Full C# Base
too stupid for a DeCompiler ^^CLR Injector:
CLR Injector
Code:
private static string GetHighestNetVersion()
{
string result = string.Empty;
string path = Path.Combine(Environment.GetEnvironmentVariable("WINDIR"), "Microsoft.NET\\Framework");
if (Directory.Exists(path))
{
IOrderedEnumerable<string> source =
from d in Directory.GetDirectories(path, "v*")
select Path.GetFileName(d) into d
orderby d descending
select d;
result = ((source.Count<string>() > 0) ? source.First<string>() : "");
}
return result;
}
public static bool Inject(int hProcess, uint pBootstrap, string dll, string DllMainPath)
{
bool result = false;
if (!string.IsNullOrEmpty(CLRInjector.__netversion))
{
if (!string.IsNullOrEmpty(DllMainPath))
{
if (hProcess > 0)
{
uint num = CLRInjector.MapBootstrap(hProcess, dll, DllMainPath, pBootstrap);
if (num > 0u)
{
int num2 = (int)WinAPI.RunThread(hProcess, num, 0u);
if (num2 != -1)
{
if (!(result = ((num2 & 255) == 0)))
{
CLRInjector.SetLastError((byte)(num2 & 255));
}
}
else
{
CLRInjector.SetLastError(37);
}
CLRInjector.CleanBootstrap(hProcess, num);
}
}
else
{
CLRInjector.SetLastError(36);
}
}
else
{
CLRInjector.SetLastError(40);
}
}
else
{
CLRInjector.SetLastError(39);
}
return result;
}
public static bool Inject(int pid, string pBootstrapDll, string dll, string DllMainPath)
{
bool flag = false;
if (!string.IsNullOrEmpty(CLRInjector.__netversion))
{
int num = WinAPI.OpenProcess(1082u, false, pid);
uint pBootstrap = 0u;
uint num2 = 0u;
if (num > 0)
{
uint num3 = WinAPI.CreateRemotePointer(num, Encoding.Unicode.GetBytes(pBootstrapDll + "\0"), 4);
uint procAddress = WinAPI.GetProcAddress(WinAPI.GetModuleHandleA("kernel32.dll"), "LoadLibraryW");
if (num3 > 0u && procAddress > 0u)
{
num2 = WinAPI.RunThread(num, procAddress, num3);
flag = (num2 > 0u && (pBootstrap = WinAPI.GetProcAddressEx(num, num2, "_BootstrapDll@20")) > 0u);
WinAPI.VirtualFreeEx(num, num3, 0, 32768);
}
else
{
CLRInjector.SetLastError(33);
}
if (flag)
{
flag = CLRInjector.Inject(num, pBootstrap, dll, DllMainPath);
uint procAddress2 = WinAPI.GetProcAddress(WinAPI.GetModuleHandleA("kernel32.dll"), "FreeLibrary");
WinAPI.RunThread(num, procAddress2, num2);
}
else
{
CLRInjector.SetLastError(38);
}
WinAPI.CloseHandle(num);
}
else
{
CLRInjector.SetLastError(36);
}
}
else
{
CLRInjector.SetLastError(39);
}
return flag;
}
private static void CleanBootstrap(int hProcess, uint pAlloc)
{
for (int i = 0; i < CLRInjector.__patchAddresses.Length - 1; i++)
{
int num = CLRInjector.__patchAddresses[i];
uint lpAddress = BitConverter.ToUInt32(WinAPI.ReadRemoteMemory(hProcess, (uint)((ulong)pAlloc + (ulong)((long)num)), 4u), 0);
WinAPI.VirtualFreeEx(hProcess, lpAddress, 0, 32768);
}
WinAPI.VirtualFreeEx(hProcess, pAlloc, 0, 32768);
}
private static uint MapBootstrap(int hProcess, string dll, string classtype, uint pBootstrap)
{
uint value = WinAPI.CreateRemotePointer(hProcess, Encoding.Unicode.GetBytes(dll), 4);
uint value2 = WinAPI.CreateRemotePointer(hProcess, Encoding.Unicode.GetBytes(classtype), 4);
uint value3 = WinAPI.CreateRemotePointer(hProcess, Encoding.Unicode.GetBytes(CLRInjector.__netversion), 4);
uint value4 = WinAPI.CreateRemotePointer(hProcess, Encoding.Unicode.GetBytes("DllMain"), 4);
uint num = WinAPI.VirtualAllocEx(hProcess, 0u, CLRInjector.__asmStub.Length, 12288, 64);
if (num > 0u)
{
byte[][] array = new byte[][]
{
BitConverter.GetBytes(value3),
BitConverter.GetBytes(value4),
BitConverter.GetBytes(value2),
BitConverter.GetBytes(value),
BitConverter.GetBytes(pBootstrap - (num + 30u))
};
if (!array.Any((byte[] b) => BitConverter.ToUInt32(b, 0) == 0u))
{
for (int i = 0; i < CLRInjector.__patchAddresses.Length; i++)
{
for (int j = 0; j < array[i].Length; j++)
{
CLRInjector.__asmStub[CLRInjector.__patchAddresses[i] + j] = array[i][j];
}
}
int num2 = 0;
if (!WinAPI.WriteProcessMemory(hProcess, num, CLRInjector.__asmStub, CLRInjector.__asmStub.Length, out num2) || num2 != CLRInjector.__asmStub.Length)
{
CLRInjector.CleanBootstrap(hProcess, num);
num = 0u;
}
else
{
CLRInjector.SetLastError(35);
}
}
else
{
CLRInjector.SetLastError(34);
}
}
else
{
CLRInjector.SetLastError(33);
}
return num;
}
}
}
Form1:
Form1
Code:
private void BrowseHack_Click(object sender, EventArgs e)
{
if (this.OpenDllFiles.ShowDialog() == DialogResult.OK)
{
this.HackDllPath.Text = this.OpenDllFiles.FileName;
}
}
private void BrowseBootstrap_Click(object sender, EventArgs e)
{
if (this.OpenDllFiles.ShowDialog() == DialogResult.OK)
{
this.BootstrapDllPath.Text = this.OpenDllFiles.FileName;
}
}
private void AutoInject_CheckedChanged(object sender, EventArgs e)
{
this.InjectButton.Enabled = !this.AutoInject.Checked;
}
private void AutoInjection_Tick(object sender, EventArgs e)
{
this.TryInject();
}
private void InjectButton_Click(object sender, EventArgs e)
{
this.TryInject();
}
public void TryInject()
{
if (this.HackDllPath.Text == "")
{
this.Status.Text = "Waiting for Hack Dll";
}
else
{
if (this.BootstrapDllPath.Text == "")
{
this.Status.Text = "Waiting for Bootstrap Dll";
}
else
{
if (this.NameSpace.Text == "" || this.ClassName.Text == "")
{
this.Status.Text = "Waiting for NameSpace & Class";
}
else
{
if (Process.GetProcessesByName(this.ProcessName.Text).Length == 0)
{
this.Status.Text = "Waiting for: " + this.ProcessName.Text + ".exe";
}
else
{
this.AutoInjection.Enabled = false;
if (CLRInjector.Inject(Process.GetProcessesByName(this.ProcessName.Text)[0].Id, this.BootstrapDllPath.Text, this.HackDllPath.Text, this.NameSpace.Text + "." + this.ClassName.Text))
{
this.Status.Text = "Injection Success";
}
else
{
this.Status.Text = "Injection Failed";
}
if (this.ExitAfterInject.Checked)
{
Application.Exit();
}
}
}
}
}
}
WinAPI:
WinAPI
Code:
public static byte[] ReadRemoteMemory(int hProc, uint address, uint len)
{
byte[] array = new byte[len];
int num = 0;
if (!WinAPI.ReadProcessMemory(hProc, address, array, array.Length, out num) || (long)num != (long)((ulong)len))
{
array = null;
}
return array;
}
public static uint RunThread(int hProcess, uint lpStartAddress, uint lpParam)
{
uint result = 4294967295u;
int num = WinAPI.CreateRemoteThread(hProcess, 0, 0, lpStartAddress, lpParam, 0, 0);
if (num > 0)
{
if ((ulong)WinAPI.WaitForSingleObject(num, 1000) == 0uL)
{
WinAPI.GetExitCodeThread(num, out result);
}
}
return result;
}
public static uint CreateRemotePointer(int hProcess, byte[] pData, int flProtect)
{
uint num = 0u;
if (pData != null && hProcess > 0)
{
num = WinAPI.VirtualAllocEx(hProcess, 0u, pData.Length, 12288, flProtect);
int num2 = 0;
if (num == 0u || !WinAPI.WriteProcessMemory(hProcess, num, pData, pData.Length, out num2) || num2 != pData.Length)
{
WinAPI.VirtualFreeEx(hProcess, num, 0, 32768);
num = 0u;
}
}
return num;
}
public static uint GetProcAddressEx(int hProc, uint hModule, string lpProcName)
{
uint result = 0u;
byte[] array = WinAPI.ReadRemoteMemory(hProc, hModule, 64u);
if (array != null && BitConverter.ToUInt16(array, 0) == 23117)
{
uint num = BitConverter.ToUInt32(array, 60);
if (num > 0u)
{
byte[] array2 = WinAPI.ReadRemoteMemory(hProc, hModule + num, 264u);
if (array2 != null && BitConverter.ToUInt32(array2, 0) == 17744u)
{
uint num2 = BitConverter.ToUInt32(array2, 120);
if (num2 != 0u)
{
byte[] array3 = WinAPI.ReadRemoteMemory(hProc, hModule + num2, 40u);
uint num3 = BitConverter.ToUInt32(array3, 28);
uint num4 = BitConverter.ToUInt32(array3, 36);
uint num5 = BitConverter.ToUInt32(array3, 16);
int num6 = WinAPI.SearchExports(hProc, hModule, array3, lpProcName);
if (num3 > 0u && num4 > 0u && num6 > -1)
{
byte[] array4 = WinAPI.ReadRemoteMemory(hProc, (uint)((ulong)(hModule + num4) + (ulong)((long)((long)num6 << 1))), 2u);
int num7 = (array4 == null) ? -1 : ((int)BitConverter.ToUInt16(array4, 0));
if (num7 != -1)
{
byte[] array5 = WinAPI.ReadRemoteMemory(hProc, (uint)((ulong)(hModule + num3) + (ulong)((ulong)((long)num7 - (long)((ulong)(num5 - 1u))) << 2)), 4u);
if (array5 != null)
{
result = hModule + BitConverter.ToUInt32(array5, 0);
}
}
}
}
}
}
}
return result;
}
private static int SearchExports(int hProcess, uint hModule, byte[] exports, string name)
{
uint num = BitConverter.ToUInt32(exports, 24);
uint num2 = BitConverter.ToUInt32(exports, 32);
int num3 = -1;
if (num > 0u && num2 > 0u)
{
byte[] array = WinAPI.ReadRemoteMemory(hProcess, hModule + num2, num << 2);
if (array != null)
{
uint[] array2 = new uint[num];
for (int i = 0; i < array2.Length; i++)
{
array2[i] = BitConverter.ToUInt32(array, i << 2);
}
int num4 = 0;
int num5 = array2.Length - 1;
string text = string.Empty;
while (num4 <= num5 && num3 == -1)
{
int num6 = num4 + (num5 - num4) / 2;
text = WinAPI.AnsiStringFromPTR(hProcess, hModule + array2[num6]);
if (text.Equals(name))
{
num3 = num6;
}
else
{
if (text.CompareTo(name) < 0)
{
num4 = num6 - 1;
}
else
{
num5 = num6 + 1;
}
}
}
}
}
return num3;
}
private static string AnsiStringFromPTR(int hProcess, uint rva)
{
byte[] array = WinAPI.ReadRemoteMemory(hProcess, rva, 256u);
string text = string.Empty;
if (array != null)
{
text = Encoding.ASCII.GetString(array);
if (text.IndexOf('\0') > 0)
{
text = text.Substring(0, text.IndexOf('\0'));
}
}
return text;
}
}
}
It´s only C&P from a DeCompiler, you must fix it by yourself!

Similar Threads
Combat Arms Hack Coding / Programming / Source Code[noobproof]Nu11V0ids HotKey Base PLUS! FULL WORKING OPK/TELEKILL
100 Mission Against Terror DiscussionsPriview MAT XPS Based Full Fiture
3 CrossFire Hack Coding / Programming / Source Codefull hack info creating a simple hack with base for noobs like meAM 16 CrossFire Hack Coding / Programming / Source CodeFull base CF INDO 7 WarRock Hack Source CodeHeres my full baseTU 21



