当前位置:网站首页>3 ring kill 360 security guard process

3 ring kill 360 security guard process

2022-06-24 14:24:00 qq_ eight hundred and fifty-seven million three hundred and fiv

After a month of research , After killing the process, the driver can be loaded silently ,pac hijacked Contact in need .

Load the driver through a guard

BOOL IsElevatedAdministrator()
{
    
	BOOL fIsAdmin = FALSE;
	HANDLE hTokenToCheck = NULL;
	DWORD  lastErr;
	DWORD sidLen = SECURITY_MAX_SID_SIZE;
	BYTE localAdminsGroupSid[SECURITY_MAX_SID_SIZE];

	if (!CreateWellKnownSid(WinBuiltinAdministratorsSid, NULL,
		localAdminsGroupSid, &sidLen))
	{
    
		goto CLEANUP;
	}    
	if (CheckTokenMembership(hTokenToCheck, localAdminsGroupSid, &fIsAdmin))
	{
    
		lastErr = ERROR_SUCCESS;
	}

CLEANUP:             
	if (hTokenToCheck)
	{
    
		CloseHandle(hTokenToCheck);
		hTokenToCheck = NULL;
	}

	return (fIsAdmin);
}

原网站

版权声明
本文为[qq_ eight hundred and fifty-seven million three hundred and fiv]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/175/202206241213000162.html