الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

User-mode Unhooking

بدأه Syntax_err في 17 يونيو 2008 · 2 رد · 979 مشاهدة · في لغة Delphi
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

بسم الله والصلاة والسلام على رسول الله ,,, أما بعد ,,,

وجدت في أحد المصار لدي كود لإستعادة خطف الدوال على مستوى اليوزر مود ,,, حبيت أشارككم بيه ,,,

ما أدري إذا لازم تكون هناك مصادر لعدم تعمقي ( ما أعرف شي أصلاً ) بالدلفي :]

بأحاول أرفق المشروع كامل الموجود لدي ,,, لكن بالبداية أردت أن أقوم بتحويل الدالة إلى الفيجول بيسك ورأيت ذلك ممكناً ,,, قمت بتعديل ما إستطعت عليه ,,, والباقي عليكمـ :D

إذا كان لديكم الرغبة في إرفاق المشروع كامل وإرفاق ملفات تتحدث عن إستعادة الدوال المخطوفة والروتكتز والـ SDT Restore ما عندي مانع أرفقها لكمـ ,,, وإذا إستعطت تحويل هذا الكود ,, سأقوم بمحاولة تحويل الـ Kernel Mode Unhooking

صحيح إنها تعتبر صعبة بعض الشي ,,, لكني قد رأيت مثال عن الفيزيكل ميموري لعمل روت كت بالفيجول وبهذا لم أستبعد إستعادة جدول SDT عن طريق الفيجول بيسك ,,,

أتوقع أن الموضوع ليس في قسمه ولكن بصراحة أرى أن قسم الفيجول يجب أن يسمى قسم (برامج المبيعات والمخازن) :D وإذا طرحت الموضوع هناك لن أجد التجاوب ,, وبحكم وجود كود دلفي ,, فهنا سأجد من يساعدني على إكمال عملي بتحويله للفيجول ,,,

كود الدلفي:

function UnhookExport(hModule: HMODULE; FunctionName: pchar): boolean;
type
  TSections = array [0..0] of TImageSectionHeader;
var
  ModuleName: pchar;
  ImageBase, LoadedImage, pImageBase, pSectionBase: pointer;
  Module: THandle;
  ModuleSize, BytesRead: dword;
  ImageDosHeader: PImageDosHeader;
  ImageNtHeaders: PImageNtHeaders;
  ImageExportDirectory: PImageExportDirectory;
  ExportLoop: integer;
  ExportName: pchar;
  ExportFunction: pointer;
  PNames: pdword;
  PFunctions: pdword;
  PSections: ^TSections;
  SectionLoop: integer;
  SectionBase: pointer;
  VirtualSectionSize, RawSectionSize: dword;
  LoadedAddress: pbyte;
  ExportedAddress: pbyte;
  OldProtection: dword;
  CodeLen: dword;
begin
  Result := False;
  GetMem(ModuleName, MAX_PATH + 1);
  GetModuleFileName(hModule, ModuleName, MAX_PATH + 1);
  ExportedAddress := nil;
  LoadedAddress := nil;
  Module := CreateFile(ModuleName, GENERIC_READ, FILE_SHARE_READ, nil, OPEN_EXISTING, 0, 0);
  SetFilePointer(Module, 0, nil, FILE_BEGIN);
  ModuleSize := GetFileSize(Module, nil);
  GetMem(LoadedImage, ModuleSize);
  ReadFile(Module, LoadedImage^, ModuleSize, BytesRead, nil);
  CloseHandle(Module);
  ImageDosHeader := PImageDosHeader(LoadedImage);
  ImageNtHeaders := PImageNtHeaders(cardinal(ImageDosHeader.e_lfanew) + cardinal(LoadedImage));
  ImageBase := VirtualAlloc(nil, ImageNtHeaders.OptionalHeader.SizeOfImage, MEM_RESERVE, PAGE_NOACCESS);
  pImageBase := ImageBase;
  SectionBase := VirtualAlloc(ImageBase, ImageNtHeaders.OptionalHeader.SizeOfHeaders, MEM_COMMIT, PAGE_READWRITE);
  pSectionBase := SectionBase;
  Move(LoadedImage^, SectionBase^, ImageNtHeaders.OptionalHeader.SizeOfHeaders);
  PSections := pointer(pchar(@(ImageNtHeaders.OptionalHeader)) + ImageNtHeaders.FileHeader.SizeOfOptionalHeader);
  for SectionLoop := 0 to ImageNtHeaders.FileHeader.NumberOfSections - 1 do
  begin
	VirtualSectionSize := PSections[SectionLoop].Misc.VirtualSize;
	RawSectionSize := PSections[SectionLoop].SizeOfRawData;
	if VirtualSectionSize < RawSectionSize then VirtualSectionSize := RawSectionSize;
	SectionBase := VirtualAlloc(PSections[SectionLoop].VirtualAddress + pchar(ImageBase), VirtualSectionSize, MEM_COMMIT, PAGE_READWRITE);
	FillChar(SectionBase^, VirtualSectionSize, 0);
	Move(pointer(cardinal(LoadedImage) + PSections[SectionLoop].PointerToRawData)^, SectionBase^, RawSectionSize);
	VirtualFree(SectionBase, 0, MEM_RELEASE);
  end;
  ImageExportDirectory := PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress + cardinal(ImageBase));
  PNames := pointer(cardinal(ImageExportDirectory.AddressOfNames) + cardinal(ImageBase));
  PFunctions := pointer(cardinal(ImageExportDirectory.AddressOfFunctions) + cardinal(ImageBase));
  for ExportLoop := 0 to ImageExportDirectory.NumberOfNames - 1 do
  begin
	ExportName := pchar(pdword(PNames)^ + cardinal(ImageBase));
	ExportFunction := pointer(pdword(PFunctions)^ + cardinal(ImageBase));
	if lstrcmpi(ExportName, FunctionName) = 0 then
	begin
	  LoadedAddress := ExportFunction;
	  Break;
	end;
	Inc(PNames);
	Inc(PFunctions);
  end;
  ImageBase := pointer(GetModuleHandle(ModuleName));
  ImageDosHeader := PImageDosHeader(ImageBase);
  ImageNtHeaders := PImageNtHeaders(cardinal(ImageDosHeader.e_lfanew) + cardinal(ImageBase));
  ImageExportDirectory := PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress + cardinal(ImageBase));
  PNames := pointer(cardinal(ImageExportDirectory.AddressOfNames) + cardinal(ImageBase));
  PFunctions := pointer(cardinal(ImageExportDirectory.AddressOfFunctions) + cardinal(ImageBase));
  for ExportLoop := 0 to ImageExportDirectory.NumberOfNames - 1 do
  begin
	ExportName := pchar(pdword(PNames)^ + cardinal(ImageBase));
	ExportFunction := pointer(pdword(PFunctions)^ + cardinal(ImageBase));
	if lstrcmpi(ExportName, FunctionName) = 0 then
	begin
	  ExportedAddress := ExportFunction;
	  Break;
	end;
	Inc(PNames);
	Inc(PFunctions);
  end;
  if ((LoadedAddress <> nil) and (ExportedAddress <> nil)) then
  begin
	if ((ExportedAddress^ <> 0) and (LoadedAddress^ <> 0) and (ExportedAddress^ <> LoadedAddress^)) then
	begin
	  Result := True;
	  WriteLn('Unhooking ', FunctionName, '...');
	  WriteLn('');
	  CodeLen := SizeOfProc(LoadedAddress);
	  VirtualProtect(ExportedAddress, CodeLen, PAGE_EXECUTE_READWRITE, @OldProtection);
	  CopyMemory(ExportedAddress, LoadedAddress, CodeLen);
	  VirtualProtect(ExportedAddress, CodeLen, OldProtection, @OldProtection);
	end;
  end;
  FreeMem(ModuleName);
  FreeMem(LoadedImage);
  VirtualFree(pImageBase, 0, MEM_RELEASE);
  VirtualFree(pSectionBase, 0, MEM_RELEASE);
end;

function CheckExports(ImageBase: pointer; ImageExportDirectory: PImageExportDirectory): boolean;
var
  ExportLoop: integer;
  ExportName: pchar;
  PNames: pdword;
  HooksFound: boolean;
begin
  Result := False;
  PNames := pointer(cardinal(ImageExportDirectory.AddressOfNames) + cardinal(ImageBase));
  for ExportLoop := 0 to ImageExportDirectory.NumberOfNames - 1 do
  begin
	ExportName := pchar(pdword(PNames)^ + cardinal(ImageBase));
	HooksFound := UnhookExport(HMODULE(ImageBase), ExportName);
	if HooksFound = True then Result := True;
	Inc(PNames);
  end;
end;

procedure RemoveUserHooks;
var
  ImageBase: pointer;
  ImageDosHeader: PImageDosHeader;
  ImageNtHeaders: PImageNtHeaders;
  ImageExportDirectory: PImageExportDirectory;
begin
  ImageBase := pointer(GetModuleHandle('kernel32'));
  ImageDosHeader := PImageDosHeader(ImageBase);
  ImageNtHeaders := PImageNtHeaders(cardinal(ImageDosHeader.e_lfanew) + cardinal(ImageBase));
  ImageExportDirectory := PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress + cardinal(ImageBase));
  if ImageExportDirectory <> ImageBase then
  begin
	if ImageExportDirectory.NumberOfNames <> 0 then
	begin
	  if not CheckExports(ImageBase, ImageExportDirectory) then WriteLn('No user mode hooks found!');
	end;
  end;
end;

end.

وهذه محاولتي للتحويل للفيجول :

Option Explicit

Private Type IMAGE_DOS_HEADER
   Magic	As Integer
   cblp	 As Integer
   cp	   As Integer
   crlc	 As Integer
   cparhdr  As Integer
   minalloc As Integer
   maxalloc As Integer
   ss	   As Integer
   sp	   As Integer
   csum	 As Integer
   ip	   As Integer
   cs	   As Integer
   lfarlc   As Integer
   ovno	 As Integer
   res(3)   As Integer
   oemid	As Integer
   oeminfo  As Integer
   res2(9)  As Integer
   lfanew   As Long
End Type

Private Type IMAGE_FILE_HEADER
	Machine As Integer
	NumberOfSections As Integer
	TimeDateStamp As Long
	PointerToSymbolTable As Long
	NumberOfSymbols As Long
	SizeOfOptionalHeader As Integer
	Characteristics As Integer
End Type


Private Type IMAGE_OPTIONAL_HEADER
	Magic As Integer
	MajorLinkerVersion As Byte
	MinorLinkerVersion As Byte
	SizeOfCode As Long
	SizeOfInitializedData As Long
	SizeOfUninitializedData As Long
	AddressOfEntryPoint As Long
	BaseOfCode As Long
	BaseOfData As Long
End Type

Private Type IMAGE_DATA_DIRECTORY
   VirtualAddress As Long
   Size As Long
End Type


Private Type IMAGE_OPTIONAL_HEADER_NT
   ImageBase As Long
   SectionAlignment As Long
   FileAlignment As Long
   MajorOperatingSystemVersion As Integer
   MinorOperatingSystemVersion As Integer
   MajorImageVersion As Integer
   MinorImageVersion As Integer
   MajorSubsystemVersion As Integer
   MinorSubsystemVersion As Integer
   Win32VersionValue As Long
   SizeOfImage As Long
   SizeOfHeaders As Long
   CheckSum As Long
   Subsystem As Integer
   DllCharacteristics As Integer
   SizeOfStackReserve As Long
   SizeOfStackCommit As Long
   SizeOfHeapReserve As Long
   SizeOfHeapCommit As Long
   LoaderFlags As Long
   NumberOfRvaAndSizes As Long
   DataDirectory(0 To 15) As IMAGE_DATA_DIRECTORY
End Type

Private Type IMAGE_NT_HEADERS
	Signature As Long
	FileHeader As IMAGE_FILE_HEADER
	OptionalHeader As IMAGE_OPTIONAL_HEADER_NT
End Type

Private Type IMAGE_EXPORT_DIRECTORY
	Characteristics As Long
	TimeDateStamp As Long
	MajorVersion As Integer
	MinorVersion As Integer
	lpName As Long
	Base As Long
	NumberOfFunctions As Long
	NumberOfNames As Long
	lpAddressOfFunctions As Long
	lpAddressOfNames As Long
	lpAddressOfNameOrdinals As Long
End Type


Private Declare Function CreateFile Lib "kernel32" Alias "CreateFileA" (ByVal lpFileName As String, ByVal dwDesiredAccess As Long, ByVal dwShareMode As Long, lpSecurUnhookExportityAttributes As Any, ByVal dwCreationDisposition As Long, ByVal dwFlagsAndAttributes As Long, ByVal hTemplateFile As Long) As Long
Private Declare Function SetFilePointer Lib "kernel32" (ByVal hFile As Long, ByVal lDistanceToMove As Long, lpDistanceToMoveHigh As Long, ByVal dwMoveMethod As Long) As Long
Private Declare Function GetFileSize Lib "kernel32" (ByVal hFile As Long, lpFileSizeHigh As Long) As Long
Private Declare Function ReadFile Lib "kernel32" (ByVal hFile As Long, lpBuffer As Any, ByVal nNumberOfBytesToRead As Long, lpNumberOfBytesRead As Long, lpOverlapped As Any) As Long
Private Declare Function CloseHandle Lib "kernel32" (ByVal hObject As Long) As Long
Private Declare Function VirtualAlloc Lib "kernel32" (ByVal lpAddress As Long, ByVal dwSize As Long, ByVal flAllocationType As Long, ByVal flProtect As Long) As Long
Private Declare Sub CopyMemory Lib "kernel32" Alias "RtlMoveMemory" (pDst As Any, pSrc As Any, ByVal ByteLen As Long)
Private Declare Function VirtualProtect Lib "kernel32" (lpAddress As Any, ByVal dwSize As Long, ByVal flNewProtect As Long, lpflOldProtect As Long) As Long
Private Declare Function lstrcmpi Lib "kernel32" Alias "lstrcmpiA" (ByVal lpString1 As String, ByVal lpString2 As String) As Long
Private Declare Function VirtualFree Lib "kernel32" (ByVal lpAddress As Long, ByVal dwSize As Long, ByVal dwFreeType As Long) As Long

Private Const GENERIC_READ = &H80000000
Private Const FILE_SHARE_READ = &H1
Private Const OPEN_EXISTING = 3
Private Const FILE_BEGIN = 0

Private Const OP_MODRM = &H1
Private Const OP_DATA_I8 = &H2
Private Const OP_DATA_I16 = &H4
Private Const OP_DATA_I32 = &H8
Private Const OP_DATA_PRE66_67 = &H10

Private Const MEM_RELEASE = &H8000
Private Const MEM_COMMIT = &H1000
Private Const MEM_RESERVE = &H2000
Private Const PAGE_READWRITE = &H4
Private Const PAGE_EXECUTE_READWRITE = &H40
Private Const PAGE_NOACCESS = &H1

Private Function UnhookExport(hModule As Long, FunctionName As String) As Boolean

  Dim ModuleName As String
  Dim ImageBase As Long
  Dim LoadedImage As Long
  Dim pImageBase As Long
  Dim pSectionBase As Long
  Dim Module As Long
  Dim ModuleSize As Long
  Dim BytesRead As Long
  Dim ImageDosHeader As IMAGE_DOS_HEADER
  Dim ImageNtHeaders As IMAGE_NT_HEADERS
  Dim ImageExportDirectory As IMAGE_EXPORT_DIRECTORY
  Dim ExportLoop As Integer
  Dim ExportName As String
  Dim ExportFunction As Long
  Dim PNames As Long
  Dim PFunctions As Long
  Dim PSections As String 'TSections
  Dim SectionLoop As Integer
  Dim SectionBase As Long
  Dim VirtualSectionSize, RawSectionSize As Long
  Dim LoadedAddress As Byte
  Dim ExportedAddress As Byte
  Dim OldProtection As Long
  Dim CodeLen As Long


  UnhookExport = False
  ModuleName = Space$(256)
  GetModuleFileName hModule, ModuleName, 256
  'ExportedAddress = vbNull
  'LoadedAddress = vbNull
  Module = CreateFile(ModuleName, GENERIC_READ, FILE_SHARE_READ, vbNull, OPEN_EXISTING, 0, 0)
  SetFilePointer Module, 0, vbNull, FILE_BEGIN
  ModuleSize = GetFileSize(Module, vbNull)
  LoadedImage = Space$(ModuleSize)
  ReadFile Module, LoadedImage, ModuleSize, BytesRead, vbNull
  CloseHandle Module

  ImageDosHeader = PImageDosHeader(LoadedImage)
  ImageNtHeaders = PImageNtHeaders(ImageDosHeader.e_lfanew + LoadedImage)

  ImageBase = VirtualAlloc(vbNull, ImageNtHeaders.OptionalHeader.SizeOfImage, MEM_RESERVE, PAGE_NOACCESS)
  pImageBase = ImageBase
  SectionBase = VirtualAlloc(ImageBase, ImageNtHeaders.OptionalHeader.SizeOfHeaders, MEM_COMMIT, PAGE_READWRITE)
  pSectionBase = SectionBase
  CopyMemory SectionBase, LoadedImage, ImageNtHeaders.OptionalHeader.SizeOfHeaders
  PSections = StrPtr(ImageNtHeaders.OptionalHeader) + ImageNtHeaders.FileHeader.SizeOfOptionalHeader

  For SectionLoop = 0 To ImageNtHeaders.FileHeader.NumberOfSections - 1
	VirtualSectionSize = PSections(SectionLoop).Misc.VirtualSize
	RawSectionSize = PSections(SectionLoop).SizeOfRawData
	If VirtualSectionSize < RawSectionSize Then VirtualSectionSize = RawSectionSize
	SectionBase = VirtualAlloc(PSections(SectionLoop).VirtualAddress + StrPtr(ImageBase), VirtualSectionSize, MEM_COMMIT, PAGE_READWRITE)
	FillChar SectionBase, VirtualSectionSize, 0
	CopyMemory SectionBase, LoadedImage + PSections(SectionLoop).PointerToRawData, RawSectionSize
	VirtualFree SectionBase, 0, MEM_RELEASE
  Next

  ImageExportDirectory = PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory(IMAGE_DIRECTORY_ENTRY_EXPORT).VirtualAddress + ImageBase)
  PNames = ImageExportDirectory.lpName + ImageBase
  PFunctions = ImageExportDirectory.lpAddressOfFunctions + ImageBase

  For ExportLoop = 0 To ImageExportDirectory.NumberOfNames - 1
	ExportName = StrPtr(PNames) ^ ImageBase
	ExportFunction = PFunctions ^ ImageBase
	If lstrcmpi(ExportName, FunctionName) = 0 Then
	  LoadedAddress = ExportFunction
	  Exit For
	End If
	'Inc (PNames)
	'Inc (PFunctions)
  Next

  ImageBase = GetModuleHandle(ModuleName)
  ImageDosHeader = PImageDosHeader(ImageBase)
  ImageNtHeaders = PImageNtHeaders(ImageDosHeader.e_lfanew + ImageBase)
  ImageExportDirectory = PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory(IMAGE_DIRECTORY_ENTRY_EXPORT).VirtualAddress + ImageBase)
  PNames = ImageExportDirectory.lpAddressOfNames + ImageBase
  PFunctions = ImageExportDirectory.lpAddressOfFunctions + ImageBase
  For ExportLoop = 0 To ImageExportDirectory.NumberOfNames - 1
	ExportName = StrPtr(PNames) ^ ImageBase
	ExportFunction = PFunctions ^ ImageBase
	If lstrcmpi(ExportName, FunctionName) = 0 Then
	  ExportedAddress = ExportFunction
	  Exit For
	End If
	'Inc (PNames)
	'Inc (PFunctions)
  Next
  If ((LoadedAddress <> vbNull) And (ExportedAddress <> vbNull)) Then
	If ((ExportedAddress <> 0) And (LoadedAddress <> 0) And (ExportedAddress <> LoadedAddress)) Then
	  Result = True
	  Debug.Print "Unhooking ", FunctionName, "..."
	  Debug.Print
	  CodeLen = SizeOfProc(LoadedAddress)
	  VirtualProtect ExportedAddress, CodeLen, PAGE_EXECUTE_READWRITE, OldProtection
	  CopyMemory ExportedAddress, LoadedAddress, CodeLen
	  VirtualProtect ExportedAddress, CodeLen, OldProtection, OldProtection
	End If
  End If

  CloseHandle ModuleName
  CloseHandle LoadedImage
  VirtualFree pImageBase, 0, MEM_RELEASE
  VirtualFree pSectionBase, 0, MEM_RELEASE
End Function


Private Function CheckExports(ImageBase As Long, ImageExportDirectory As IMAGE_EXPORT_DIRECTORY) As Boolean

  Dim ExportLoop As Integer
  Dim ExportName As String
  Dim PNames As Long
  Dim HooksFound As Boolean

  Result = False
  PNames = ImageExportDirectory.lpAddressOfNames + ImageBase
  For ExportLoop = 0 To ImageExportDirectory.NumberOfNames - 1
	ExportName = StrPtr(PNames) ^ ImageBase
	HooksFound = UnhookExport(hModule(ImageBase), ExportName)
	If HooksFound = True Then Result = True
	'Inc (PNames)
  Next

End Function

Private Sub RemoveUserHooks()

Dim ImageBase As Long
Dim ImageDosHeader As IMAGE_DOS_HEADER
Dim ImageNtHeaders As IMAGE_NT_HEADERS
Dim ImageExportDirectory As IMAGE_EXPORT_DIRECTORY

  ImageBase = GetModuleHandle("kernel32")
  ImageDosHeader = PImageDosHeader(ImageBase)
  ImageNtHeaders = PImageNtHeaders(ImageDosHeader.e_lfanew + ImageBase)
  ImageExportDirectory = PImageExportDirectory(ImageNtHeaders.OptionalHeader.DataDirectory(IMAGE_DIRECTORY_ENTRY_EXPORT).VirtualAddress + ImageBase)
  If ImageExportDirectory <> ImageBase Then
	If ImageExportDirectory.NumberOfNames <> 0 Then
	  If Not CheckExports(ImageBase, ImageExportDirectory) Then Debug.Print "No user mode hooks found!"
	End If
  End If
End Sub

Private Function SizeOfProc(Proc() As Byte) As Long
	Dim Length As Long, pOpcode As Byte, Result As Long
	pOpcode = 1
	Do
		Length = SizeOfCode(Proc, pOpcode)
		Result = Result + Length
		If ((Length = 1) And (pOpcode = &HC3)) Then Exit Do
		If ((Length = 3) And (pOpcode = &HC2)) Then Exit Do
		sProc = StrConv(Proc, vbUnicode)
		sProc = Right$(sProc, Len(sProc) - Length)
		Proc = StrConv(sProc, vbFromUnicode)
	Loop Until (Length < 1)
	SizeOfProc = Result
End Function

Private Function SizeOfCode(Code() As Byte, ByRef pOpcode As Byte) As Long

	Dim PFX66 As Boolean, PFX67 As Boolean, SibPresent As Boolean
	Dim OffsetSize As Byte, Add As Byte, iMod As Byte, iRM As Byte, cPtr As Byte, Flags As Byte

	OffsetSize = 0
	PFX66 = False
	PFX67 = False
	cPtr = 0

	While ((Code(cPtr) = &H2E) Or (Code(cPtr) = &H3E) Or (Code(cPtr) = &H36) Or (Code(cPtr) = &H26) Or (Code(cPtr) = &H64) Or (Code(cPtr) = &H65) Or (Code(cPtr) = &HF0) Or (Code(cPtr) = &HF2) Or (Code(cPtr) = &HF3) Or (Code(cPtr) = &H66) Or (Code(cPtr) = &H67))
	  If (Code(cPtr) = &H66) Then PFX66 = True
	  If (Code(cPtr) = &H67) Then PFX67 = True
	  cPtr = cPtr + 1
	  If (cPtr > 16) Then SizeOfCode = 0: Exit Function
	Wend
	If pOpcode Then pOpcode = Code(cPtr)

	If (Code(cPtr) = &HF) Then
	  cPtr = cPtr + 1
	  Flags = OpcodeFlagsExt(Code(cPtr))
	Else
	  Flags = OpcodeFlags(Code(cPtr))
	End If
	cPtr = cPtr + 1
	If (Flags And OP_WORD) Then cPtr = cPtr + 1

	If (Flags And OP_MODRM) Then
	  iMod = Int(Code(cPtr) / (2 ^ 6))
	  iRM = Code(cPtr) And 7
	  cPtr = cPtr + 1

	  SibPresent = (Not PFX67) And (iRM = 4)
	  Select Case iMod
		Case 0:
		  If (PFX67 And (iRM = 6)) Then OffsetSize = 2
		  If ((Not PFX67) And (iRM = 5)) Then OffsetSize = 4
		Case 1: OffsetSize = 1
		Case 2: If (PFX67) Then OffsetSize = 2 Else OffsetSize = 4
		Case 3: SibPresent = False
	  End Select
	  If (SibPresent) Then
		If (((Code(cPtr) And 7) = 5) And ((Not iMod) Or (iMod = 2))) Then OffsetSize = 4
		cPtr = cPtr + 1
	  End If
	  cPtr = cPtr + OffsetSize
	End If
	If (Flags And OP_DATA_I8) Then cPtr = cPtr + 1
	If (Flags And OP_DATA_I16) Then cPtr = cPtr + 2
	If (Flags And OP_DATA_I32) Then cPtr = cPtr + 4
	If (PFX66) Then Add = 2 Else Add = 4
	If (Flags And OP_DATA_PRE66_67) Then cPtr = cPtr + Add
	SizeOfCode = cPtr
End Function

لو تلاحظون إني وقفت عند دالة inc وكم تحويل و "^" وكم شي ما عرفت له بالضبط ,,, أرجو المساعدة في إكمال ذلك ,, وزي ما قلت ,,, لو محتاجين باقي مشروع الدلفي وكود الـ kernel level unhooking أنا موجود وتحت الأمر

والمعذرة إذا خالفنا شرط ولا شرطين :D

#2

مبرووووووووووووووووووك .. لقد أتم الموضوع 100 مشاهدة , ولارد .. :lol:

منتظر ,,

#3

هههههههههههههههههههههههههههههههههههههه

لا احب العمل في هذه المواضيع من الـuser-mode :P ... اذا كان هناك نية لمناقشة(وليس طلب اكواد جاهزة) كيفية استرجاع الـKernel Modified Code فيستحسن ان يكون بقسم الـAPI :evil: .

mov eax, dword ptr ds:[0xffdf0308]

jmp dword ptr [eax+0xfc]

مواضيع مشابهة