ZwProtectVirtualMemory , ZwWriteVirtualMemory , NtWriteVirtualMemory

Posts 1–13 of 13 · Page 1 of 1
ZwProtectVirtualMemory , ZwWriteVirtualMemory , NtWriteVirtualMemory
Hello, I am trying to use these 2 codes:

NtWriteProcessMemory or ZwWriteVirtualMemory to write in the process in place of WriteProcessMemory,

Code:
<DllImport("ntdll", SetLastError:=True)> _
Private Shared Function NtWriteVirtualMemory(ByVal hProcess As IntPtr, ByVal VABA As IntPtr, ByVal lpBuffer As Byte(), ByVal nSS As UInteger, ByVal NOBW As Integer) As Boolean
End Function

Public Declare Function ZwWriteVirtualMemory _
               Lib "NTDLL.DLL" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal pBuffer As Long, _
                                ByVal NumberOfBytesToWrite As Long, _
                                ByRef NumberOfBytesWritten As Long) As Long
and ZwProtectVirtualMemory to unprotect the process memory in place of VirtualProcessEx.

Code:
Public Declare Function ZwProtectVirtualMemory _
               Lib "ntdll.dll" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal RegionSize As Long, _
                                ByVal NewProtect As Long, _
                                ByVal OldProtect As Long) As Long
Public Const PAGE_READWRITE As Long = &H4
Public Const PAGE_GUARD As Long = &H100
Public Const PAGE_EXECUTE As Long = &H10
But I am not able to make them work, they do not have any effect in the game, it is as if they had not found the PID / Handle of the process, could someone help me?
Quote Originally Posted by JVN View Post
Hello, I am trying to use these 2 codes:

NtWriteProcessMemory or ZwWriteVirtualMemory to write in the process in place of WriteProcessMemory,

Code:
<DllImport("ntdll", SetLastError:=True)> _
Private Shared Function NtWriteVirtualMemory(ByVal hProcess As IntPtr, ByVal VABA As IntPtr, ByVal lpBuffer As Byte(), ByVal nSS As UInteger, ByVal NOBW As Integer) As Boolean
End Function

Public Declare Function ZwWriteVirtualMemory _
               Lib "NTDLL.DLL" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal pBuffer As Long, _
                                ByVal NumberOfBytesToWrite As Long, _
                                ByRef NumberOfBytesWritten As Long) As Long
and ZwProtectVirtualMemory to unprotect the process memory in place of VirtualProcessEx.

Code:
Public Declare Function ZwProtectVirtualMemory _
               Lib "ntdll.dll" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal RegionSize As Long, _
                                ByVal NewProtect As Long, _
                                ByVal OldProtect As Long) As Long
Public Const PAGE_READWRITE As Long = &H4
Public Const PAGE_GUARD As Long = &H100
Public Const PAGE_EXECUTE As Long = &H10
But I am not able to make them work, they do not have any effect in the game, it is as if they had not found the PID / Handle of the process, could someone help me?
post your code
Quote Originally Posted by Sazor98 View Post
post your code
Code:
Class Memory
    Private pHandel As IntPtr = IntPtr.Zero
    Private attachedProcess As Process = Nothing
    Private buffer As Byte()

    Public Function Open_pHandel(processName As String) As Boolean
        Dim proc As Process() = Process.GetProcessesByName(processName)

        If proc.Length = 0 Then
            Return False
        ElseIf proc.Length > 1 Then
            Throw New Exception("More then one process found.")
        Else
            attachedProcess = proc(0)
            pHandel = proc(0).Handle
            Return True
        End If
    End Function

#Region "x86"
#Region "Write"
    Public Function WriteBytes(address As Integer, value As Byte(), Optional virtualProtect As Boolean = False) As Boolean
        Dim countOfUsed As Integer = 0
        Dim result As Boolean = False
        Dim oldProtection As UInteger = 0
        Dim value2 as Long

        If virtualProtect Then
            Win32.x86.ZwProtectVirtualMemory(pHandel, address, CUInt(value.Length), &H4, oldProtection)
        End If

        result = Win32.x86.ZwWriteVirtualMemory(pHandel, address, value2, CUInt(value.Length), countOfUsed)

        If virtualProtect Then
            Win32.x86.ZwProtectVirtualMemory(pHandel, address, CUInt(value.Length), oldProtection, oldProtection)
        End If

        Return result
    End Function

    Public Function WriteInt(address As Integer, value As Integer, Optional virtualProtect As Boolean = False) As Boolean
        buffer = BitConverter.GetBytes(value)
        Return WriteBytes(address, buffer, virtualProtect)
    End Function

    Public Function WriteByte(address As Integer, value As Byte, Optional virtualProtect As Boolean = False) As Boolean
        buffer = New Byte() {value}
        Return WriteBytes(address, buffer, virtualProtect)
    End Function

    Public Function WriteString(address As Integer, value As String, Optional virtualProtect As Boolean = False) As Boolean
        buffer = Encoding.ASCII.GetBytes(value)
        'No unicode support atm
        Return WriteBytes(address, buffer, virtualProtect)
    End Function

    Public Function WriteFloat(address As Integer, value As Single, Optional virtualProtect As Boolean = False) As Boolean
        buffer = BitConverter.GetBytes(value)
        Return WriteBytes(address, buffer, virtualProtect)
    End Function
#End Region
#Region "Read"
    Public Function ReadBytes(address As Integer, length As Integer) As Byte()
        Dim readBytes__1 As Byte() = New Byte(length - 1) {}
        Dim numBytesChanged As Integer = 0

        Win32.x86.ReadProcessMemory(pHandel, address, readBytes__1, CUInt(length), numBytesChanged)

        Return readBytes__1
    End Function

    Public Function ReadInt(address As Integer) As Integer
        Return BitConverter.ToInt32(ReadBytes(address, 4), 0)
    End Function

    Public Function ReadByte(address As Integer) As Byte
        Return ReadBytes(address, 1)(0)
    End Function

    Public Function ReadString(address As Integer, length As Integer) As String
        'No unicode support
        Return Encoding.ASCII.GetString(ReadBytes(address, length))
    End Function

    Public Function ReadStringAdvanced(address As Integer, Optional maxStringLength As Integer = 1000) As String
        'No unicode support
        Dim result As String = Nothing
        Dim currentByte As Byte = 0

        For i As Integer = 0 To maxStringLength - 1
            currentByte = ReadByte(address + i)

            If currentByte = &H0 Then
                Exit For
            Else
                result += ChrW(currentByte)

            End If
        Next

        Return result
    End Function

    Public Function ReadFloat(address As Integer) As Single
        Return BitConverter.ToSingle(ReadBytes(address, 4), 0)
    End Function
#End Region
#Region "Scans"
    Public Function PatternScan(pattern As String) As Integer
        Dim splitPattern As String() = pattern.Split(" "c)
        Dim indexValid As Boolean() = New Boolean(splitPattern.Length - 1) {}
        Dim indexValue As Byte() = New Byte(splitPattern.Length - 1) {}

        Dim tempByte As Byte = CByte(&H0)

        For i As Integer = 0 To splitPattern.Length - 1
            indexValid(i) = Not (splitPattern(i) = "??" OrElse splitPattern(i) = "?")
            If [Byte].TryParse(splitPattern(i), tempByte) Then
                indexValue(i) = tempByte
            Else
                indexValid(i) = False
            End If
        Next

        Dim startOfMemory As Integer = attachedProcess.MainModule.BaseAddress.ToInt32()
        Dim endOfMemory As Integer = attachedProcess.MainModule.ModuleMemorySize

        For currentMemAddy As Integer = startOfMemory To endOfMemory - 1
            Dim complete As Boolean = False
            For i As Integer = 0 To splitPattern.Length - 1
                If Not indexValid(i) Then
                    Continue For
                End If

                tempByte = ReadByte(currentMemAddy + i)

                If tempByte <> indexValue(i) Then
                    Exit For
                End If

                If i = splitPattern.Length - 1 Then
                    complete = True
                End If

                If complete Then
                    Exit For
                End If
            Next

            If complete Then
                Return currentMemAddy
            End If
        Next

        Throw New Exception("Pattern not found!")
        Return 0
    End Function
#End Region
#End Region

    Private NotInheritable Class Win32
        Private Sub New()
        End Sub
        Public NotInheritable Class NativeMethods
            Private Sub New()
            End Sub
#Region "IsWow64Process"
            Public Shared Function IsWow64Process(handel As IntPtr) As Boolean
                Dim isTarget64Bit As Boolean = False
                IsWow64Process(handel, isTarget64Bit)
                Return isTarget64Bit
            End Function

            <DllImport("kernel32.dll", SetLastError:=True, CallingConvention:=CallingConvention.Winapi)> _
            Private Shared Function IsWow64Process(<[In]> process As IntPtr, <Out> ByRef wow64Process As Boolean) As <MarshalAs(UnmanagedType.Bool)> Boolean
            End Function
#End Region
        End Class

        Public NotInheritable Class x64
            Private Sub New()
            End Sub
            <DllImport("kernel32.dll", SetLastError:=True)> _
            Public Shared Function VirtualProtectEx(hProcess As IntPtr, lpAddress As Long, dwSize As UInt32, flNewProtect As UInteger, ByRef lpflOldProtect As UInteger) As Boolean
            End Function

            Public Declare Function ZwProtectVirtualMemory _
               Lib "ntdll.dll" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal RegionSize As Long, _
                                ByVal NewProtect As Long, _
                                ByVal OldProtect As Long) As Long
            Public Const PAGE_READWRITE As Long = &H4
            Public Const PAGE_GUARD As Long = &H100
            Public Const PAGE_EXECUTE As Long = &H10

            Public Declare Function ZwWriteVirtualMemory _
               Lib "NTDLL.DLL" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal pBuffer As Long, _
                                ByVal NumberOfBytesToWrite As Long, _
                                ByRef NumberOfBytesWritten As Long) As Long

            <DllImport("kernel32.dll")> _
            Public Shared Function ReadProcessMemory(hProcess As IntPtr, lpBaseAddress As Long, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function

            <DllImport("kernel32.dll")> _
            Public Shared Function WriteProcessMemory(hProcess As IntPtr, lpBaseAddress As Long, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function
        End Class

        Public NotInheritable Class x86
            Private Sub New()
            End Sub
            <DllImport("kernel32.dll", SetLastError:=True)> _
            Public Shared Function VirtualProtectEx(hProcess As IntPtr, lpAddress As Integer, dwSize As UInt32, flNewProtect As UInteger, ByRef lpflOldProtect As UInteger) As Boolean
            End Function

            Public Declare Function ZwProtectVirtualMemory _
               Lib "ntdll.dll" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal RegionSize As Long, _
                                ByVal NewProtect As Long, _
                                ByVal OldProtect As Long) As Long
            Public Const PAGE_READWRITE As Long = &H4
            Public Const PAGE_GUARD As Long = &H100
            Public Const PAGE_EXECUTE As Long = &H10

            Public Declare Function ZwWriteVirtualMemory _
               Lib "NTDLL.DLL" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal pBuffer As Long, _
                                ByVal NumberOfBytesToWrite As Long, _
                                ByRef NumberOfBytesWritten As Long) As Long

            <DllImport("kernel32.dll")> _
            Public Shared Function ReadProcessMemory(hProcess As IntPtr, lpBaseAddress As Integer, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function

            <DllImport("kernel32.dll")> _
            Public Shared Function WriteProcessMemory(hProcess As IntPtr, lpBaseAddress As Integer, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function
        End Class
    End Class
End Class

Code:
    Dim mem = New Memory()
        If mem.Open_pHandel("main") Then
            mem.WriteByte(address, 1 , true)
        End If
Quote Originally Posted by JVN View Post
Code:
Class Memory
    Private pHandel As IntPtr = IntPtr.Zero
    Private attachedProcess As Process = Nothing
    Private buffer As Byte()

    Public Function Open_pHandel(processName As String) As Boolean
        Dim proc As Process() = Process.GetProcessesByName(processName)

        If proc.Length = 0 Then
            Return False
        ElseIf proc.Length > 1 Then
            Throw New Exception("More then one process found.")
        Else
            attachedProcess = proc(0)
            pHandel = proc(0).Handle
            Return True
        End If
    End Function

#Region "x86"
#Region "Write"
    Public Function WriteBytes(address As Integer, value As Byte(), Optional virtualProtect As Boolean = False) As Boolean
        Dim countOfUsed As Integer = 0
        Dim result As Boolean = False
        Dim oldProtection As UInteger = 0
        Dim value2 as Long

        If virtualProtect Then
            Win32.x86.ZwProtectVirtualMemory(pHandel, address, CUInt(value.Length), &H4, oldProtection)
        End If

        result = Win32.x86.ZwWriteVirtualMemory(pHandel, address, value2, CUInt(value.Length), countOfUsed)

        If virtualProtect Then
            Win32.x86.ZwProtectVirtualMemory(pHandel, address, CUInt(value.Length), oldProtection, oldProtection)
        End If

        Return result
    End Function

    Public Function WriteInt(address As Integer, value As Integer, Optional virtualProtect As Boolean = False) As Boolean
        buffer = BitConverter.GetBytes(value)
        Return WriteBytes(address, buffer, virtualProtect)
    End Function

    Public Function WriteByte(address As Integer, value As Byte, Optional virtualProtect As Boolean = False) As Boolean
        buffer = New Byte() {value}
        Return WriteBytes(address, buffer, virtualProtect)
    End Function

    Public Function WriteString(address As Integer, value As String, Optional virtualProtect As Boolean = False) As Boolean
        buffer = Encoding.ASCII.GetBytes(value)
        'No unicode support atm
        Return WriteBytes(address, buffer, virtualProtect)
    End Function

    Public Function WriteFloat(address As Integer, value As Single, Optional virtualProtect As Boolean = False) As Boolean
        buffer = BitConverter.GetBytes(value)
        Return WriteBytes(address, buffer, virtualProtect)
    End Function
#End Region
#Region "Read"
    Public Function ReadBytes(address As Integer, length As Integer) As Byte()
        Dim readBytes__1 As Byte() = New Byte(length - 1) {}
        Dim numBytesChanged As Integer = 0

        Win32.x86.ReadProcessMemory(pHandel, address, readBytes__1, CUInt(length), numBytesChanged)

        Return readBytes__1
    End Function

    Public Function ReadInt(address As Integer) As Integer
        Return BitConverter.ToInt32(ReadBytes(address, 4), 0)
    End Function

    Public Function ReadByte(address As Integer) As Byte
        Return ReadBytes(address, 1)(0)
    End Function

    Public Function ReadString(address As Integer, length As Integer) As String
        'No unicode support
        Return Encoding.ASCII.GetString(ReadBytes(address, length))
    End Function

    Public Function ReadStringAdvanced(address As Integer, Optional maxStringLength As Integer = 1000) As String
        'No unicode support
        Dim result As String = Nothing
        Dim currentByte As Byte = 0

        For i As Integer = 0 To maxStringLength - 1
            currentByte = ReadByte(address + i)

            If currentByte = &H0 Then
                Exit For
            Else
                result += ChrW(currentByte)

            End If
        Next

        Return result
    End Function

    Public Function ReadFloat(address As Integer) As Single
        Return BitConverter.ToSingle(ReadBytes(address, 4), 0)
    End Function
#End Region
#Region "Scans"
    Public Function PatternScan(pattern As String) As Integer
        Dim splitPattern As String() = pattern.Split(" "c)
        Dim indexValid As Boolean() = New Boolean(splitPattern.Length - 1) {}
        Dim indexValue As Byte() = New Byte(splitPattern.Length - 1) {}

        Dim tempByte As Byte = CByte(&H0)

        For i As Integer = 0 To splitPattern.Length - 1
            indexValid(i) = Not (splitPattern(i) = "??" OrElse splitPattern(i) = "?")
            If [Byte].TryParse(splitPattern(i), tempByte) Then
                indexValue(i) = tempByte
            Else
                indexValid(i) = False
            End If
        Next

        Dim startOfMemory As Integer = attachedProcess.MainModule.BaseAddress.ToInt32()
        Dim endOfMemory As Integer = attachedProcess.MainModule.ModuleMemorySize

        For currentMemAddy As Integer = startOfMemory To endOfMemory - 1
            Dim complete As Boolean = False
            For i As Integer = 0 To splitPattern.Length - 1
                If Not indexValid(i) Then
                    Continue For
                End If

                tempByte = ReadByte(currentMemAddy + i)

                If tempByte <> indexValue(i) Then
                    Exit For
                End If

                If i = splitPattern.Length - 1 Then
                    complete = True
                End If

                If complete Then
                    Exit For
                End If
            Next

            If complete Then
                Return currentMemAddy
            End If
        Next

        Throw New Exception("Pattern not found!")
        Return 0
    End Function
#End Region
#End Region

    Private NotInheritable Class Win32
        Private Sub New()
        End Sub
        Public NotInheritable Class NativeMethods
            Private Sub New()
            End Sub
#Region "IsWow64Process"
            Public Shared Function IsWow64Process(handel As IntPtr) As Boolean
                Dim isTarget64Bit As Boolean = False
                IsWow64Process(handel, isTarget64Bit)
                Return isTarget64Bit
            End Function

            <DllImport("kernel32.dll", SetLastError:=True, CallingConvention:=CallingConvention.Winapi)> _
            Private Shared Function IsWow64Process(<[In]> process As IntPtr, <Out> ByRef wow64Process As Boolean) As <MarshalAs(UnmanagedType.Bool)> Boolean
            End Function
#End Region
        End Class

        Public NotInheritable Class x64
            Private Sub New()
            End Sub
            <DllImport("kernel32.dll", SetLastError:=True)> _
            Public Shared Function VirtualProtectEx(hProcess As IntPtr, lpAddress As Long, dwSize As UInt32, flNewProtect As UInteger, ByRef lpflOldProtect As UInteger) As Boolean
            End Function

            Public Declare Function ZwProtectVirtualMemory _
               Lib "ntdll.dll" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal RegionSize As Long, _
                                ByVal NewProtect As Long, _
                                ByVal OldProtect As Long) As Long
            Public Const PAGE_READWRITE As Long = &H4
            Public Const PAGE_GUARD As Long = &H100
            Public Const PAGE_EXECUTE As Long = &H10

            Public Declare Function ZwWriteVirtualMemory _
               Lib "NTDLL.DLL" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal pBuffer As Long, _
                                ByVal NumberOfBytesToWrite As Long, _
                                ByRef NumberOfBytesWritten As Long) As Long

            <DllImport("kernel32.dll")> _
            Public Shared Function ReadProcessMemory(hProcess As IntPtr, lpBaseAddress As Long, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function

            <DllImport("kernel32.dll")> _
            Public Shared Function WriteProcessMemory(hProcess As IntPtr, lpBaseAddress As Long, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function
        End Class

        Public NotInheritable Class x86
            Private Sub New()
            End Sub
            <DllImport("kernel32.dll", SetLastError:=True)> _
            Public Shared Function VirtualProtectEx(hProcess As IntPtr, lpAddress As Integer, dwSize As UInt32, flNewProtect As UInteger, ByRef lpflOldProtect As UInteger) As Boolean
            End Function

            Public Declare Function ZwProtectVirtualMemory _
               Lib "ntdll.dll" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal RegionSize As Long, _
                                ByVal NewProtect As Long, _
                                ByVal OldProtect As Long) As Long
            Public Const PAGE_READWRITE As Long = &H4
            Public Const PAGE_GUARD As Long = &H100
            Public Const PAGE_EXECUTE As Long = &H10

            Public Declare Function ZwWriteVirtualMemory _
               Lib "NTDLL.DLL" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal pBuffer As Long, _
                                ByVal NumberOfBytesToWrite As Long, _
                                ByRef NumberOfBytesWritten As Long) As Long

            <DllImport("kernel32.dll")> _
            Public Shared Function ReadProcessMemory(hProcess As IntPtr, lpBaseAddress As Integer, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function

            <DllImport("kernel32.dll")> _
            Public Shared Function WriteProcessMemory(hProcess As IntPtr, lpBaseAddress As Integer, <[In], Out> buffer As Byte(), size As UInt32, ByRef lpNumberOfBytesWritten As Integer) As Boolean
            End Function
        End Class
    End Class
End Class

Code:
    Dim mem = New Memory()
        If mem.Open_pHandel("main") Then
            mem.WriteByte(address, 1 , true)
        End If
you gonna give credits, or nah?
Quote Originally Posted by Silent View Post


you gonna give credits, or nah?

Sorry if you misunderstood, I do not want to say that this template is mine, I got it on your forum thread and just tried to adapt my needs.
Can someone help me ?
found this reply somewere, might help
WriteProcessMemory attempts (and in this case does) to modify the virtual memory protection on the virtual memory to ensure write access is granted (it also flushes the instruction cache of the process by calling ZwFlushInstructionCache), ZwWriteVirtualMemory does not.

If you want to use ZwWriteVirtualMemory then you need to change the memory protection of the virtual memory to grant yourself write access.
Quote Originally Posted by Sazor98 View Post
found this reply somewere, might help
Could you explain a little?
Somebody help me, please
Quote Originally Posted by JVN View Post
Somebody help me, please
He clearly said you need to change the virtual page to allow write access.
I.E. Use ZwProtectVirtualMemory ( If you want low level calls ) before using ZwWriteVirtualMemory. ( Make sure both are imported successfully. )

If one call fails, your parameters are incorrect in which case you'd need to debug why yourself.

QuickTip: Make sure your process token allows write access.
Quote Originally Posted by Hitokiri~ View Post


He clearly said you need to change the virtual page to allow write access.
I.E. Use ZwProtectVirtualMemory ( If you want low level calls ) before using ZwWriteVirtualMemory. ( Make sure both are imported successfully. )

If one call fails, your parameters are incorrect in which case you'd need to debug why yourself.

QuickTip: Make sure your process token allows write access.
This is where you're friend, I know I have to remove the memory protection first. That's where I come to the forum to ask you for help, I'm not able to remove this protection, I do not know what I'm doing wrong, the process is correct, the address is too, I do not know what it can be.

Code:
Public Declare Function ZwProtectVirtualMemory _
               Lib "ntdll.dll" (ByVal ProcessHandle As Long, _
                                ByVal BaseAddress As Long, _
                                ByVal RegionSize As Long, _
                                ByVal NewProtect As Long, _
                                ByVal OldProtect As Long) As Long
Public Const PAGE_READWRITE As Long = &H4
Public Const PAGE_GUARD As Long = &H100
Public Const PAGE_EXECUTE As Long = &H10
Quote Originally Posted by Hitokiri~ View Post
LINK
Check this out.
I tried to apply this code in VB.NET and did not succeed.
Posts 1–13 of 13 · Page 1 of 1

Post a Reply

Tags for this Thread

None

Need help?