查看: 736|回复: 0

[其他发布] 开源市面上荒野行动某辅助的过检测

[复制链接]
发表于 2021-2-25 18:08 | 显示全部楼层 |阅读模式
非法程序、 2021-2-25 18:08 736 0 显示全部楼层
写内存字节集 (进程ID, GetProcAddress (ntdll, “RtlCaptureStackBackTrace”), 还原字节集2 (“C2 10 00”))


写内存字节集 (进程ID, GetProcAddress (GDI32.dll, “BitBlt”), 还原字节集2 (“C2 24 00”))
写内存字节集 (进程ID, GetProcAddress (GDI32.dll, “DeleteDC”), 还原字节集2 (“C2 04 00”))
写内存字节集 (进程ID, GetProcAddress (GDI32.dll, “GetBoundsRect”), 还原字节集2 (“C2 1E 00”)))
写内存字节集 (进程ID, GetProcAddress (GDI32.dll, “StretchBlt”), 还原字节集2 (“C2 2C 00”))


)
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “DragDetect”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “EnumDesktopWindows”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “EnumThreadWindows”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “EnumWindows”), 还原字节集2 (“C2 08 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “FindWindowExA”), 还原字节集2 (“C2 10 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “GetActiveWindow”), 还原字节集2 (“C3 01 E8”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “GetWindowDC”), 还原字节集2 (“C2 04 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “PrintWindow”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “ReleaseDC”), 还原字节集2 (“C2 08 00”))
写内存字节集 (进程ID, GetProcAddress (USER32.dll, “WindowFromPoint”), 还原字节集2 (“C2 08 00”))



写内存字节集 (进程ID, GetProcAddress (kernel32, “CreateToolhelp32Snapshot”), 还原字节集2 (“C2 08 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “Heap32ListNext”), 还原字节集2 (“C2 08 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32EnumPageFilesA”), 还原字节集2 (“C2 08 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32EnumPageFilesW”), 还原字节集2 (“C2 08 00”))
程ID, GetProcAddress (kernel32, “K32GetDeviceDriverBaseNameA”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetDeviceDriverBaseNameW”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetDeviceDriverFileNameA”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetDeviceDriverFileNameW”), 还原字节集2 (“C2 0C 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetMappedFileNameA”), 还原字节集2 (“C2 10 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetMappedFileNameW”), 还原字节集2 (“C2 10 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetModuleBaseNameW”), 还原字节集2 (“C2 10 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetModuleFileNameExA”), 还原字节集2 (“C2 10 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “K32GetModuleFileNameExW”), 还原字节集2 (“C2 10 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “Module32First”), 还原字节集2 (“C2 08 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “Module32Next”), 还原字节集2 (“C2 08 00”))
写内存字节集 (进程ID, GetProcAddress (kernel32, “Thread32First”), 还原字节集2 (“C2 08 00”))

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则 返回列表 发新帖

快速回复 返回顶部 返回列表