profps โพสต์ 2015-11-16 08:32:09

HWID Protected Injector Source

Imports System.Management
Imports System.Net


Public Class Form1
    Dim cpuInfo As String = String.Empty
    Dim mc As New ManagementClass("win32_processor")
    Dim moc As ManagementObjectCollection = mc.GetInstances()

    Private TargetProcessHandle As Integer
    Private pfnStartAddr As Integer
    Private pszLibFileRemote As String
    Private TargetBufferSize As Integer

    Public Const PROCESS_VM_READ = &H10
    Public Const TH32CS_SNAPPROCESS = &H2
    Public Const MEM_COMMIT = 4096
    Public Const PAGE_READWRITE = 4
    Public Const PROCESS_CREATE_THREAD = (&H2)
    Public Const PROCESS_VM_OPERATION = (&H8)
    Public Const PROCESS_VM_WRITE = (&H20)
    Dim DLLFileName As String
    Public Declare Function ReadProcessMemory Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpBaseAddress As Integer, _
    ByVal lpBuffer As String, _
    ByVal nSize As Integer, _
    ByRef lpNumberOfBytesWritten As Integer) As Integer

    Public Declare Function LoadLibrary Lib "kernel32" Alias "LoadLibraryA" ( _
    ByVal lpLibFileName As String) As Integer

    Public Declare Function VirtualAllocEx Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpAddress As Integer, _
    ByVal dwSize As Integer, _
    ByVal flAllocationType As Integer, _
    ByVal flProtect As Integer) As Integer

    Public Declare Function WriteProcessMemory Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpBaseAddress As Integer, _
    ByVal lpBuffer As String, _
    ByVal nSize As Integer, _
    ByRef lpNumberOfBytesWritten As Integer) As Integer

    Public Declare Function GetProcAddress Lib "kernel32" ( _
    ByVal hModule As Integer, ByVal lpProcName As String) As Integer

    Private Declare Function GetModuleHandle Lib "Kernel32" Alias "GetModuleHandleA" ( _
    ByVal lpModuleName As String) As Intege
    Public Declare Function CreateRemoteThread Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpThreadAttributes As Integer, _
    ByVal dwStackSize As Integer, _
    ByVal lpStartAddress As Integer, _
    ByVal lpParameter As Integer, _
    ByVal dwCreationFlags As Integer, _
    ByRef lpThreadId As Integer) As Integer

    Public Declare Function OpenProcess Lib "kernel32" ( _
    ByVal dwDesiredAccess As Integer, _
    ByVal bInheritHandle As Integer, _
    ByVal dwProcessId As Integer) As Integer

    Private Declare Function FindWindow Lib "user32" Alias "FindWindowA" ( _
    ByVal lpClassName As String, _
    ByVal lpWindowName As String) As Integer

    Private Declare Function CloseHandle Lib "kernel32" Alias "CloseHandleA" ( _
    ByVal hObject As Integer) As Integer


    Dim ExeName As String = IO.Path.GetFileNameWithoutExtension(Application.ExecutablePath)


Private Sub Inject()
      On Error GoTo 1
      Timer2.Stop()
      Dim TargetProcess As Process() = Process.GetProcessesByName(TextBox1.Text)
      TargetProcessHandle = OpenProcess(PROCESS_CREATE_THREAD Or PROCESS_VM_OPERATION Or PROCESS_VM_WRITE, False, TargetProcess(0).Id)
      pszLibFileRemote = OpenFileDialog1.FileName
      pfnStartAddr = GetProcAddress(GetModuleHandle("Kernel32"), "LoadLibraryA")
      TargetBufferSize = 1 + Len(pszLibFileRemote)
      Dim Rtn As Integer
      Dim LoadLibParamAdr As Integer
      LoadLibParamAdr = VirtualAllocEx(TargetProcessHandle, 0, TargetBufferSize, MEM_COMMIT, PAGE_READWRITE)
      Rtn = WriteProcessMemory(TargetProcessHandle, LoadLibParamAdr, pszLibFileRemote, TargetBufferSize, 0)
      CreateRemoteThread(TargetProcessHandle, 0, 0, pfnStartAddr, LoadLibParamAdr, 0, 0)
      CloseHandle(TargetProcessHandle)
1:      Me.Show()
    End Sub


Private Sub Form1_Load(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles MyBase.Load
      Timer1.start()
      If Connection() = True Then
            For Each mo As ManagementObject In moc
                If cpuInfo = "" Then
                  cpuInfo = mo.Properties("processorID").Value.ToString()
                  Exit For
                End If
            Next

            Dim HWID As String

            HWID = cpuInfo

            Dim wc As New WebClient
            Dim strings As String
            strings = wc.DownloadString("http://upload a text file to a free host with the HWID numbers in it./HWID.txt")

            wc.Dispose()

            If strings.Contains(HWID) Then
                Me.Show()
                MsgBox("Access Granted!", MsgBoxStyle.Information)
            End If
            If strings.Contains(HWID) = False Then
                MsgBox("You are not allowed to enter Contact Joered333 how to get acces", MsgBoxStyle.Critical)
                Me.Close()
            End If
      Else
            MsgBox("Not Connected to the internet!!!!!!", MsgBoxStyle.Information)
            Me.Close()
      End If

      Button1.Text = "Browse"
      Label1.Text = "Waiting for .dll"
      Timer2.Interval = 50
      Timer2.Start()

    End Sub


Public Function Connection() As Boolean
      Dim sitetocheck As New System.Uri("http://www.google.com/")
      Dim checkrequest As System.Net.WebRequest
      checkrequest = System.Net.WebRequest.Create(sitetocheck)
      Dim objResp As System.Net.WebResponse
      Try
            objResp = checkrequest.GetResponse
            objResp.Close()
            checkrequest = Nothing
            Return True
      Catch x As Exception
            Return False
      End Try
    End Function


Private Sub Timer1_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer1.Tick
      Protect()
    End Sub


Private Sub Timer2_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer2.Tick
      If IO.File.Exists(OpenFileDialog1.FileName) Then
            Dim TargetProcess As Process() = Process.GetProcessesByName(TextBox1.Text)
            If TargetProcess.Length = 0 Then
                Me.Label1.Text = ("Waiting for " + TextBox1.Text + ".exe")

            Else
                Timer2.Stop()
                Me.Label1.Text = "Successfully Injected!"
                Call Inject()
            End If
      Else

      End If
    End Sub


Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click
      OpenFileDialog1.Filter = "DLL (*.dll) |*.dll|(*.*) |*.*"
      OpenFileDialog1.ShowDialog()
      Dim FileName As String
      FileName = OpenFileDialog1.FileName.Substring(OpenFileDialog1.FileName.LastIndexOf("\"))
      Dim DllFileName As String = FileName.Replace("\", "")
      Me.TextBox2.Text = (DllFileName)
    End Sub
///////
Private Function Dlls() As Object
      Throw New NotImplementedException
    End Function


Private Sub Button2_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button2.Click
      End
    End Sub
/////
Private Sub Button3_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button3.Click
      MsgBox("Credits: Joered333      ([email protected]")
    End Sub
End Class


You could do also add something like this in the source when some one opens Ollydb or some programm like that you could let the programm let him self shutdown.
Dim TargetProcess1() As Process = Process.GetProcessesByName("Ollydb")

If Not TargetProcess1.Length = 0 Then
            TargetProcess5(0).Kill()
            MsgBox("Ollydb Detected!", MsgBoxStyle.Critical, "Close it!!")
            Me.Close()
      End If


หน้า: [1]
ดูในรูปแบบกติ: HWID Protected Injector Source