-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathfakews_exe.dpr
62 lines (58 loc) · 1.72 KB
/
fakews_exe.dpr
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
program fakews_exe;
{$APPTYPE CONSOLE}
uses
SysUtils, uallHook, uallUtil, Windows;
function RunProcess(FileName: string; ShowCmd: DWORD; wait: Boolean; ProcID: PCardinal): Longword;
var
StartupInfo: TStartupInfo;
ProcessInfo: TProcessInformation;
begin
FillChar(StartupInfo, SizeOf(StartupInfo), #0);
StartupInfo.cb := SizeOf(StartupInfo);
StartupInfo.dwFlags := STARTF_USESHOWWINDOW or STARTF_FORCEONFEEDBACK;
StartupInfo.wShowWindow := ShowCmd;
if not CreateProcess(nil,
@Filename[1],
nil,
nil,
False,
CREATE_NEW_CONSOLE or
NORMAL_PRIORITY_CLASS,
nil,
nil,
StartupInfo,
ProcessInfo)
then
Result := WAIT_FAILED
else
begin
if wait = FALSE then
begin
if ProcID <> nil then ProcID^ := ProcessInfo.dwProcessId;
exit;
end;
WaitForSingleObject(ProcessInfo.hProcess, INFINITE);
GetExitCodeProcess(ProcessInfo.hProcess, Result);
end;
if ProcessInfo.hProcess <> 0 then
CloseHandle(ProcessInfo.hProcess);
if ProcessInfo.hThread <> 0 then
CloseHandle(ProcessInfo.hThread);
end;
var PID: Cardinal;
begin
if ParamCount() < 1 then begin
WriteLn(Output,'Parameters:');
WriteLn(Output, '1. Application to be executed.')
end
else begin
RunProcess(ParamStr(1), SW_RESTORE, FALSE, @PID);
WriteLn(Output, 'Injecting '+ExtractFilePath(ParamStr(0))+'fakews.dll');
if InjectLibrary(PID,pchar(ExtractFilePath(ParamStr(0))+'fakews.dll')) then begin
WriteLn(Output, 'Hook injected.');
end
else begin
WriteLn(Output, 'Hook failed!');
end;
end;
end.