Compare commits
4 Commits
78278820eb
...
c8aeddb902
| Author | SHA1 | Date | |
|---|---|---|---|
| c8aeddb902 | |||
| 4d7ffb4136 | |||
| 60725b5434 | |||
| 32d8fd5951 |
@@ -149,6 +149,7 @@
|
|||||||
<ClCompile Include="kernel_function.cpp" />
|
<ClCompile Include="kernel_function.cpp" />
|
||||||
<ClCompile Include="load_Image_callback.cpp" />
|
<ClCompile Include="load_Image_callback.cpp" />
|
||||||
<ClCompile Include="ob_reg_callback.cpp" />
|
<ClCompile Include="ob_reg_callback.cpp" />
|
||||||
|
<ClCompile Include="process_func.cpp" />
|
||||||
<ClCompile Include="protect_filter.cpp" />
|
<ClCompile Include="protect_filter.cpp" />
|
||||||
<ClCompile Include="utils.cpp" />
|
<ClCompile Include="utils.cpp" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
@@ -161,6 +162,7 @@
|
|||||||
<ClInclude Include="kernel_function.h" />
|
<ClInclude Include="kernel_function.h" />
|
||||||
<ClInclude Include="load_Image_callback.h" />
|
<ClInclude Include="load_Image_callback.h" />
|
||||||
<ClInclude Include="ob_reg_callback.h" />
|
<ClInclude Include="ob_reg_callback.h" />
|
||||||
|
<ClInclude Include="process_func.h" />
|
||||||
<ClInclude Include="protect_filter.h" />
|
<ClInclude Include="protect_filter.h" />
|
||||||
<ClInclude Include="utils.h" />
|
<ClInclude Include="utils.h" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|||||||
@@ -35,6 +35,9 @@
|
|||||||
<Filter Include="kernel_private">
|
<Filter Include="kernel_private">
|
||||||
<UniqueIdentifier>{17541143-1a94-4036-9c0b-54a1855caa73}</UniqueIdentifier>
|
<UniqueIdentifier>{17541143-1a94-4036-9c0b-54a1855caa73}</UniqueIdentifier>
|
||||||
</Filter>
|
</Filter>
|
||||||
|
<Filter Include="process_function">
|
||||||
|
<UniqueIdentifier>{e30d7c3e-b37a-4d86-9561-383f1b377fba}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<ClCompile Include="driver_main.cpp">
|
<ClCompile Include="driver_main.cpp">
|
||||||
@@ -67,6 +70,9 @@
|
|||||||
<ClCompile Include="protect_filter.cpp">
|
<ClCompile Include="protect_filter.cpp">
|
||||||
<Filter>kernel_private</Filter>
|
<Filter>kernel_private</Filter>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
<ClCompile Include="process_func.cpp">
|
||||||
|
<Filter>process_function</Filter>
|
||||||
|
</ClCompile>
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<ClInclude Include="Base.h">
|
<ClInclude Include="Base.h">
|
||||||
@@ -99,5 +105,8 @@
|
|||||||
<ClInclude Include="protect_filter.h">
|
<ClInclude Include="protect_filter.h">
|
||||||
<Filter>kernel_private</Filter>
|
<Filter>kernel_private</Filter>
|
||||||
</ClInclude>
|
</ClInclude>
|
||||||
|
<ClInclude Include="process_func.h">
|
||||||
|
<Filter>process_function</Filter>
|
||||||
|
</ClInclude>
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
</Project>
|
</Project>
|
||||||
@@ -1,13 +1,10 @@
|
|||||||
#include "create_thread_callback.h"
|
#include "create_thread_callback.h"
|
||||||
#include "protect_filter.h"
|
#include "protect_filter.h"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
namespace thread_notify_routine
|
namespace thread_notify_routine
|
||||||
{
|
{
|
||||||
//保护的进程ID
|
//保护的进程ID
|
||||||
auto protect_id = ULongToHandle(8976);
|
//auto protect_id = ULongToHandle(8976);
|
||||||
|
|
||||||
|
|
||||||
void thread_notify_routine(HANDLE ProcessId, HANDLE ThreadId, BOOLEAN Create)
|
void thread_notify_routine(HANDLE ProcessId, HANDLE ThreadId, BOOLEAN Create)
|
||||||
@@ -19,9 +16,6 @@ namespace thread_notify_routine
|
|||||||
if (!NT_SUCCESS(status))
|
if (!NT_SUCCESS(status))
|
||||||
goto end;
|
goto end;
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
/*PEPROCESS protect_process{ 0 };
|
/*PEPROCESS protect_process{ 0 };
|
||||||
status = PsLookupProcessByProcessId(protect_id, &protect_process);
|
status = PsLookupProcessByProcessId(protect_id, &protect_process);
|
||||||
if (!NT_SUCCESS(status))
|
if (!NT_SUCCESS(status))
|
||||||
@@ -49,6 +43,7 @@ namespace thread_notify_routine
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
end:
|
end:
|
||||||
ObDereferenceObject(process);
|
ObDereferenceObject(process);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
#include "create_thread_callback.h"
|
#include "create_thread_callback.h"
|
||||||
#include "load_Image_callback.h"
|
#include "load_Image_callback.h"
|
||||||
#include "protect_filter.h"
|
#include "protect_filter.h"
|
||||||
|
#include "process_func.h"
|
||||||
|
|
||||||
EXTERN_C NTSTATUS DriverEntry(PDRIVER_OBJECT drv_obj, PUNICODE_STRING)
|
EXTERN_C NTSTATUS DriverEntry(PDRIVER_OBJECT drv_obj, PUNICODE_STRING)
|
||||||
{
|
{
|
||||||
@@ -11,19 +12,19 @@ EXTERN_C NTSTATUS DriverEntry(PDRIVER_OBJECT drv_obj, PUNICODE_STRING)
|
|||||||
ob_call_back::uninstall_ob_callback();
|
ob_call_back::uninstall_ob_callback();
|
||||||
thread_notify_routine::unload_thread_routine();
|
thread_notify_routine::unload_thread_routine();
|
||||||
load_image_notify_routine::remove_image_load_notify_routine();
|
load_image_notify_routine::remove_image_load_notify_routine();
|
||||||
|
|
||||||
|
|
||||||
|
//process_function::eprocess_protect_process_off(4732);
|
||||||
};
|
};
|
||||||
|
|
||||||
kernel_api::kernel_api_init();
|
kernel_api::kernel_api_init();
|
||||||
|
|
||||||
protect_filter::Init();
|
protect_filter::Init();
|
||||||
protect_filter::add_list(4504, 0);
|
|
||||||
protect_filter::add_list(8152, 0);
|
|
||||||
protect_filter::add_list(8224, 0);
|
|
||||||
|
|
||||||
//protect_filter::is_protect_pid(0);
|
//protect_filter::add_list(6644, 0);
|
||||||
|
|
||||||
//protect_filter::remove_list(7868,0);
|
|
||||||
//protect_filter::is_protect_pid(0);
|
//process_function::eprocess_protect_process_on(4732);
|
||||||
|
|
||||||
|
|
||||||
ob_call_back::register_ob_reg_callback();
|
ob_call_back::register_ob_reg_callback();
|
||||||
|
|||||||
@@ -27,4 +27,7 @@ namespace kernel_api
|
|||||||
return reinterpret_cast<UCHAR * (*)(PEPROCESS)>
|
return reinterpret_cast<UCHAR * (*)(PEPROCESS)>
|
||||||
(imported.ps_getprocessimage_filname)(Process);
|
(imported.ps_getprocessimage_filname)(Process);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -22,13 +22,7 @@ namespace load_image_notify_routine
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -67,7 +67,6 @@ auto ob_call_back::register_ob_reg_callback() -> NTSTATUS
|
|||||||
|
|
||||||
status = ObRegisterCallbacks(&obReg, ®_ob_callback_handle);
|
status = ObRegisterCallbacks(&obReg, ®_ob_callback_handle);
|
||||||
return status;
|
return status;
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
auto ob_call_back::uninstall_ob_callback() -> BOOLEAN
|
auto ob_call_back::uninstall_ob_callback() -> BOOLEAN
|
||||||
|
|||||||
@@ -0,0 +1,61 @@
|
|||||||
|
#include "process_func.h"
|
||||||
|
namespace process_function
|
||||||
|
{
|
||||||
|
ULONG orin_protect_val;
|
||||||
|
|
||||||
|
auto eprocess_get_protect_offset() -> UINT32
|
||||||
|
{
|
||||||
|
UNICODE_STRING func_name{ 0 };
|
||||||
|
RtlInitUnicodeString(&func_name, L"PsIsProtectedProcess");
|
||||||
|
auto pfunc_address = reinterpret_cast<unsigned char*>(MmGetSystemRoutineAddress(&func_name));
|
||||||
|
auto offset = *(UINT32*)(pfunc_address + 0x2);
|
||||||
|
return offset;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
auto eprocess_protect_process_on(UINT32 Pid) -> NTSTATUS
|
||||||
|
{
|
||||||
|
PEPROCESS process{ 0 };
|
||||||
|
|
||||||
|
auto status = PsLookupProcessByProcessId(ULongToHandle(Pid), &process);
|
||||||
|
if (!NT_SUCCESS(status))
|
||||||
|
return status;
|
||||||
|
|
||||||
|
auto offset = eprocess_get_protect_offset();
|
||||||
|
|
||||||
|
auto Protection = reinterpret_cast<unsigned long*>((UINT64)process + offset);
|
||||||
|
if (*Protection != 0xc0000061)
|
||||||
|
{
|
||||||
|
orin_protect_val = *Protection;
|
||||||
|
*Protection = 0xc0000061;
|
||||||
|
}
|
||||||
|
|
||||||
|
ObDereferenceObject(process);
|
||||||
|
return status;
|
||||||
|
}
|
||||||
|
|
||||||
|
auto eprocess_protect_process_off(UINT32 Pid) -> NTSTATUS
|
||||||
|
{
|
||||||
|
PEPROCESS process{ 0 };
|
||||||
|
|
||||||
|
auto status = PsLookupProcessByProcessId(ULongToHandle(Pid), &process);
|
||||||
|
if (!NT_SUCCESS(status))
|
||||||
|
return status;
|
||||||
|
|
||||||
|
auto offset = eprocess_get_protect_offset();
|
||||||
|
auto Protection = reinterpret_cast<unsigned long*>((UINT64)process + offset);
|
||||||
|
if (*Protection == 0xc0000061)
|
||||||
|
*Protection = orin_protect_val;
|
||||||
|
|
||||||
|
ObDereferenceObject(process);
|
||||||
|
return status;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
#pragma once
|
||||||
|
#ifndef PROCESS_FUNC
|
||||||
|
#define PROCESS_FUNC
|
||||||
|
#include "Base.h"
|
||||||
|
|
||||||
|
|
||||||
|
namespace process_function
|
||||||
|
{
|
||||||
|
auto eprocess_protect_process_on(UINT32 Pid)->NTSTATUS;
|
||||||
|
|
||||||
|
auto eprocess_protect_process_off(UINT32 Pid)->NTSTATUS;
|
||||||
|
|
||||||
|
auto kernel_kill_process(UINT32 Pid)->NTSTATUS;
|
||||||
|
}
|
||||||
|
|
||||||
|
#endif // !PROCESS_FUNC
|
||||||
Reference in New Issue
Block a user