30Q币请人修改一个P版的纯AU3隐藏进程
要求可以同时隐藏多个不同的进程,包括自身的进程! 本帖最后由 yang3114 于 2012-3-29 13:40 编辑联系QQ:858850548 50Q币,涨价了。 本帖最后由 ajian55 于 2012-3-29 20:23 编辑
隐藏自身进程知道了吧?来看下隐藏其他的进程~
如隐藏 "hello.exe":#include <Thread.au3>
#include <LocalSecurityAuthority.au3>
Global $subPid = Run("hello.exe") ;此处运行子程序将下面这个函数:Func _NotifyProcessEnumeration($hWnd, $iMsg, $iCurPid, $pProcessInfo)
Local $iPid, $iOffset, $iPrevOffset, $hProcess
$hProcess = _RTOpenProcess(Number($iCurPid))
While 1
$iPid = _RTReadProcessMemory($hProcess, $pProcessInfo + 68, 0, 4, "dword*")
$iOffset = _RTReadProcessMemory($hProcess, $pProcessInfo, 0, 4, "dword*")
If ($iPid = @AutoItPid) Then
If ($iOffset = 0) Then
_RTWriteProcessMemory($hProcess, $pProcessInfo - $iPrevOffset, 0, 4, "dword*")
Else
_RTWriteProcessMemory($hProcess, $pProcessInfo - $iPrevOffset, $iPrevOffset + $iOffset, 4, "dword*")
EndIf
ExitLoop
EndIf
If ($iOffset = 0) Then ExitLoop
$pProcessInfo += $iOffset
$iPrevOffset = $iOffset
WEnd
_RTCloseHandle($hProcess)
EndFunc ;==>_NotifyProcessEnumeration改成:Func _NotifyProcessEnumeration($hWnd, $iMsg, $iCurPid, $pProcessInfo)
Local $iPid, $iOffset, $iPrevOffset, $hProcess
Local $pProcessInfo_0 = $pProcessInfo
$hProcess = _RTOpenProcess(Number($iCurPid))
While 1
$iPid = _RTReadProcessMemory($hProcess, $pProcessInfo + 68, 0, 4, "dword*")
$iOffset = _RTReadProcessMemory($hProcess, $pProcessInfo, 0, 4, "dword*")
If ($iPid = @AutoItPid) Then
If ($iOffset = 0) Then
_RTWriteProcessMemory($hProcess, $pProcessInfo - $iPrevOffset, 0, 4, "dword*")
Else
_RTWriteProcessMemory($hProcess, $pProcessInfo - $iPrevOffset, $iPrevOffset + $iOffset, 4, "dword*")
EndIf
ExitLoop
EndIf
If ($iOffset = 0) Then ExitLoop
$pProcessInfo += $iOffset
$iPrevOffset = $iOffset
WEnd
$pProcessInfo = $pProcessInfo_0
$iPrevOffset = 0
While 1
$iPid = _RTReadProcessMemory($hProcess, $pProcessInfo + 68, 0, 4, "dword*")
$iOffset = _RTReadProcessMemory($hProcess, $pProcessInfo, 0, 4, "dword*")
If ($iPid = $subPid) Then
If ($iOffset = 0) Then
_RTWriteProcessMemory($hProcess, $pProcessInfo - $iPrevOffset, 0, 4, "dword*")
Else
_RTWriteProcessMemory($hProcess, $pProcessInfo - $iPrevOffset, $iPrevOffset + $iOffset, 4, "dword*")
EndIf
ExitLoop
EndIf
If ($iOffset = 0) Then ExitLoop
$pProcessInfo += $iOffset
$iPrevOffset = $iOffset
WEnd
_RTCloseHandle($hProcess)
EndFunc ;==>_NotifyProcessEnumeration俺的联系方式里有俺QQ号,有不懂的就Q俺吧~{:face (356):} 能否封装成函数? 如果要隐藏多几个呢? 我也正在找,很需要! 钱扣了,东西没下来,还我钱来。。。 我也正在找,很需要! 我也正在找,很需要! 经验之谈,谢谢楼主了,请继续努力
http://www.discuz.net/static/image/common/sigline.gif
同心米粉 同心米粉批发 同心米粉价格
页:
[1]