登录
首页 » Delphi » driver

driver

于 2007-11-02 发布 文件大小:3KB
0 95
下载积分: 1 下载次数: 114

代码说明:

  用DDDK编写驱动,修改SSDT表HOOK NTDebugActiveProcess函数 钩子函数中可以判断PID号,决定是否放行,放行则在钩子函数中调用原来的NTDebugActiveProcess函数.否则直接返回False.HOOK成功后所有调用DebugActiveProcess的程序将会失效.当然可以按照你的需要HOOK更多的系统服务函数.同一服务函数的服务号在每个操作系统版本中是不同的.下面附件中编译完成的驱动请在WinXP SP2的环境下测试.否则可能会导致直接重启(Used to prepare DDDK drive, modify SSDT Table HOOK NTDebugActiveProcess function hook function can determine the PID number, decide whether to release, release in the hook function to call the original function NTDebugActiveProcess. False.HOOK Otherwise, after the success of a direct return all calls DebugActiveProcess procedures will be failure. You can, of course, in accordance with the needs of more system services HOOK function. the same service function of the service in each of the operating system versions are different. following the completion of the annex to compile drivers in WinXP SP2 test environment. or else may lead to the resumption of direct)

下载说明:请别用迅雷下载,失败请重下,重下不扣分!

发表评论

0 个回复

  • 111111
    说明:  关于DLL解释得比较好的文章,天天和dll文件打交道,究竟有多少人清楚的知道它的作用和原理呢,本文深入浅出,能学习到钩子的原理!(DLL good explanation on the article, dealing with every day, and the dll file, how many people know exactly what its role and principles, this article easy to understand, to learn the principles of the hook!)
    2011-03-03 21:39:55下载
    积分:1
  • wordTOOLS100629
    word开发测试工具,方便了解应用word自身API调用过程(word tools Application Demo)
    2012-07-01 10:44:50下载
    积分:1
  • InnerHook
    一个简单的 钩子小程序 屏蔽了 鼠标键盘,(A simple hook applet shielding mouse, keyboard,)
    2013-07-24 20:45:28下载
    积分:1
  • xubcldss_dqnamic
    这是一个禁止浏览某些网站的程序,可以直接调试通过,非常好用,适合于学习(This is a ban on certain web site procedures, can be directly debugging through, very good, suitable for learning)
    2017-04-23 16:41:11下载
    积分:1
  • srcUDiskCpyManager_V2013_1012_1653
    防止向U盘中拷贝文件, Hook Win32API, 实现在WinXp下U盘 DLP Hook函数列表:CopyFileExW Win7(x86/x64)下U盘DLP Hook函数列表: CoCreateInstance, IFileOperation::CopyItems IFileOperation::MoveItems IFileOperation::NewItem IFileOperation::RenameItem (U disk to copy files to prevent, Hook Win32API, U disk under WinXp achieve DLP Hook Function list: CopyFileExW Win7 (x86/x64) under U disk DLP Hook Function list: CoCreateInstance, IFileOperation :: CopyItems IFileOperation :: MoveItems IFileOperation: : NewItem IFileOperation :: RenameItem)
    2021-01-27 11:38:35下载
    积分:1
  • Hooker
    Hooker you can Create Hooker.dll this file is used Keylogging & injection
    2011-08-22 11:49:40下载
    积分:1
  • monndis
    一个通过hook ndis层来达到监控的工具,代码不错(a tool for hook ndis)
    2021-01-24 23:18:43下载
    积分:1
  • In-VC-achieve-transparent
    有一种按键,看起来是一幅完整的图片,当鼠标移到按键区域时,图片的一部分凸现,形成一个按键,当鼠标移走时又恢复原来状态。(There is a button looks like a complete picture when the mouse is moved to the key areas, the picture is part of the highlights, the formation of a button when the mouse is moved Shiyou restore the original state.)
    2013-08-10 08:22:52下载
    积分:1
  • SSDTHook
    进程隐藏与进程保护(SSDT Hook 实现) 文章目录: 1. 引子 – Hook 技术 2. SSDT 简介 3. 应用层调用 Win32 API 的完整执行流程 4. 详解 SSDT 5. SSDT Hook 原理(SSDT Hook)
    2012-06-25 11:46:29下载
    积分:1
  • DelphiApiHook
    APIHOOK,通过遍历PE文件修改导出函数表进行HOOK(APIHOOK, by traversing the PE file to modify the derived function table HOOK)
    2016-09-13 22:28:38下载
    积分:1
  • 696524资源总数
  • 103838会员总数
  • 43今日下载