بسم الله والصلاة والسلام على رسول الله ,,, أما بعد ,,,
وجدت في أحد المصار لدي كود لإستعادة خطف الدوال على مستوى اليوزر مود ,,, حبيت أشارككم بيه ,,,
ما أدري إذا لازم تكون هناك مصادر لعدم تعمقي ( ما أعرف شي أصلاً ) بالدلفي :]
بأحاول أرفق المشروع كامل الموجود لدي ,,, لكن بالبداية أردت أن أقوم بتحويل الدالة إلى الفيجول بيسك ورأيت ذلك ممكناً ,,, قمت بتعديل ما إستطعت عليه ,,, والباقي عليكمـ :D
إذا كان لديكم الرغبة في إرفاق المشروع كامل وإرفاق ملفات تتحدث عن إستعادة الدوال المخطوفة والروتكتز والـ SDT Restore ما عندي مانع أرفقها لكمـ ,,, وإذا إستعطت تحويل هذا الكود ,, سأقوم بمحاولة تحويل الـ Kernel Mode Unhooking
صحيح إنها تعتبر صعبة بعض الشي ,,, لكني قد رأيت مثال عن الفيزيكل ميموري لعمل روت كت بالفيجول وبهذا لم أستبعد إستعادة جدول SDT عن طريق الفيجول بيسك ,,,
أتوقع أن الموضوع ليس في قسمه ولكن بصراحة أرى أن قسم الفيجول يجب أن يسمى قسم (برامج المبيعات والمخازن) :D وإذا طرحت الموضوع هناك لن أجد التجاوب ,, وبحكم وجود كود دلفي ,, فهنا سأجد من يساعدني على إكمال عملي بتحويله للفيجول ,,,
كود الدلفي:
function UnhookExport(hModule: HMODULE; FunctionName: pchar): boolean;
type
TSections = array [0..0] of TImageSectionHeader;
var
ModuleName: pchar;
ImageBase, LoadedImage, pImageBase, pSectionBase: pointer;
Module: THandle;
ModuleSize, BytesRead: dword;
ImageDosHeader: PImageDosHeader;
ImageNtHeaders: PImageNtHeaders;
ImageExportDirectory: PImageExportDirectory;
ExportLoop: integer;
ExportName: pchar;
ExportFunction: pointer;
PNames: pdword;
PFunctions: pdword;
PSections: ^TSections;
SectionLoop: integer;
SectionBase: pointer;
VirtualSectionSize, RawSectionSize: dword;
LoadedAddress: pbyte;
ExportedAddress: pbyte;
OldProtection: dword;
CodeLen: dword;
begin
Result := False;
GetMem(ModuleName, MAX_PATH + 1);
GetModuleFileName(hModule, ModuleName, MAX_PATH + 1);
ExportedAddress := nil;
LoadedAddress := nil;
Module := CreateFile(ModuleName, GENERIC_READ, FILE_SHARE_READ, nil, OPEN_EXISTING, 0, 0);
SetFilePointer(Module, 0, nil, FILE_BEGIN);
ModuleSize := GetFileSize(Module, nil);
GetMem(LoadedImage, ModuleSize);
ReadFile(Module, LoadedImage^, ModuleSize, BytesRead, nil);
CloseHandle(Module);
ImageDosHeader := PImageDosHeader(LoadedImage);
ImageNtHeaders := PImageNtHeaders(cardinal(ImageDosHeader.e_lfanew) + cardinal(LoadedImage));
ImageBase := VirtualAlloc(nil, ImageNtHeaders.OptionalHeader.SizeOfImage, MEM_RESERVE, PAGE_NOACCESS);
pImageBase := ImageBase;
SectionBase := VirtualAlloc(ImageBase, ImageNtHeaders.OptionalHeader.SizeOfHeaders, MEM_COMMIT, PAGE_READWRITE);
pSectionBase := SectionBase;
Move(LoadedImage^, SectionBase^, ImageNtHeaders.OptionalHeader.SizeOfHeaders);
PSections := pointer(pchar(@(ImageNtHeaders.OptionalHeader)) + ImageNtHeaders.FileHeader.SizeOfOptionalHeader);
for SectionLoop := 0 to ImageNtHeaders.FileHeader.NumberOfSections - 1 do
begin
VirtualSectionSize := PSections[SectionLoop].Misc.VirtualSize;
RawSectionSize := PSections[SectionLoop].SizeOfRawData;
if VirtualSectionSize < RawSectionSize then VirtualSectionSize := RawSectionSize;
SectionBase := VirtualAlloc(PSections[SectionLoop].VirtualAddress + pchar(ImageBase), VirtualSectionSize, MEM_COMMIT, PAGE_READWRITE);
FillChar(SectionBase^, VirtualSectionSize, 0);
Move(pointer(cardinal(LoadedImage) + PSections[SectionLoop].PointerToRawData)^, SectionBase^, RawSectionSize);
VirtualFree(SectionBase, 0, MEM_RELEASE);
end;
ImageExportDirectory := PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress + cardinal(ImageBase));
PNames := pointer(cardinal(ImageExportDirectory.AddressOfNames) + cardinal(ImageBase));
PFunctions := pointer(cardinal(ImageExportDirectory.AddressOfFunctions) + cardinal(ImageBase));
for ExportLoop := 0 to ImageExportDirectory.NumberOfNames - 1 do
begin
ExportName := pchar(pdword(PNames)^ + cardinal(ImageBase));
ExportFunction := pointer(pdword(PFunctions)^ + cardinal(ImageBase));
if lstrcmpi(ExportName, FunctionName) = 0 then
begin
LoadedAddress := ExportFunction;
Break;
end;
Inc(PNames);
Inc(PFunctions);
end;
ImageBase := pointer(GetModuleHandle(ModuleName));
ImageDosHeader := PImageDosHeader(ImageBase);
ImageNtHeaders := PImageNtHeaders(cardinal(ImageDosHeader.e_lfanew) + cardinal(ImageBase));
ImageExportDirectory := PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress + cardinal(ImageBase));
PNames := pointer(cardinal(ImageExportDirectory.AddressOfNames) + cardinal(ImageBase));
PFunctions := pointer(cardinal(ImageExportDirectory.AddressOfFunctions) + cardinal(ImageBase));
for ExportLoop := 0 to ImageExportDirectory.NumberOfNames - 1 do
begin
ExportName := pchar(pdword(PNames)^ + cardinal(ImageBase));
ExportFunction := pointer(pdword(PFunctions)^ + cardinal(ImageBase));
if lstrcmpi(ExportName, FunctionName) = 0 then
begin
ExportedAddress := ExportFunction;
Break;
end;
Inc(PNames);
Inc(PFunctions);
end;
if ((LoadedAddress <> nil) and (ExportedAddress <> nil)) then
begin
if ((ExportedAddress^ <> 0) and (LoadedAddress^ <> 0) and (ExportedAddress^ <> LoadedAddress^)) then
begin
Result := True;
WriteLn('Unhooking ', FunctionName, '...');
WriteLn('');
CodeLen := SizeOfProc(LoadedAddress);
VirtualProtect(ExportedAddress, CodeLen, PAGE_EXECUTE_READWRITE, @OldProtection);
CopyMemory(ExportedAddress, LoadedAddress, CodeLen);
VirtualProtect(ExportedAddress, CodeLen, OldProtection, @OldProtection);
end;
end;
FreeMem(ModuleName);
FreeMem(LoadedImage);
VirtualFree(pImageBase, 0, MEM_RELEASE);
VirtualFree(pSectionBase, 0, MEM_RELEASE);
end;
function CheckExports(ImageBase: pointer; ImageExportDirectory: PImageExportDirectory): boolean;
var
ExportLoop: integer;
ExportName: pchar;
PNames: pdword;
HooksFound: boolean;
begin
Result := False;
PNames := pointer(cardinal(ImageExportDirectory.AddressOfNames) + cardinal(ImageBase));
for ExportLoop := 0 to ImageExportDirectory.NumberOfNames - 1 do
begin
ExportName := pchar(pdword(PNames)^ + cardinal(ImageBase));
HooksFound := UnhookExport(HMODULE(ImageBase), ExportName);
if HooksFound = True then Result := True;
Inc(PNames);
end;
end;
procedure RemoveUserHooks;
var
ImageBase: pointer;
ImageDosHeader: PImageDosHeader;
ImageNtHeaders: PImageNtHeaders;
ImageExportDirectory: PImageExportDirectory;
begin
ImageBase := pointer(GetModuleHandle('kernel32'));
ImageDosHeader := PImageDosHeader(ImageBase);
ImageNtHeaders := PImageNtHeaders(cardinal(ImageDosHeader.e_lfanew) + cardinal(ImageBase));
ImageExportDirectory := PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress + cardinal(ImageBase));
if ImageExportDirectory <> ImageBase then
begin
if ImageExportDirectory.NumberOfNames <> 0 then
begin
if not CheckExports(ImageBase, ImageExportDirectory) then WriteLn('No user mode hooks found!');
end;
end;
end;
end.وهذه محاولتي للتحويل للفيجول :
Option Explicit
Private Type IMAGE_DOS_HEADER
Magic As Integer
cblp As Integer
cp As Integer
crlc As Integer
cparhdr As Integer
minalloc As Integer
maxalloc As Integer
ss As Integer
sp As Integer
csum As Integer
ip As Integer
cs As Integer
lfarlc As Integer
ovno As Integer
res(3) As Integer
oemid As Integer
oeminfo As Integer
res2(9) As Integer
lfanew As Long
End Type
Private Type IMAGE_FILE_HEADER
Machine As Integer
NumberOfSections As Integer
TimeDateStamp As Long
PointerToSymbolTable As Long
NumberOfSymbols As Long
SizeOfOptionalHeader As Integer
Characteristics As Integer
End Type
Private Type IMAGE_OPTIONAL_HEADER
Magic As Integer
MajorLinkerVersion As Byte
MinorLinkerVersion As Byte
SizeOfCode As Long
SizeOfInitializedData As Long
SizeOfUninitializedData As Long
AddressOfEntryPoint As Long
BaseOfCode As Long
BaseOfData As Long
End Type
Private Type IMAGE_DATA_DIRECTORY
VirtualAddress As Long
Size As Long
End Type
Private Type IMAGE_OPTIONAL_HEADER_NT
ImageBase As Long
SectionAlignment As Long
FileAlignment As Long
MajorOperatingSystemVersion As Integer
MinorOperatingSystemVersion As Integer
MajorImageVersion As Integer
MinorImageVersion As Integer
MajorSubsystemVersion As Integer
MinorSubsystemVersion As Integer
Win32VersionValue As Long
SizeOfImage As Long
SizeOfHeaders As Long
CheckSum As Long
Subsystem As Integer
DllCharacteristics As Integer
SizeOfStackReserve As Long
SizeOfStackCommit As Long
SizeOfHeapReserve As Long
SizeOfHeapCommit As Long
LoaderFlags As Long
NumberOfRvaAndSizes As Long
DataDirectory(0 To 15) As IMAGE_DATA_DIRECTORY
End Type
Private Type IMAGE_NT_HEADERS
Signature As Long
FileHeader As IMAGE_FILE_HEADER
OptionalHeader As IMAGE_OPTIONAL_HEADER_NT
End Type
Private Type IMAGE_EXPORT_DIRECTORY
Characteristics As Long
TimeDateStamp As Long
MajorVersion As Integer
MinorVersion As Integer
lpName As Long
Base As Long
NumberOfFunctions As Long
NumberOfNames As Long
lpAddressOfFunctions As Long
lpAddressOfNames As Long
lpAddressOfNameOrdinals As Long
End Type
Private Declare Function CreateFile Lib "kernel32" Alias "CreateFileA" (ByVal lpFileName As String, ByVal dwDesiredAccess As Long, ByVal dwShareMode As Long, lpSecurUnhookExportityAttributes As Any, ByVal dwCreationDisposition As Long, ByVal dwFlagsAndAttributes As Long, ByVal hTemplateFile As Long) As Long
Private Declare Function SetFilePointer Lib "kernel32" (ByVal hFile As Long, ByVal lDistanceToMove As Long, lpDistanceToMoveHigh As Long, ByVal dwMoveMethod As Long) As Long
Private Declare Function GetFileSize Lib "kernel32" (ByVal hFile As Long, lpFileSizeHigh As Long) As Long
Private Declare Function ReadFile Lib "kernel32" (ByVal hFile As Long, lpBuffer As Any, ByVal nNumberOfBytesToRead As Long, lpNumberOfBytesRead As Long, lpOverlapped As Any) As Long
Private Declare Function CloseHandle Lib "kernel32" (ByVal hObject As Long) As Long
Private Declare Function VirtualAlloc Lib "kernel32" (ByVal lpAddress As Long, ByVal dwSize As Long, ByVal flAllocationType As Long, ByVal flProtect As Long) As Long
Private Declare Sub CopyMemory Lib "kernel32" Alias "RtlMoveMemory" (pDst As Any, pSrc As Any, ByVal ByteLen As Long)
Private Declare Function VirtualProtect Lib "kernel32" (lpAddress As Any, ByVal dwSize As Long, ByVal flNewProtect As Long, lpflOldProtect As Long) As Long
Private Declare Function lstrcmpi Lib "kernel32" Alias "lstrcmpiA" (ByVal lpString1 As String, ByVal lpString2 As String) As Long
Private Declare Function VirtualFree Lib "kernel32" (ByVal lpAddress As Long, ByVal dwSize As Long, ByVal dwFreeType As Long) As Long
Private Const GENERIC_READ = &H80000000
Private Const FILE_SHARE_READ = &H1
Private Const OPEN_EXISTING = 3
Private Const FILE_BEGIN = 0
Private Const OP_MODRM = &H1
Private Const OP_DATA_I8 = &H2
Private Const OP_DATA_I16 = &H4
Private Const OP_DATA_I32 = &H8
Private Const OP_DATA_PRE66_67 = &H10
Private Const MEM_RELEASE = &H8000
Private Const MEM_COMMIT = &H1000
Private Const MEM_RESERVE = &H2000
Private Const PAGE_READWRITE = &H4
Private Const PAGE_EXECUTE_READWRITE = &H40
Private Const PAGE_NOACCESS = &H1
Private Function UnhookExport(hModule As Long, FunctionName As String) As Boolean
Dim ModuleName As String
Dim ImageBase As Long
Dim LoadedImage As Long
Dim pImageBase As Long
Dim pSectionBase As Long
Dim Module As Long
Dim ModuleSize As Long
Dim BytesRead As Long
Dim ImageDosHeader As IMAGE_DOS_HEADER
Dim ImageNtHeaders As IMAGE_NT_HEADERS
Dim ImageExportDirectory As IMAGE_EXPORT_DIRECTORY
Dim ExportLoop As Integer
Dim ExportName As String
Dim ExportFunction As Long
Dim PNames As Long
Dim PFunctions As Long
Dim PSections As String 'TSections
Dim SectionLoop As Integer
Dim SectionBase As Long
Dim VirtualSectionSize, RawSectionSize As Long
Dim LoadedAddress As Byte
Dim ExportedAddress As Byte
Dim OldProtection As Long
Dim CodeLen As Long
UnhookExport = False
ModuleName = Space$(256)
GetModuleFileName hModule, ModuleName, 256
'ExportedAddress = vbNull
'LoadedAddress = vbNull
Module = CreateFile(ModuleName, GENERIC_READ, FILE_SHARE_READ, vbNull, OPEN_EXISTING, 0, 0)
SetFilePointer Module, 0, vbNull, FILE_BEGIN
ModuleSize = GetFileSize(Module, vbNull)
LoadedImage = Space$(ModuleSize)
ReadFile Module, LoadedImage, ModuleSize, BytesRead, vbNull
CloseHandle Module
ImageDosHeader = PImageDosHeader(LoadedImage)
ImageNtHeaders = PImageNtHeaders(ImageDosHeader.e_lfanew + LoadedImage)
ImageBase = VirtualAlloc(vbNull, ImageNtHeaders.OptionalHeader.SizeOfImage, MEM_RESERVE, PAGE_NOACCESS)
pImageBase = ImageBase
SectionBase = VirtualAlloc(ImageBase, ImageNtHeaders.OptionalHeader.SizeOfHeaders, MEM_COMMIT, PAGE_READWRITE)
pSectionBase = SectionBase
CopyMemory SectionBase, LoadedImage, ImageNtHeaders.OptionalHeader.SizeOfHeaders
PSections = StrPtr(ImageNtHeaders.OptionalHeader) + ImageNtHeaders.FileHeader.SizeOfOptionalHeader
For SectionLoop = 0 To ImageNtHeaders.FileHeader.NumberOfSections - 1
VirtualSectionSize = PSections(SectionLoop).Misc.VirtualSize
RawSectionSize = PSections(SectionLoop).SizeOfRawData
If VirtualSectionSize < RawSectionSize Then VirtualSectionSize = RawSectionSize
SectionBase = VirtualAlloc(PSections(SectionLoop).VirtualAddress + StrPtr(ImageBase), VirtualSectionSize, MEM_COMMIT, PAGE_READWRITE)
FillChar SectionBase, VirtualSectionSize, 0
CopyMemory SectionBase, LoadedImage + PSections(SectionLoop).PointerToRawData, RawSectionSize
VirtualFree SectionBase, 0, MEM_RELEASE
Next
ImageExportDirectory = PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory(IMAGE_DIRECTORY_ENTRY_EXPORT).VirtualAddress + ImageBase)
PNames = ImageExportDirectory.lpName + ImageBase
PFunctions = ImageExportDirectory.lpAddressOfFunctions + ImageBase
For ExportLoop = 0 To ImageExportDirectory.NumberOfNames - 1
ExportName = StrPtr(PNames) ^ ImageBase
ExportFunction = PFunctions ^ ImageBase
If lstrcmpi(ExportName, FunctionName) = 0 Then
LoadedAddress = ExportFunction
Exit For
End If
'Inc (PNames)
'Inc (PFunctions)
Next
ImageBase = GetModuleHandle(ModuleName)
ImageDosHeader = PImageDosHeader(ImageBase)
ImageNtHeaders = PImageNtHeaders(ImageDosHeader.e_lfanew + ImageBase)
ImageExportDirectory = PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory(IMAGE_DIRECTORY_ENTRY_EXPORT).VirtualAddress + ImageBase)
PNames = ImageExportDirectory.lpAddressOfNames + ImageBase
PFunctions = ImageExportDirectory.lpAddressOfFunctions + ImageBase
For ExportLoop = 0 To ImageExportDirectory.NumberOfNames - 1
ExportName = StrPtr(PNames) ^ ImageBase
ExportFunction = PFunctions ^ ImageBase
If lstrcmpi(ExportName, FunctionName) = 0 Then
ExportedAddress = ExportFunction
Exit For
End If
'Inc (PNames)
'Inc (PFunctions)
Next
If ((LoadedAddress <> vbNull) And (ExportedAddress <> vbNull)) Then
If ((ExportedAddress <> 0) And (LoadedAddress <> 0) And (ExportedAddress <> LoadedAddress)) Then
Result = True
Debug.Print "Unhooking ", FunctionName, "..."
Debug.Print
CodeLen = SizeOfProc(LoadedAddress)
VirtualProtect ExportedAddress, CodeLen, PAGE_EXECUTE_READWRITE, OldProtection
CopyMemory ExportedAddress, LoadedAddress, CodeLen
VirtualProtect ExportedAddress, CodeLen, OldProtection, OldProtection
End If
End If
CloseHandle ModuleName
CloseHandle LoadedImage
VirtualFree pImageBase, 0, MEM_RELEASE
VirtualFree pSectionBase, 0, MEM_RELEASE
End Function
Private Function CheckExports(ImageBase As Long, ImageExportDirectory As IMAGE_EXPORT_DIRECTORY) As Boolean
Dim ExportLoop As Integer
Dim ExportName As String
Dim PNames As Long
Dim HooksFound As Boolean
Result = False
PNames = ImageExportDirectory.lpAddressOfNames + ImageBase
For ExportLoop = 0 To ImageExportDirectory.NumberOfNames - 1
ExportName = StrPtr(PNames) ^ ImageBase
HooksFound = UnhookExport(hModule(ImageBase), ExportName)
If HooksFound = True Then Result = True
'Inc (PNames)
Next
End Function
Private Sub RemoveUserHooks()
Dim ImageBase As Long
Dim ImageDosHeader As IMAGE_DOS_HEADER
Dim ImageNtHeaders As IMAGE_NT_HEADERS
Dim ImageExportDirectory As IMAGE_EXPORT_DIRECTORY
ImageBase = GetModuleHandle("kernel32")
ImageDosHeader = PImageDosHeader(ImageBase)
ImageNtHeaders = PImageNtHeaders(ImageDosHeader.e_lfanew + ImageBase)
ImageExportDirectory = PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory(IMAGE_DIRECTORY_ENTRY_EXPORT).VirtualAddress + ImageBase)
If ImageExportDirectory <> ImageBase Then
If ImageExportDirectory.NumberOfNames <> 0 Then
If Not CheckExports(ImageBase, ImageExportDirectory) Then Debug.Print "No user mode hooks found!"
End If
End If
End Sub
Private Function SizeOfProc(Proc() As Byte) As Long
Dim Length As Long, pOpcode As Byte, Result As Long
pOpcode = 1
Do
Length = SizeOfCode(Proc, pOpcode)
Result = Result + Length
If ((Length = 1) And (pOpcode = &HC3)) Then Exit Do
If ((Length = 3) And (pOpcode = &HC2)) Then Exit Do
sProc = StrConv(Proc, vbUnicode)
sProc = Right$(sProc, Len(sProc) - Length)
Proc = StrConv(sProc, vbFromUnicode)
Loop Until (Length < 1)
SizeOfProc = Result
End Function
Private Function SizeOfCode(Code() As Byte, ByRef pOpcode As Byte) As Long
Dim PFX66 As Boolean, PFX67 As Boolean, SibPresent As Boolean
Dim OffsetSize As Byte, Add As Byte, iMod As Byte, iRM As Byte, cPtr As Byte, Flags As Byte
OffsetSize = 0
PFX66 = False
PFX67 = False
cPtr = 0
While ((Code(cPtr) = &H2E) Or (Code(cPtr) = &H3E) Or (Code(cPtr) = &H36) Or (Code(cPtr) = &H26) Or (Code(cPtr) = &H64) Or (Code(cPtr) = &H65) Or (Code(cPtr) = &HF0) Or (Code(cPtr) = &HF2) Or (Code(cPtr) = &HF3) Or (Code(cPtr) = &H66) Or (Code(cPtr) = &H67))
If (Code(cPtr) = &H66) Then PFX66 = True
If (Code(cPtr) = &H67) Then PFX67 = True
cPtr = cPtr + 1
If (cPtr > 16) Then SizeOfCode = 0: Exit Function
Wend
If pOpcode Then pOpcode = Code(cPtr)
If (Code(cPtr) = &HF) Then
cPtr = cPtr + 1
Flags = OpcodeFlagsExt(Code(cPtr))
Else
Flags = OpcodeFlags(Code(cPtr))
End If
cPtr = cPtr + 1
If (Flags And OP_WORD) Then cPtr = cPtr + 1
If (Flags And OP_MODRM) Then
iMod = Int(Code(cPtr) / (2 ^ 6))
iRM = Code(cPtr) And 7
cPtr = cPtr + 1
SibPresent = (Not PFX67) And (iRM = 4)
Select Case iMod
Case 0:
If (PFX67 And (iRM = 6)) Then OffsetSize = 2
If ((Not PFX67) And (iRM = 5)) Then OffsetSize = 4
Case 1: OffsetSize = 1
Case 2: If (PFX67) Then OffsetSize = 2 Else OffsetSize = 4
Case 3: SibPresent = False
End Select
If (SibPresent) Then
If (((Code(cPtr) And 7) = 5) And ((Not iMod) Or (iMod = 2))) Then OffsetSize = 4
cPtr = cPtr + 1
End If
cPtr = cPtr + OffsetSize
End If
If (Flags And OP_DATA_I8) Then cPtr = cPtr + 1
If (Flags And OP_DATA_I16) Then cPtr = cPtr + 2
If (Flags And OP_DATA_I32) Then cPtr = cPtr + 4
If (PFX66) Then Add = 2 Else Add = 4
If (Flags And OP_DATA_PRE66_67) Then cPtr = cPtr + Add
SizeOfCode = cPtr
End Functionلو تلاحظون إني وقفت عند دالة inc وكم تحويل و "^" وكم شي ما عرفت له بالضبط ,,, أرجو المساعدة في إكمال ذلك ,, وزي ما قلت ,,, لو محتاجين باقي مشروع الدلفي وكود الـ kernel level unhooking أنا موجود وتحت الأمر
والمعذرة إذا خالفنا شرط ولا شرطين :D