Introduction - If you have any usage issues, please Google them yourself
Start, Run enter sigverif by checking the digital signature is not on the know of the ms. Win32API realize the main use of the application or driver to verify WinVerifyTrust API. If the API was Hook has no other way to verify whether the application or driver through Microsoft Signed? If merely being linked to the IAT, you can call directly through the function pointer. If it is used as the Detours as to alter the function jmp head, can be read in WinVerifyTrust Wintrust.dll realize the location, the restoration of function of the binary header. Do not know the use of CryptoAPI, and then use the specified certificate is not Microsoft a little better, not easy to be deceived by fear api tune hook, then he would write the code to verify, using openssl should be easy points.
Packet : 65520746shuziqianming_d7.rar filelist
uSimpleTrustCheck.dcu
Unit_main.ddp
Unit_main.dfm
Project2.dpr
Dir_Scan.pas
FileLoop_func.pas
Unit_main.pas
uSimpleTrustCheck.pas
Project2.dof
Project2.res
一个中英文记录delphi实现.txt
Project2.exe
Project2.cfg
Dir_Scan.dcu
File_func.dcu
Unit_main.dcu