Erase PE Header
Hey guys, i am trying to do a erase pe header function in vb, here is my code (It doesn't works) can you help me out to find the problem? :/
How i use it
I think the problem come from IntPtr but i don't really know why, could you explain me a little bit how IntPtr & UIntPtr work in this little exemple?
- - - Updated - - -
Fixed.
Code:
Private Function ErasePEHeader(ByVal hModule As IntPtr, ByVal procName As String) As Integer
Dim imagentheaderptr As Byte() = New Byte(3) {}
Dim Stub As Byte() = New Byte(119) {}
Dim Stub2 As Byte() = New Byte(263) {}
Dim Out2 As Integer, Out As Integer = 0
Dim proc As IntPtr = OpenProcess(2035711, False, Process.GetProcessesByName(procName)(0).Id)
Dim IMAGE_NT_HEADER As IntPtr = New IntPtr((hModule.ToInt32() + 60)), out22 As IntPtr = IntPtr.Zero
ReadProcessMemory(proc, IMAGE_NT_HEADER, imagentheaderptr, 4, out2)
If (WriteProcessMemory(proc, hModule, Stub, 120, Out2) = True) AndAlso (WriteProcessMemory(proc, hModule, Stub2, 256, Out2) = True) Then
Return Out + Out2 Else Return 0
MsgBox("Done")
End Function
Code:
Dim processId As Integer = targets(0).Id Dim hModule As IntPtr = IntPtr.Zero ErasePEHeader(hModule, processId)
- - - Updated - - -
Fixed.
