 0x56 0x0 0x53 0x0 0x38 0x0 0x30 0x0 0x43"
"0x0 0x4f 0x0 0x4d 0x0 0x4e 0x0 0x54 0x0 0x4f"
"0x0 0x4f 0x0 0x4c 0x0 0x53 0x0 0x3d 0x0 0x43"
"0x0 0x3a 0x0 0x5c 0x0 0x50 0x0 0x72 0x0 0x6f"
"0x0 0x67 0x0 0x72 0x0 0x61 0x0 0x6d 0x0 0x20"
"0x0 0x46 0x0 0x69 0x0 0x6c 0x0 0x65 0x0 0x73"
"0x0 0x5c 0x0 0x4d 0x0 0x69 0x0 0x63 0x0 0x72"
"0x0 0x6f 0x0 0x73 0x0 0x6f 0x0 0x66 0x0 0x74"
"0x0 0x20 0x0 0x56 0x0 0x69 0x0 0x73 0x0 0x75"
"0x0 0x61 0x0 0x6c 0x0 0x20 0x0 0x53 0x0 0x74"
"0x0 0x75 0x0 0x64 0x0 0x69 0x0 0x6f 0x0 0x20"
"0x0 0x38 0x0 0x5c 0x0 0x43 0x0 0x6f 0x0 0x6d"
"0x0 0x6d 0x0 0x6f 0x0 0x6e 0x0 0x37 0x0 0x5c"
"0x0 0x54 0x0 0x6f 0x0 0x6f 0x0 0x6c 0x0 0x73"
"0x0 0x5c 0x0 0x0 0x0 0x77 0x0 0x69 0x0 0x6e"
"0x0 0x64 0x0 0x69 0x0 0x72 0x0 0x3d 0x0 0x43"
"0x0 0x3a 0x0 0x5c 0x0 0x57 0x0 0x49 0x0 0x4e"
"0x0 0x44 0x0 0x4f 0x0 0x57 0x0 0x53 0x0 0x0"
"0x0 0x57 0x0 0x4e 0x0 0x45 0x0 0x54 0x0 0x42"
"0x0 0x41 0x0 0x53 0x0 0x45 0x0 0x3d 0x0 0x46"
"0x0 0x3a 0x0 0x5c 0x0 0x57 0x0 0x49 0x0 0x4e"
"0x0 0x44 0x0 0x44 0x0 0x4b 0x0 0x5c 0x0 0x33"
"0x0 0x37 0x0 0x39 0x0 0x30 0x0 0x2e 0x0 0x31"
"0x0 0x38 0x0 0x33 0x0 0x30 0x0 0x0 0x0 0x5f"
"0x0 0x41 0x0 0x43 0x0 0x50 0x0 0x5f 0x0 0x4c"
"0x0 0x49 0x0 0x42 0x0 0x3d 0x0 0x43 0x0 0x3a"
"0x0 0x5c 0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67"
"0x0 0x72 0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46"
"0x0 0x69 0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c"
"0x0 0x4d 0x0 0x69 0x0 0x63 0x0 0x72 0x0 0x6f"
"0x0 0x73 0x0 0x6f 0x0 0x66 0x0 0x74 0x0 0x20"
"0x0 0x56 0x0 0x69 0x0 0x73 0x0 0x75 0x0 0x61"
"0x0 0x6c 0x0 0x20 0x0 0x53 0x0 0x74 0x0 0x75"
"0x0 0x64 0x0 0x69 0x0 0x6f 0x0 0x5c 0x0 0x56"
"0x0 0x43 0x0 0x39 0x0 0x38 0x0 0x5c 0x0 0x4c"
"0x0 0x49 0x0 0x42 0x0 0x3b 0x0 0x43 0x0 0x3a"
"0x0 0x5c 0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67"
"0x0 0x72 0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46"
"0x0 0x69 0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c"
"0x0 0x4d 0x0 0x69 0x0 0x63 0x0 0x72 0x0 0x6f"
"0x0 0x73 0x0 0x6f 0x0 0x66 0x0 0x74 0x0 0x20"
"0x0 0x56 0x0 0x69 0x0 0x73 0x0 0x75 0x0 0x61"
"0x0 0x6c 0x0 0x20 0x0 0x53 0x0 0x74 0x0 0x75"
"0x0 0x64 0x0 0x69 0x0 0x6f 0x0 0x5c 0x0 0x56"
"0x0 0x43 0x0 0x39 0x0 0x38 0x0 0x5c 0x0 0x4d"
"0x0 0x46 0x0 0x43 0x0 0x5c 0x0 0x4c 0x0 0x49"
"0x0 0x42 0x0 0x0 0x0 0x5f 0x0 0x41 0x0 0x43"
"0x0 0x50 0x0 0x5f 0x0 0x50 0x0 0x41 0x0 0x54"
"0x0 0x48 0x0 0x3d 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72"
"0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69"
"0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x4d"
"0x0 0x69 0x0 0x63 0x0 0x72 0x0 0x6f 0x0 0x73"
"0x0 0x6f 0x0 0x66 0x0 0x74 0x0 0x20 0x0 0x56"
"0x0 0x69 0x0 0x73 0x0 0x75 0x0 0x61 0x0 0x6c"
"0x0 0x20 0x0 0x53 0x0 0x74 0x0 0x75 0x0 0x64"
"0x0 0x69 0x0 0x6f 0x0 0x5c 0x0 0x43 0x0 0x6f"
"0x0 0x6d 0x0 0x6d 0x0 0x6f 0x0 0x6e 0x0 0x5c"
"0x0 0x4d 0x0 0x53 0x0 0x44 0x0 0x65 0x0 0x76"
"0x0 0x39 0x0 0x38 0x0 0x5c 0x0 0x42 0x0 0x69"
"0x0 0x6e 0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72"
"0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69"
"0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x4d"
"0x0 0x69 0x0 0x63 0x0 0x72 0x0 0x6f 0x0 0x73"
"0x0 0x6f 0x0 0x66 0x0 0x74 0x0 0x20 0x0 0x56"
"0x0 0x69 0x0 0x73 0x0 0x75 0x0 0x61 0x0 0x6c"
"0x0 0x20 0x0 0x53 0x0 0x74 0x0 0x75 0x0 0x64"
"0x0 0x69 0x0 0x6f 0x0 0x5c 0x0 0x56 0x0 0x43"
"0x0 0x39 0x0 0x38 0x0 0x5c 0x0 0x42 0x0 0x49"
"0x0 0x4e 0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72"
"0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69"
"0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x4d"
"0x0 0x69 0x0 0x63 0x0 0x72 0x0 0x6f 0x0 0x73"
"0x0 0x6f 0x0 0x66 0x0 0x74 0x0 0x20 0x0 0x56"
"0x0 0x69 0x0 0x73 0x0 0x75 0x0 0x61 0x0 0x6c"
"0x0 0x20 0x0 0x53 0x0 0x74 0x0 0x75 0x0 0x64"
"0x0 0x69 0x0 0x6f 0x0 0x5c 0x0 0x43 0x0 0x6f"
"0x0 0x6d 0x0 0x6d 0x0 0x6f 0x0 0x6e 0x0 0x5c"
"0x0 0x54 0x0 0x4f 0x0 0x4f 0x0 0x4c 0x0 0x53"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50"
"0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61"
"0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c"
"0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x4d 0x0 0x69"
"0x0 0x63 0x0 0x72 0x0 0x6f 0x0 0x73 0x0 0x6f"
"0x0 0x66 0x0 0x74 0x0 0x20 0x0 0x56 0x0 0x69"
"0x0 0x73 0x0 0x75 0x0 0x61 0x0 0x6c 0x0 0x20"
"0x0 0x53 0x0 0x74 0x0 0x75 0x0 0x64 0x0 0x69"
"0x0 0x6f 0x0 0x5c 0x0 0x43 0x0 0x6f 0x0 0x6d"
"0x0 0x6d 0x0 0x6f 0x0 0x6e 0x0 0x5c 0x0 0x54"
"0x0 0x4f 0x0 0x4f 0x0 0x4c 0x0 0x53 0x0 0x5c"
"0x0 0x57 0x0 0x49 0x0 0x4e 0x0 0x4e 0x0 0x54"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x57"
"0x0 0x49 0x0 0x4e 0x0 0x44 0x0 0x4f 0x0 0x57"
"0x0 0x53 0x0 0x5c 0x0 0x73 0x0 0x79 0x0 0x73"
"0x0 0x74 0x0 0x65 0x0 0x6d 0x0 0x33 0x0 0x32"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x57"
"0x0 0x49 0x0 0x4e 0x0 0x44 0x0 0x4f 0x0 0x57"
"0x0 0x53 0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x57 0x0 0x49 0x0 0x4e 0x0 0x44 0x0 0x4f"
"0x0 0x57 0x0 0x53 0x0 0x5c 0x0 0x53 0x0 0x79"
"0x0 0x73 0x0 0x74 0x0 0x65 0x0 0x6d 0x0 0x33"
"0x0 0x32 0x0 0x5c 0x0 0x57 0x0 0x62 0x0 0x65"
"0x0 0x6d 0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72"
"0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69"
"0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x43"
"0x0 0x6f 0x0 0x6d 0x0 0x6d 0x0 0x6f 0x0 0x6e"
"0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c 0x0 0x65"
"0x0 0x73 0x0 0x5c 0x0 0x54 0x0 0x65 0x0 0x6c"
"0x0 0x65 0x0 0x63 0x0 0x61 0x0 0x20 0x0 0x53"
"0x0 0x68 0x0 0x61 0x0 0x72 0x0 0x65 0x0 0x64"
"0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c 0x0 0x50"
"0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72 0x0 0x61"
"0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69 0x0 0x6c"
"0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x53 0x0 0x74"
"0x0 0x6f 0x0 0x72 0x0 0x6d 0x0 0x49 0x0 0x49"
"0x0 0x5c 0x0 0x43 0x0 0x6f 0x0 0x64 0x0 0x65"
"0x0 0x63 0x0 0x3b 0x0 0x43 0x0 0x3a 0x0 0x5c"
"0x0 0x50 0x0 0x72 0x0 0x6f 0x0 0x67 0x0 0x72"
"0x0 0x61 0x0 0x6d 0x0 0x20 0x0 0x46 0x0 0x69"
"0x0 0x6c 0x0 0x65 0x0 0x73 0x0 0x5c 0x0 0x53"
"0x0 0x74 0x0 0x6f 0x0 0x72 0x0 0x6d 0x0 0x49"
"0x0 0x49 0x0 0x0 0x0 0x5f 0x0 0x4d 0x0 0x53"
"0x0 0x44 0x0 0x45 0x0 0x56 0x0 0x5f 0x0 0x42"
"0x0 0x4c 0x0 0x44 0x0 0x5f 0x0 0x45 0x0 0x4e"
"0x0 0x56 0x0 0x5f 0x0 0x3d 0x0 0x31 0x0 0x0"
"0x0 0x5f 0x0 0x5f 0x0 0x43 0x0 0x4f 0x0 0x4d"
"0x0 0x50 0x0 0x41 0x0 0x54 0x0 0x5f 0x0 0x4c"
"0x0 0x41 0x0 0x59 0x0 0x45 0x0 0x52 0x0 0x3d"
"0x0 0x45 0x0 0x6e 0x0 0x61 0x0 0x62 0x0 0x6c"
"0x0 0x65 0x0 0x4e 0x0 0x58 0x0 0x53 0x0 0x68"
"0x0 0x6f 0x0 0x77 0x0 0x55 0x0 0x49 0x0 0x20"
"0x0 0x0 0x0"};

.....
2009-1-12 23:51
0
雪    币: 66
活跃值: (16)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
30
从这儿读吧

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment
2009-1-12 23:54
0
雪    币: 364
活跃值: (152)
能力值: ( LV12,RANK:450 )
在线值:
发帖
回帖
粉丝
31
都创建了进程了,线程不是早就创建完毕了
2009-1-13 19:18
0
雪    币: 217
活跃值: (35)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
32
纯粹从“意义”角度说的。
创建User Thread,就可以在在这个Thread里面CreateProcess,就不用做InfoCsrss这类的Dirty Work。。。
2009-1-14 23:20
0
雪    币: 451
活跃值: (78)
能力值: ( LV12,RANK:470 )
在线值:
发帖
回帖
粉丝
33
其实一样要InfoCsrss的
少的只是前面那些进程的环境初始化(比如PEB之类)
2009-2-2 12:51
0
雪    币: 252
活跃值: (13)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
34
先谢谢啦。哪位大哥解释一下。我怎么弄不明白啊?这些函数为什么要自己获得地址啊
ZwWriteVirtualMemory   =    (pFnZwWriteVirtualMemory)  GetSSDTApi("ZwWriteVirtualMemory");//从ssdt表里面得到这些函数的地址
        ZwResumeThread         =        (pFnZwResumeThread)        GetSSDTApi("ZwResumeThread");
        ZwCreateThread         =        (pFnZwCreateThread)        GetSSDTApi("ZwCreateThread");
        ZwProtectVirtualMemory =        (pFnZwProtectVirtualMemory)GetSSDTApi("ZwProtectVirtualMemory");
        ZwCreateProcess        =        (pFnZwCreateProcess)       GetSSDTApi("ZwCreateProcess");
    ExEnumHandleTable     =     (pFnExEnumHandleTable)     GetFunctionAddr(L"ExEnumHandleTable");
而ZwAllocateVirtualMemory,ZwOpenFile, ZwCreateSection, ZwMapViewOfSection为什么就不用得到函数地址就能用呢
2009-3-2 21:49
0
雪    币: 157
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
35
另外还有个驱动中创建用户态线程的函数,觉得太简单了,就不贴了
=============================================



贴出来扫扫盲啊
2009-3-12 17:21
0
雪    币: 157
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
36
编译测试了一下,报错了????

不知道有没有人测试成功的。。

我把ssdt.exe改成了calc.exe。。。。

是不是运行界面程序有问题?
2009-3-25 20:45
0
雪    币: 157
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
37
测试 报错如下:
上传的附件:
2009-3-26 09:02
0
雪    币: 364
活跃值: (152)
能力值: ( LV12,RANK:450 )
在线值:
发帖
回帖
粉丝
38
如果在用户态线程创建进程,那还不如用以前的插apc呢……

出错我分析是没加锁吧?后面没搞了。牛人们帮忙改改~
2009-3-26 22:39
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
39
我也遇到了这样的问题....
2009-3-28 21:44
0
雪    币: 252
活跃值: (13)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
40
一样的啊
2009-4-12 22:48
0
雪    币: 217
活跃值: (35)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
41
插apc要强制改变一个线程的alartable状态,虽然大多数时候没事,但是毕竟是不安全的。
用创建用户态线程,就安全多了。
2009-4-13 00:10
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
42
楼主太厉害了!
2009-7-14 14:50
0
雪    币: 243
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
scm
43
是不是防止SSDT HOOK?!
2009-7-15 09:48
0
雪    币: 284
活跃值: (16)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
44
早就看出是武陵盟主的大作
2009-7-16 11:09
0
雪    币: 203
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
45
强烈要求知道的出来扫盲
2009-8-27 13:59
0
雪    币: 203
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
46
37 楼那个错误,有人能解释下不??
2009-8-27 15:07
0
雪    币: 276
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
47
这个方法比用apc的方法优美啊
2009-8-30 11:13
0
雪    币: 364
活跃值: (152)
能力值: ( LV12,RANK:450 )
在线值:
发帖
回帖
粉丝
48
很简单的函数,创建远程线程。内核态用户态都可以:
NTSTATUS
MyCreateRemoteThread(
      IN     HANDLE ProcessHandle,
      IN     PVOID   ThreadStartAddress,
      IN     PVOID   ThreadParameter,
      IN OUT ULONG *ThreadStackSize,
      OUT PVOID *ThreadStackAddress,
      OUT HANDLE *ThreadHandle
      )
{
    OBJECT_ATTRIBUTES ObjectAttributes;
    CONTEXT           ThreadContext;
    INITIAL_TEB       InitialTeb;
    CLIENT_ID         ThreadClientId;
    NTSTATUS          Status;
//HMODULE hNTDLL   =   LoadLibraryW(L"ntdll.dll");
//pFnZwAllocateVirtualMemory   ZwAllocateVirtualMemory =
//   (pFnZwAllocateVirtualMemory) GetProcAddress (hNTDLL, "ZwAllocateVirtualMemory");
//pFnZwFreeVirtualMemory   ZwFreeVirtualMemory =
//   (pFnZwFreeVirtualMemory) GetProcAddress (hNTDLL,   "ZwFreeVirtualMemory");
//pFnZwCreateThread ZwCreateThread =
//   (pFnZwCreateThread) GetProcAddress (hNTDLL,   "ZwCreateThread");
//pFnRtlInitializeContext RtlInitializeContext =
//   (pFnRtlInitializeContext) GetProcAddress (hNTDLL,   "RtlInitializeContext");
    // 创建新线程的堆栈   

*ThreadHandle       = NULL;
    *ThreadStackAddress = NULL;
*ThreadStackSize    = 0x400000;
    Status = ZwAllocateVirtualMemory(
   ProcessHandle,
   ThreadStackAddress,
   0,
   ThreadStackSize,
   MEM_COMMIT,
   PAGE_READWRITE
   );

    if ( ! NT_SUCCESS( Status ))
        return Status;

    InitialTeb.StackLimit = *ThreadStackAddress;
    InitialTeb.StackBase = (PVOID)((PCHAR)*ThreadStackAddress + *ThreadStackSize );
//RtlpCreateStack(handle, 0, 0, 0L, &InitialTeb );
    RtlInitializeContext(
        ProcessHandle,
        &ThreadContext,
        ThreadParameter,
        ThreadStartAddress,
        InitialTeb.StackBase
        );

    InitializeObjectAttributes( &ObjectAttributes, NULL, 0, NULL, NULL );

    Status = ZwCreateThread(
   ThreadHandle,
   THREAD_ALL_ACCESS,
   &ObjectAttributes,
   ProcessHandle,
   &ThreadClientId,
   &ThreadContext,
   &InitialTeb,
   FALSE
   );

    if ( ! NT_SUCCESS( Status )) {
        *ThreadStackSize = 0;
        ZwFreeVirtualMemory(
            ProcessHandle,
            ThreadStackAddress,
            ThreadStackSize,
            MEM_RELEASE
            );
}

    return Status;
}

int __stdcall RtlInitializeContext(int a1, CONTEXT *a2, char a3, DWORD a4, DWORD a5)
{
int result;  

DWORD v6;

DWORD v7;

int v8;

a2->Eax = 0;
a2->Ebp = 0;
a2->SegGs = 0;
a2->SegEs = 32;
a2->SegDs = 32;
a2->SegSs = 32;
a2->Eip = a4;
v6 = a5;
v7 = (DWORD)&a2->Esp;
a2->Ebx = 1;
a2->Ecx = 2;
a2->Edx = 3;
a2->Esi = 4;
a2->Edi = 5;
a2->SegFs = 56;
a2->SegCs = 24;
a2->EFlags = 512;
a2->ContextFlags = 65543;
v6 -= 4;
v8 = a1;
a2->Esp = v6;
result = ZwWriteVirtualMemory(v8, v6, &a3, 4, 0);
*(_DWORD *)v7 -= 4;
return result;
}

HANDLE MyOpenProcess(HANDLE id)
{
    NTSTATUS status;
    OBJECT_ATTRIBUTES oa = {sizeof(OBJECT_ATTRIBUTES), 0, NULL, 0};
    ACCESS_MASK da = 0x0001;
    HANDLE ProcessHandle = NULL;
    CLIENT_ID ClientId;
    ClientId.UniqueProcess = id;
    ClientId.UniqueThread = 0;

    ZwOpenProcess(&ProcessHandle, da, &oa, &ClientId);
return ProcessHandle;

}
2009-9-17 12:42
0
雪    币: 235
活跃值: (10)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
49

最近在搞进程加载,创建
2009-12-17 15:09
0
雪    币: 130
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
50
有创建用户态进程,那有没有加载DLL的呢:H贪心一个
2009-12-17 17:29
0
游客
登录 | 注册 方可回帖
返回
//