亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來(lái)到蟲(chóng)蟲(chóng)下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲(chóng)蟲(chóng)下載站

?? 29a-7.026

?? 從29A上收集的病毒源碼
?? 026
字號(hào):

                         Process Hide v1.0

                         by 90210//HI-TECH

0. Abstract
-----------

"Phide"  (process  hide)  is  the  engine  for  the  low level process
manipulating  on  kernel  level,  designed  to  be  used by a userland
process. It supports only nt-based systems (NT4, 2k, XP, 2k3). Process
management  is  done  through  the  playing  with EPROCESS structures.
Thread   that   calls   engine   MUST   have   read/write   access  to
\Device\PhysicalMemory, otherwise engine will fail.

1. Features
-----------

The engine main features are:
- get EPROCESS offset for a given pid.
- hide  the  selected  process by excluding its EPROCESS from the most
low-level  kernel  process list, which starts from PsActiveProcessHead
symbol.
- change selected process image name in run-time.
- patch  UniqueProcess  field  in  all  ETHREADs  that  belong  to the
selected  process  to  hide  it  from  klister-like  tools.
- process  can  be  selected  by  pid  or  directly  by  its  EPROCESS
structure.  This is useful when process is already hidden and you have
to  hide  new thread from klister, because even one thread with a real
pid of its process-creator will compromise the whole process.

Process  hiding  technique is the same, as in the 'fu' rootkit, but my
goal  was  to  make  a small engine callable from r3. For now it's the
only  tool,  which hides processes from klister (i have version 0.3 of
this brilliant software).

Engine  code  doesn't rely on the hardcoded ntoskrnl offsets, that may
vary from one servicepack to another. It only relays on the offsets of
the  needed  EPROCESS  and  EHTREADS fields, because these structs are
different in 4 types of nt-based oses.

2. Usage
--------

ProcessHide proc dwProcess2Hide:DWORD,\
                 dwFlags:DWORD,\
                 pNewImgName:DWORD,\
                 ppEPROCESS:DWORD

Function format is STDCALL.

Parameters:

dwProcess2Hide
  Specifies  the process. May be PID or pointer to EPROCESS structure.
  When  setting dwProcess2Hide to pid, the PH_PROCESS_BY_PID flag must
  be set. Otherwise, set PH_PROCESS_BY_EPROCESS flag.

dwFlags
  Specifies  what  engine  should  do with selected process and how it
  should  interpret  dwProcess2Hide  parameter.  dwFlags  may  be    a
  combination of following flags:
  
  PH_PROCESS_BY_PID
    dwProcess2Hide is a PID.
    
  PH_PROCESS_BY_EPROCESS
    dwProcess2Hide points to a EPROCESS structure.
    
  PH_EXCLUDE_EPROCESS
    Hide specified process by excluding its EPROCESS from the EPROCESS
    linked list, which start from PsActiveProcessHead.
  
  PH_CHANGE_THREADS_PID
    Enumerate  all  threads  that  belong to specified process, change
    their  creator's  pid to 8 (System process) and set process' image
    file  name  to  'System'.  This  is done to avoid detecting hidden
    process by klister tool.

  PH_CHANGE_IMGNAME
    Changes  image  file name of the specified process. Name is set to
    pNewImgName. Note that on XP and above process image name will not
    increase its length - if user supplied name is longer than current
    image name, it will be truncated.
    
pNewImgName
  Points  to  a  null-terminated  ANSI  string  that  will be set as a
  process  image  filename  if  PH_CHANGE_IMGNAME flag is set. Ignored
  otherwise.
  
ppEPROCESS
  Points  to DWORD that the engine sets to the found process' EPROCESS
  pointer. May be NULL if EPROCESS offset is not needed.



Return valules
  If  the  engine  succeeds,  the  return value is zero. If the engine
  fails for some reason, return value will be one of the following:

  PH_ERR_GENERAL
    An exception occured somewhere in the engine while working.
  
  PH_ERR_PROCESS_NOT_FOUND
    Engine  couldn't  find  process  with  specified  PID or specified
    EPROCESS seems to be invalid.
  
  PH_ERR_MUST_SPECIFY_NAME
    Flag PH_CHANGE_IMGNAME is set but pNewImgName is NULL.
  
  PH_ERR_NOT_ENOUGH_MEMORY
    One of the VirtualAlloc engine calls has failed.
  
  PH_ERR_CANT_FIND_NTOSKRNL
    Engine couldn't find ntoskrnl imagebase. Strange.
  
  PH_ERR_CANT_OPEN_SECTION
    \Device\PhysicalMemory  is  protected  by some security program or
    you  haven't enough privileges to open it. By default, only admins
    can do that.
  
  PH_ERR_CANT_LOAD_NTOSKRNL
    Internal engine error: it couldn't load ntoskrnl image for further
    analysis. Strange.
  
  PH_ERR_CANT_FIND_PAPH
    Engine failed to find PsActiveProcessHead offset in ntoskrnl.
    
  PH_ERR_CANT_MAP_SECTION
    Engine  couldn't  map a region of physical memory to some userland
    region. Usually happens in VMWare systems.
  
  PH_ERR_CANT_LOCK_PAGES
    R0 code and data pages couldn't be locked for some reason.

  PH_ERR_CANT_FIND_FREE_DESCRIPTOR
    All GDT entries are present (bit P set). Strange.
  
  PH_ERR_OS_NOT_SUPPORTED
    Only NT4, 2k, XP and 2k3 server are supported.
  

Remarks

  Use  PH_CHANGE_THREADS_PID  very  carefully.  After  this  operation
  threads  will  "disconnect"  from  csrss  -  console  output will be
  trashed. GUI processes may cause bsod on their ExitProcess.
  Note  that  XP  and 2k3 don't set EPROCESS SE AUDIT PROCESS CREATION
  INFO ImageFileName field before first thread start - they do that "a
  bit  later",  so  don't  expect  that  PH_CHANGE_IMGNAME  call  will
  succesfully change the name of the newly created process.

?? 快捷鍵說(shuō)明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號(hào) Ctrl + =
減小字號(hào) Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
色网站国产精品| 国产综合色视频| 欧美最猛性xxxxx直播| 亚洲九九爱视频| 精品视频资源站| 久久精品国产精品亚洲精品 | 国产成人福利片| 国产色一区二区| 91在线国产观看| 亚洲3atv精品一区二区三区| 日韩一区二区在线免费观看| www.久久精品| 一区二区在线免费观看| 欧美人xxxx| 国产乱色国产精品免费视频| 国产精品不卡在线观看| 在线观看一区二区精品视频| 秋霞影院一区二区| 国产欧美一区二区三区鸳鸯浴| 91丨porny丨户外露出| 亚洲一区二区在线播放相泽| 欧美videos大乳护士334| 成人听书哪个软件好| 亚洲一区精品在线| 欧美精品一区二区三区久久久| 波多野结衣精品在线| 天堂蜜桃一区二区三区| 久久精品网站免费观看| 欧美日韩中文字幕一区二区| 国产一区二区三区免费看| 亚洲精品视频在线观看免费 | 99精品视频在线观看免费| 亚洲二区在线视频| 国产欧美日韩卡一| 欧美精品欧美精品系列| jlzzjlzz亚洲女人18| 日韩电影在线看| 亚洲美女在线一区| 国产亚洲欧美色| 91超碰这里只有精品国产| 99久久婷婷国产| 久久国产剧场电影| 亚洲国产精品自拍| 亚洲欧洲在线观看av| 欧美一级搡bbbb搡bbbb| 欧美影院精品一区| 成人午夜精品在线| 韩国成人福利片在线播放| 日韩激情av在线| 亚洲麻豆国产自偷在线| 国产精品区一区二区三区| 精品久久久三级丝袜| 91精品国产欧美日韩| 色天天综合久久久久综合片| 北条麻妃一区二区三区| 国产真实精品久久二三区| 午夜精品免费在线观看| 一区二区三区成人| 自拍偷在线精品自拍偷无码专区| 久久精品视频在线看| 精品国产青草久久久久福利| 欧美人狂配大交3d怪物一区| 欧美午夜片在线观看| 91麻豆国产精品久久| 9i在线看片成人免费| 成人网男人的天堂| 成人不卡免费av| 成人激情开心网| 成人h动漫精品一区二区| 国产99一区视频免费| 国产激情视频一区二区在线观看 | 日本欧洲一区二区| 日韩影院精彩在线| 亚洲va欧美va人人爽| 亚洲无人区一区| 亚洲一级在线观看| 一区二区三区蜜桃| 亚洲国产视频一区二区| 亚洲电影在线播放| 亚洲成a人片在线不卡一二三区| 亚洲国产aⅴ天堂久久| 午夜精品爽啪视频| 久久精品国产一区二区| 韩国女主播一区二区三区| 久草在线在线精品观看| 国产一区二区久久| 成人成人成人在线视频| 91影视在线播放| 91国模大尺度私拍在线视频 | 欧美丰满嫩嫩电影| 日韩欧美中文字幕公布| 欧美日高清视频| 欧美日韩成人综合| av激情亚洲男人天堂| 在线观看一区不卡| 欧美一区二区三区四区五区| 精品久久久久一区二区国产| 精品久久久久一区| 日韩一区欧美小说| 综合中文字幕亚洲| 无吗不卡中文字幕| 国产精品自拍三区| 色婷婷激情综合| 91精品国产91热久久久做人人| 精品av综合导航| 综合久久久久久| 婷婷开心久久网| 国产精品一区免费视频| 一本大道久久a久久综合婷婷| 91麻豆精品91久久久久久清纯 | 日韩激情在线观看| 精品一区二区三区久久| 99精品一区二区| 日韩欧美国产午夜精品| 国产精品高潮呻吟| 日韩**一区毛片| 精品视频免费在线| 欧美一区二区观看视频| 国产精品天干天干在线综合| 午夜影院在线观看欧美| 国产一区二区女| 欧美日韩亚洲综合在线 欧美亚洲特黄一级| 日韩免费观看高清完整版在线观看| 中文字幕亚洲电影| 美女在线观看视频一区二区| a级精品国产片在线观看| 日韩视频免费观看高清完整版在线观看 | 一区二区三区四区不卡在线| 久久精品国产一区二区| 91在线视频免费观看| 欧美mv和日韩mv的网站| 一区二区三区在线观看网站| 国产一区二区三区久久久 | 99vv1com这只有精品| 日韩午夜在线观看视频| 亚洲精品乱码久久久久久黑人| 国产一区在线看| 欧美一区二区精品在线| 亚洲激情在线激情| 粉嫩绯色av一区二区在线观看| 9191成人精品久久| 亚洲国产一区二区在线播放| 99re视频精品| 国产精品久久久久三级| 国产一区二区0| 91精品久久久久久蜜臀| 一区二区三区蜜桃| 色综合久久中文综合久久牛| 久久精品人人做人人综合 | 国内精品视频666| 91精品国产综合久久久蜜臀粉嫩 | 日本 国产 欧美色综合| 欧美日韩国产123区| 亚洲精品久久久蜜桃| zzijzzij亚洲日本少妇熟睡| 久久精品视频免费观看| 国产一区二区三区国产| 精品国产乱码91久久久久久网站| 青娱乐精品在线视频| 欧美一区二区私人影院日本| 亚洲.国产.中文慕字在线| 在线观看日韩一区| 亚洲人成在线观看一区二区| 91精品国产乱| 视频在线在亚洲| 91精品国产91综合久久蜜臀| 日本va欧美va精品| 日韩精品一区二区三区在线观看| 蜜桃久久久久久| 日韩一级高清毛片| 美女视频黄免费的久久| 日韩丝袜情趣美女图片| 极品销魂美女一区二区三区| 久久一区二区三区四区| 高清成人免费视频| 中文字幕在线一区| 色综合久久六月婷婷中文字幕| 亚洲色图视频网| 精品视频一区二区三区免费| 男男成人高潮片免费网站| 精品国产乱码久久久久久图片| 国产一区福利在线| 国产精品国产三级国产普通话99 | 欧美一区二区福利在线| 狠狠v欧美v日韩v亚洲ⅴ| 久久精品免费在线观看| 不卡在线观看av| 亚洲国产精品一区二区www在线| 欧美日韩和欧美的一区二区| 蜜桃视频一区二区| 中文字幕av一区二区三区免费看| heyzo一本久久综合| 亚洲成人一二三| 久久影院午夜论| 色老综合老女人久久久| 日本女人一区二区三区| 国产精品沙发午睡系列990531| 91免费观看国产| 蜜臀91精品一区二区三区| 国产视频在线观看一区二区三区 |