Memory cloaking driver 2 (Windows 7)

Wanted: Windows 7 device driver (ring 0) C source code that can be used to cloak memory in a userland process. Goal: Patching a userland process .IMAGE (code redirection/hooking) that has internal CRC self-checks -> Bypassing them. Driver must work on Windows 7 64bits (-> driver signing bypass + patchguard disabled -> no problem)


1. Userland application creates & starts memory cloaking service (driver)

2. Userland application launches target (CreateProcess)

3. Userland application calls driver -> CloakVirtualMemoryOnRead( hTargetProcess, dwVMemStart, dwVMemEnd, pFakeMem )

Memory is now cloaked, that means:

1. Reading the protected virtual memory will trigger a (forced) PAGE_FAULT

2. The PAGE handler decides whether the PAGE request was OnRead or OnExecute

2a. OnRead: Redirect the request to pFakeMem (cloak)

2b. OnExecute: Return the "real" memory (e.g. patched)

The userland application should be unable to detect the .CODE patches by reading them directly (internal = direct access) nor by the use of ReadProcessMemory for instance.

Pay on deliver. No cash in advance/scam possible.

Compétences : Assembly, Programmation C

en voir plus : memory cloaking, virtual device, self programming, programming on windows, programming in assembly, goal programming, driver 1, assembly service, assembly process, assembly direct, cloak process windows, Windows Driver, windows 7, windows 2012, patching, memory, driver, device driver, code signing, cash advance, bypass patchguard, windows virtual driver, windows service application, patched, patchguard bypass

Concernant l'employeur :
( 0 commentaires ) Stuttgart, Germany

Nº du projet : #1673232

4 freelance font une offre moyenne de $2000 pour ce travail


Hi, your requirements are clear but I'm not sure if they are achievable. The main problem is in that isn't possible to differ whether memory access was made for generic read or for CRC calculation. If the target proces Plus

%bids___i_sum_sub_35% %project_currencyDetails_sign_sub_36% USD en 10 jours
(15 Commentaires)

Custom Software Development - <b><i>Removed by Admin</i></b>

%bids___i_sum_sub_32% %project_currencyDetails_sign_sub_33% USD en 1 jour
(0 Commentaires)

I can do it very well. Nothing is impossible.

%bids___i_sum_sub_35% %project_currencyDetails_sign_sub_36% USD en 10 jours
(0 Commentaires)

Please check my PM

%bids___i_sum_sub_35% %project_currencyDetails_sign_sub_36% USD en 20 jours
(0 Commentaires)