?
Solved

Need native Windows NT API to either delete, rename or move a read-ony file on boot up

Posted on 2011-03-19
2
Medium Priority
?
738 Views
Last Modified: 2013-12-04
I wrote a simple program using DDK that smss.exe fires off. It deletes the specified file and outputs the results to the blue screen before login. It works fine as long as the file is not read-only. From what I have read, this is normal behavior. I figured the work around is to change the attributes of the file before it is deleted, rename the file or move the file. The problem is that I cannot seem to find much info on this. I think I can use NtOpenFile, NtQueryInformationFile and NtSetInformationFile to rename or change attributes, but not sure how. Any help would be appreciated.

Here is the working code for deleting files that are not read-only:
//nt.c

#include "ntddk.h"
#include "nt.h"  

HANDLE Heap;
PWCHAR fileNameStringBuffer;
RTL_HEAP_DEFINITION  heapParams;
UNICODE_STRING filePathString;
OBJECT_ATTRIBUTES ObjectAttributes;
UNICODE_STRING del_SUCCEEDED,del_ERROR;
PWCHAR success_stringBuffer,error_stringbuffer; 

void kill(PWCHAR name){        
	NTSTATUS status;         
	filePathString.Buffer=fileNameStringBuffer;        
	filePathString.Length=wcslen( name ) * sizeof(WCHAR);         
	filePathString.MaximumLength=filePathString.Length + sizeof(WCHAR);        
	ObjectAttributes.Length = sizeof(OBJECT_ATTRIBUTES);        
	ObjectAttributes.RootDirectory=NULL;        
	ObjectAttributes.ObjectName=&filePathString;        
	ObjectAttributes.Attributes = OBJ_CASE_INSENSITIVE| OBJ_INHERIT;         
	ObjectAttributes.SecurityQualityOfService=NULL;        
	ObjectAttributes.SecurityDescriptor=NULL;        
	status=NtDeleteFile(&ObjectAttributes);        

	if ((NTSTATUS)(status) >= 0) {                  
		NtDisplayString(&filePathString);                  
		NtDisplayString(&del_SUCCEEDED);        
	}else{
		NtDisplayString(&del_ERROR);        
	}

}

void NtProcessStartup( PSTARTUP_ARGUMENT Argument){                   
	memset( &heapParams, 0, sizeof( RTL_HEAP_DEFINITION ));        
	heapParams.Length = sizeof( RTL_HEAP_DEFINITION );        
	Heap = RtlCreateHeap( 2, 0, 0x100000, 0x1000, 0, &heapParams );         
	fileNameStringBuffer= RtlAllocateHeap( Heap, 0, 256 );        
	success_stringBuffer=RtlAllocateHeap(Heap,0,20);        
	success_stringBuffer=L"....Deleted!\n";        
	del_SUCCEEDED.Buffer=success_stringBuffer;        
	del_SUCCEEDED.Length=wcslen( success_stringBuffer ) * sizeof(WCHAR);         
	del_SUCCEEDED.MaximumLength = del_SUCCEEDED.Length + sizeof(WCHAR);         
	error_stringbuffer=RtlAllocateHeap(Heap,0,20);        
	error_stringbuffer=L"....ERROR!\n";        
	del_ERROR.Buffer=error_stringbuffer;        
	del_ERROR.Length=wcslen(error_stringbuffer) * sizeof(WCHAR);        
	del_ERROR.MaximumLength = del_ERROR.Length + sizeof(WCHAR);         
	fileNameStringBuffer=L"\\??\\c:\\test\\test.exe";        
	kill(fileNameStringBuffer);          
	RtlFreeHeap( Heap, 0, fileNameStringBuffer );           
	NtTerminateProcess( NtCurrentProcess(), 0 );
}

Open in new window

//nt.h
typedef struct {
	ULONG Unknown[21];
	UNICODE_STRING CommandLine; 
	UNICODE_STRING ImageFile;
} ENVIRONMENT_INFORMATION, *PENVIRONMENT_INFORMATION;


//// This structure is passed as NtProcessStartup's parameter
typedef struct {        
	ULONG Unknown[3];        
	PENVIRONMENT_INFORMATION  Environment;
} STARTUP_ARGUMENT, *PSTARTUP_ARGUMENT;


//// Data structure for heap definition. This includes various
// sizing parameters and callback routines, which, if left NULL,
// result in default behavior
typedef struct {        
	ULONG Length;        
	ULONG Unknown[11];
} RTL_HEAP_DEFINITION, *PRTL_HEAP_DEFINITION;

//Native NT API functions

NTSTATUS NTAPI NtTerminateProcess(HANDLE ProcessHandle, LONG ExitStatus);

NTSTATUS NTAPI NtDisplayString(PUNICODE_STRING String);

HANDLE NTAPI RtlCreateHeap(ULONG Flags, PVOID BaseAddress, ULONG SizeToReserve, ULONG SizeToCommit, PVOID Unknown,PRTL_HEAP_DEFINITION Definition);

PVOID NTAPI RtlAllocateHeap(HANDLE Heap, ULONG Flags, ULONG Size);

BOOLEAN NTAPI RtlFreeHeap(HANDLE Heap, ULONG Flags, PVOID Address);

NTSYSAPI NTSTATUS NTAPI NtDeleteFile(IN POBJECT_ATTRIBUTES ObjectAttributes);

Open in new window

0
Comment
Question by:advcom
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 19

Accepted Solution

by:
mrwad99 earned 2000 total points
ID: 35179402
Have you looked at http://www.osronline.com/article.cfm?article=85, which talks about the rename operation in detail?
0
 

Author Closing Comment

by:advcom
ID: 35181478
thats what I needed, thanks
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this post we will learn how to make Android Gesture Tutorial and give different functionality whenever a user Touch or Scroll android screen.
Computer science students often experience many of the same frustrations when going through their engineering courses. This article presents seven tips I found useful when completing a bachelors and masters degree in computing which I believe may he…
An introduction to basic programming syntax in Java by creating a simple program. Viewers can follow the tutorial as they create their first class in Java. Definitions and explanations about each element are given to help prepare viewers for future …
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question