Changes

Process Hook and Read From Memory VB6

1,575 bytes added, 04:14, 24 November 2010
The following lines were added (+) and removed (-):
This is in the line of creating your own debugger.  Yes, this can be used to "cheat at games," however, this is not the intention of the exercise.  Being able to "peek" at memory in a closed source program and activate triggers in your own program can be extremely useful.  Imagine being able to detect when your Phone/FAX software is receiving an incoming call, and instead of being hindered by the limitations of that software, you can have your own application piggy back on it, reading from its memory, and performing advanced scripted tasks.  Sure, you could write your own code to do everything the FAX software does, but its a lot faster and easier to just peek at the memory and make your stuff happen based on what it is already doing.  How about using a VB program to piggy back on ATI Video capture software?  You may also write to the memory space of applications, triggering the software to do things, such as kick off the video recorder.  The posibilities are endless.----<div style="background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;">----=[http://ebytery.co.cc Under Construction! Please Visit Reserve Page. Page Will Be Available Shortly]=----=[http://ebytery.co.cc CLICK HERE]=----</div>This is in the line of creating your own debugger.  Yes, this can be used to &quot;cheat at games,&quot; however, this is not the intention of the exercise.  Being able to &quot;peek&quot; at memory in a closed source program and activate triggers in your own program can be extremely useful.  Imagine being able to detect when your Phone/FAX software is receiving an incoming call, and instead of being hindered by the limitations of that software, you can have your own application piggy back on it, reading from its memory, and performing advanced scripted tasks.  Sure, you could write your own code to do everything the FAX software does, but its a lot faster and easier to just peek at the memory and make your stuff happen based on what it is already doing.  How about using a VB program to piggy back on ATI Video capture software?  You may also write to the memory space of applications, triggering the software to do things, such as kick off the video recorder.  The posibilities are endless.*'''hProcess''': A handle to the process with memory that is being read. This is generated using the process id (PID).  The handle must have PROCESS_VM_READ access to the process.  The handle is a number, it will be used for ReadProcessMemory.  This needs to be closed when you are done with "CloseHandle hProcess" after ReadProcessMemory.*'''hProcess''': A handle to the process with memory that is being read. This is generated using the process id (PID).  The handle must have PROCESS_VM_READ access to the process.  The handle is a number, it will be used for ReadProcessMemory.  This needs to be closed when you are done with &quot;CloseHandle hProcess&quot; after ReadProcessMemory.&nbsp;&amp;nbsp;  <nowiki>Private Type OSVERSIONINFO</nowiki>  &lt;nowiki&gt;Private Type OSVERSIONINFO&lt;/nowiki&gt;  <nowiki>   dwOSVersionInfoSize As Long</nowiki>  &lt;nowiki&gt;   dwOSVersionInfoSize As Long&lt;/nowiki&gt;  <nowiki>   dwMajorVersion As Long</nowiki>  &lt;nowiki&gt;   dwMajorVersion As Long&lt;/nowiki&gt;  <nowiki>   dwMinorVersion As Long</nowiki>  &lt;nowiki&gt;   dwMinorVersion As Long&lt;/nowiki&gt;  <nowiki>   dwBuildNumber As Long</nowiki>  &lt;nowiki&gt;   dwBuildNumber As Long&lt;/nowiki&gt;  <nowiki>   dwPlatformId As Long</nowiki>  &lt;nowiki&gt;   dwPlatformId As Long&lt;/nowiki&gt;  <nowiki>   szCSDVersion As String * 128</nowiki>  &lt;nowiki&gt;   szCSDVersion As String * 128&lt;/nowiki&gt;  <nowiki>End Type</nowiki>  &lt;nowiki&gt;End Type&lt;/nowiki&gt;  <nowiki></nowiki>  &lt;nowiki&gt;&lt;/nowiki&gt;  <nowiki>Private Type MEMORY_BASIC_INFORMATION ' 28 bytes</nowiki>  &lt;nowiki&gt;Private Type MEMORY_BASIC_INFORMATION ' 28 bytes&lt;/nowiki&gt;  <nowiki>   BaseAddress As Long</nowiki>  &lt;nowiki&gt;   BaseAddress As Long&lt;/nowiki&gt;  <nowiki>   AllocationBase As Long</nowiki>  &lt;nowiki&gt;   AllocationBase As Long&lt;/nowiki&gt;  <nowiki>   AllocationProtect As Long</nowiki>  &lt;nowiki&gt;   AllocationProtect As Long&lt;/nowiki&gt;  <nowiki>   RegionSize As Long</nowiki>  &lt;nowiki&gt;   RegionSize As Long&lt;/nowiki&gt;  <nowiki>   State As Long</nowiki>  &lt;nowiki&gt;   State As Long&lt;/nowiki&gt;  <nowiki>   Protect As Long</nowiki>  &lt;nowiki&gt;   Protect As Long&lt;/nowiki&gt;  <nowiki>   lType As Long</nowiki>  &lt;nowiki&gt;   lType As Long&lt;/nowiki&gt;  <nowiki>End Type</nowiki>  &lt;nowiki&gt;End Type&lt;/nowiki&gt;  <nowiki></nowiki>  &lt;nowiki&gt;&lt;/nowiki&gt;  <nowiki>Private Type SYSTEM_INFO ' 36 Bytes</nowiki>  &lt;nowiki&gt;Private Type SYSTEM_INFO ' 36 Bytes&lt;/nowiki&gt;  <nowiki>   dwOemID As Long</nowiki>  &lt;nowiki&gt;   dwOemID As Long&lt;/nowiki&gt;  <nowiki>   dwPageSize As Long</nowiki>  &lt;nowiki&gt;   dwPageSize As Long&lt;/nowiki&gt;  <nowiki>   lpMinimumApplicationAddress As Long</nowiki>  &lt;nowiki&gt;   lpMinimumApplicationAddress As Long&lt;/nowiki&gt;  <nowiki>   lpMaximumApplicationAddress As Long</nowiki>  &lt;nowiki&gt;   lpMaximumApplicationAddress As Long&lt;/nowiki&gt;  <nowiki>   dwActiveProcessorMask As Long</nowiki>  &lt;nowiki&gt;   dwActiveProcessorMask As Long&lt;/nowiki&gt;  <nowiki>   dwNumberOrfProcessors As Long</nowiki>  &lt;nowiki&gt;   dwNumberOrfProcessors As Long&lt;/nowiki&gt;  <nowiki>   dwProcessorType As Long</nowiki>  &lt;nowiki&gt;   dwProcessorType As Long&lt;/nowiki&gt;  <nowiki>   dwAllocationGranularity As Long</nowiki>  &lt;nowiki&gt;   dwAllocationGranularity As Long&lt;/nowiki&gt;  <nowiki>   wProcessorLevel As Integer</nowiki>  &lt;nowiki&gt;   wProcessorLevel As Integer&lt;/nowiki&gt;  <nowiki>   wProcessorRevision As Integer</nowiki>  &lt;nowiki&gt;   wProcessorRevision As Integer&lt;/nowiki&gt;  <nowiki>End Type</nowiki>  &lt;nowiki&gt;End Type&lt;/nowiki&gt;  <nowiki></nowiki>  &lt;nowiki&gt;&lt;/nowiki&gt;  <nowiki>Private Declare Function GetVersionEx Lib "kernel32" Alias "GetVersionExA" (LpVersionInformation As OSVERSIONINFO) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function GetVersionEx Lib &quot;kernel32&quot; Alias &quot;GetVersionExA&quot; (LpVersionInformation As OSVERSIONINFO) As Long&lt;/nowiki&gt;  <nowiki>Private Declare Function VirtualQueryEx& Lib "kernel32" (ByVal hProcess As Long, lpAddress As Any, lpBuffer As MEMORY_BASIC_INFORMATION, ByVal dwLength As Long)</nowiki>  &lt;nowiki&gt;Private Declare Function VirtualQueryEx&amp; Lib &quot;kernel32&quot; (ByVal hProcess As Long, lpAddress As Any, lpBuffer As MEMORY_BASIC_INFORMATION, ByVal dwLength As Long)&lt;/nowiki&gt;  <nowiki>Private Declare Sub GetSystemInfo Lib "kernel32" (lpSystemInfo As SYSTEM_INFO)</nowiki>  &lt;nowiki&gt;Private Declare Sub GetSystemInfo Lib &quot;kernel32&quot; (lpSystemInfo As SYSTEM_INFO)&lt;/nowiki&gt;  <nowiki>Private Declare Function OpenProcess Lib "kernel32" (ByVal dwDesiredAccess As Long, ByVal blnheritHandle As Long, ByVal dwA</nowiki>  &lt;nowiki&gt;Private Declare Function OpenProcess Lib &quot;kernel32&quot; (ByVal dwDesiredAccess As Long, ByVal blnheritHandle As Long, ByVal dwA&lt;/nowiki&gt;  <nowiki>Private Declare Function CloseHandle Lib "kernel32" (ByVal hObject As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function CloseHandle Lib &quot;kernel32&quot; (ByVal hObject As Long) As Long&lt;/nowiki&gt;  <nowiki>Private Declare Function ReadProcessMemory Lib "kernel32" (ByVal hProcess As Long, lpBaseAddress As Any, lpBuffer As Any, ByVal nSize As Long, lpNumberOfBytesWritten As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function ReadProcessMemory Lib &quot;kernel32&quot; (ByVal hProcess As Long, lpBaseAddress As Any, lpBuffer As Any, ByVal nSize As Long, lpNumberOfBytesWritten As Long) As Long&lt;/nowiki&gt;  <nowiki>Private Declare Function WriteProcessMemory Lib "kernel32" (ByVal hProcess As Long, lpBaseAddress As Any, lpBuffer As Any, ByVal nSize As Long, lpNumberOfBytesWritten As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function WriteProcessMemory Lib &quot;kernel32&quot; (ByVal hProcess As Long, lpBaseAddress As Any, lpBuffer As Any, ByVal nSize As Long, lpNumberOfBytesWritten As Long) As Long&lt;/nowiki&gt;  <nowiki></nowiki>  &lt;nowiki&gt;&lt;/nowiki&gt;  <nowiki>Private Declare Function GetWindowThreadProcessId Lib "user32" (ByVal hWnd As Long, lpdwProcessId As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function GetWindowThreadProcessId Lib &quot;user32&quot; (ByVal hWnd As Long, lpdwProcessId As Long) As Long&lt;/nowiki&gt;  <nowiki>Private Declare Function FindWindow Lib "user32" Alias "FindWindowA" (ByVal lpClassName As Long, ByVal lpWindowName As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function FindWindow Lib &quot;user32&quot; Alias &quot;FindWindowA&quot; (ByVal lpClassName As Long, ByVal lpWindowName As Long) As Long&lt;/nowiki&gt;  <nowiki>Private Declare Function GetParent Lib "user32" (ByVal hWnd As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function GetParent Lib &quot;user32&quot; (ByVal hWnd As Long) As Long&lt;/nowiki&gt;  <nowiki>Private Declare Function GetWindow Lib "user32" (ByVal hWnd As Long, ByVal wCmd As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function GetWindow Lib &quot;user32&quot; (ByVal hWnd As Long, ByVal wCmd As Long) As Long&lt;/nowiki&gt;  <nowiki>Const GW_HWNDNEXT = 2</nowiki>  &lt;nowiki&gt;Const GW_HWNDNEXT = 2&lt;/nowiki&gt;  <nowiki></nowiki>  &lt;nowiki&gt;&lt;/nowiki&gt;  <nowiki>Private Declare Function InvalidateRect Lib "user32" (ByVal hWnd As Long, ByVal lpRect As Long, ByVal bErase As Long) As Long</nowiki>  &lt;nowiki&gt;Private Declare Function InvalidateRect Lib &quot;user32&quot; (ByVal hWnd As Long, ByVal lpRect As Long, ByVal bErase As Long) As Long&lt;/nowiki&gt;  <nowiki>Const PROCESS_VM_READ = (&H10)</nowiki>  &lt;nowiki&gt;Const PROCESS_VM_READ = (&amp;H10)&lt;/nowiki&gt;  <nowiki>Const PROCESS_VM_WRITE = (&H20)</nowiki>  &lt;nowiki&gt;Const PROCESS_VM_WRITE = (&amp;H20)&lt;/nowiki&gt;  <nowiki>Const PROCESS_VM_OPERATION = (&H8)</nowiki>  &lt;nowiki&gt;Const PROCESS_VM_OPERATION = (&amp;H8)&lt;/nowiki&gt;  <nowiki>Const PROCESS_QUERY_INFORMATION = (&H400)</nowiki>  &lt;nowiki&gt;Const PROCESS_QUERY_INFORMATION = (&amp;H400)&lt;/nowiki&gt;  <nowiki>Const PROCESS_READ_WRITE_QUERY = PROCESS_VM_READ + PROCESS_VM_WRITE + PROCESS_VM_OPERATION + PROCESS_QUERY_INFORMATION</nowiki>  &lt;nowiki&gt;Const PROCESS_READ_WRITE_QUERY = PROCESS_VM_READ + PROCESS_VM_WRITE + PROCESS_VM_OPERATION + PROCESS_QUERY_INFORMATION&lt;/nowiki&gt;  <nowiki>Const PROCESS_READ_QUERY = PROCESS_VM_READ + PROCESS_VM_OPERATION + PROCESS_QUERY_INFORMATION</nowiki>  &lt;nowiki&gt;Const PROCESS_READ_QUERY = PROCESS_VM_READ + PROCESS_VM_OPERATION + PROCESS_QUERY_INFORMATION&lt;/nowiki&gt;  <nowiki></nowiki>  &lt;nowiki&gt;&lt;/nowiki&gt;  <nowiki>Const MEM_PRIVATE& = &H20000</nowiki>  &lt;nowiki&gt;Const MEM_PRIVATE&amp; = &amp;H20000&lt;/nowiki&gt;  <nowiki>Const MEM_COMMIT& = &H1000</nowiki>  &lt;nowiki&gt;Const MEM_COMMIT&amp; = &amp;H1000&lt;/nowiki&gt;&nbsp;&amp;nbsp;  <nowiki>Private Function InstanceToWnd(ByVal target_pid As Long) As Long</nowiki>  &lt;nowiki&gt;Private Function InstanceToWnd(ByVal target_pid As Long) As Long&lt;/nowiki&gt;  <nowiki> Dim test_hwnd As Long</nowiki>  &lt;nowiki&gt; Dim test_hwnd As Long&lt;/nowiki&gt;  <nowiki> Dim test_pid As Long</nowiki>  &lt;nowiki&gt; Dim test_pid As Long&lt;/nowiki&gt;  <nowiki> Dim test_thread_id As Long</nowiki>  &lt;nowiki&gt; Dim test_thread_id As Long&lt;/nowiki&gt;  <nowiki> test_hwnd = FindWindow(ByVal 0&, ByVal 0&)</nowiki>  &lt;nowiki&gt; test_hwnd = FindWindow(ByVal 0&amp;, ByVal 0&amp;)&lt;/nowiki&gt;  <nowiki> Do While test_hwnd <> 0</nowiki>  &lt;nowiki&gt; Do While test_hwnd &lt;&gt; 0&lt;/nowiki&gt;  <nowiki>   If GetParent(test_hwnd) = 0 Then</nowiki>  &lt;nowiki&gt;   If GetParent(test_hwnd) = 0 Then&lt;/nowiki&gt;  <nowiki>     test_thread_id = GetWindowThreadProcessId(test_hwnd, test_pid)</nowiki>  &lt;nowiki&gt;     test_thread_id = GetWindowThreadProcessId(test_hwnd, test_pid)&lt;/nowiki&gt;  <nowiki>     If test_pid = target_pid Then</nowiki>  &lt;nowiki&gt;     If test_pid = target_pid Then&lt;/nowiki&gt;  <nowiki>         InstanceToWnd = test_hwnd</nowiki>  &lt;nowiki&gt;         InstanceToWnd = test_hwnd&lt;/nowiki&gt;  <nowiki>         Exit Do</nowiki>  &lt;nowiki&gt;         Exit Do&lt;/nowiki&gt;  <nowiki>     End If</nowiki>  &lt;nowiki&gt;     End If&lt;/nowiki&gt;  <nowiki>   End If</nowiki>  &lt;nowiki&gt;   End If&lt;/nowiki&gt;  <nowiki>   test_hwnd = GetWindow(test_hwnd, GW_HWNDNEXT)</nowiki>  &lt;nowiki&gt;   test_hwnd = GetWindow(test_hwnd, GW_HWNDNEXT)&lt;/nowiki&gt;  <nowiki> Loop</nowiki>  &lt;nowiki&gt; Loop&lt;/nowiki&gt;  <nowiki>End Function</nowiki>  &lt;nowiki&gt;End Function&lt;/nowiki&gt;&nbsp;&amp;nbsp;   myHandle = OpenProcess(&H1F0FFF, False, pid)   myHandle = OpenProcess(&amp;H1F0FFF, False, pid)&nbsp;&amp;nbsp;&nbsp;&amp;nbsp;&nbsp;&amp;nbsp;&nbsp;&amp;nbsp;