ÄúÕýÔڲ鿴 "ÓÎÏ··ÖÎö" ·ÖÀàϵÄÎÄÕÂ
2009-02-25 13:23
// MainProcessDll.cpp : Defines the entry point for the DLL application.
//
#include <windows.h>
#include <stdlib.h>
#include <stdio.h>
char g_waiguaFullPath[0x100] = {0};
DWORD g_FunAddr = 0;
DWORD g_PatchFunc = 0;
DWORD g_PatchAllHookFun = 0;
DWORD g_CmdLen = 5;
BYTE g_Cmd[0x14] = {0};
LPVOID g_mem = NULL;
DWORD g_hookflag = 0;
WCHAR tt[] = L"tt";
typedef HANDLE (CA |
2009-02-16 11:29
¼ÙÉèÎÒÃÇÓÐÒ»¸öľÂí³ÌÐò£¬ËüÔËÐкó»áÊͷųöÒ»¸ödll£¬×¢Èëµ½ÓÎÏ·³ÌÐòÖÐÈ¥¡£ÏÖÔÚ£¬ÎÒÃÇÈç¹ûÒªµ÷ÊÔÕâ¸ödll£¬ÎÒÃǾÍÐèÒªÔÚÓÎÏ·½ø³ÌÖÐÀ¹½Øµ½Ëü£¬È»ºóÔÙµ÷ÊÔËüµÄ¹¦ÄÜ¡£
Òò´Ë£¬µ÷ÊԵIJ½Öè¾ÍÊÇ£º
1. Æô¶¯ÓÎÏ·£¬ÈÃÓÎÏ·Õý³£ÔËÐÐÆðÀ´¡£ÓÃOD¸½¼ÓÉÏ¡£
2. ϶Ïbp LoadLibraryA£¬Æô¶¯Ä¾Âí³ÌÐò¡£ÈÃÆädll×¢Èë¡£
3. ¶ÏϺó£¬ËµÃ÷×¢Èë³É¹¦.Õâ¸öʱºò¿ÉÒÔ¸ú×ÙľÂíÊͷųöµÄdllÔÚÓÎÏ·Öе͝×÷¡£
4. ¼ÌÐø¶ÏÏÂ×¢ÈëdllÖÐµÄÆäËûµ¼³öº¯Êý£¬½øÐе÷ÊÔ£¬Ã÷È·Æä¸÷¸öµ¼³öº¯Êý¡£
×¢£º |
2009-02-06 00:27
½üÀ´ÊÕµ½ÁËÒ»¸öÉñ»°ÂíµÄÑù±¾£¬´ÖÂԵĿ´ÁËËûµÄ¿ò¼Ü¡£»ù±¾Éϰüº¬3²¿·Ö¡£
1. Ò»¸öexeÔØÌå¡£ÓÃÓÚÊͷųöÒ»¸ödll,²¢»áͨ¹ýrundll32.exe¼ÓÔØdllÖеÄÒ»¸öµ¼³öº¯Êýins¡£
ÕâÀïΪÁËÒþ±Î£¬Ëû»á°ÑϵͳµÄrundll32.exe£¬copy³öÒ»·Ý£¬¸ÄÃûΪr05015.exe¡£ °Ñµ¼³öµÄdll·ÅÔÚÁÙʱĿ¼Ï£¬ºó׺Ϊ".~~~"µÄÁÙʱÎļþ.
2. ÔÚdllÖУ¬»áÓ³Ïñ½Ù³Örpcss.dll. Ëûµ¼³öÁËrpcss.dllµÄËùÓк¯Êý£¬²¢ÇҶർ³öÁËÒ»¸öinsº¯Êý¡£Õâ¸ödllº¯Êý£¬»áÒòΪ½Ù³Örpcss.dll·þÎñ£¬¸Ä±ä×¢²á±íÖеÄrpcss·þÎñ¼üÖµ£¬¶ø¿ª»ú×Ô¶¯¼ÓÔØ£¬²¢ÇһὫ×Ô |
2008-12-15 09:47
¡¾ÆÆÎıêÌâ¡¿QQ2008ÊäÈëÃÜÂë-TSSafeEdit-±£»¤ÆÆÊÍ·ÖÎö
¡¾¶Ô¡¡¡¡Ïó¡¿³õÈëÃŵÄÐÂÊÖ
¡¾ÏÂÔØµØÖ·¡¿www.qq.com
¡¾ÆÆ½â¹¤¾ß¡¿OD
¡¾±£»¤·½Ê½¡¿ÏûÏ¢¼ÓÃܱ£»¤
¡¾ÈΡ¡¡¡Îñ¡¿ÕÒ³öÔʼÏûÏ¢¼Ç¼´¥·¢µã
¡¾ÆÆÎÄ×÷Õß¡¿thomasyzh
¡¾×é¡¡¡¡Ö¯¡¿Ã»ÓÐ
¡¾ÆÆ½âÉùÃ÷¡¿ÕâÆªÆÆÎÄͼµÄÊÇËÙ¶È£¬ºÍ½â¾öÎÊÌâ---ûÓиü¼Ó¶àµÄÉîÈë·ÖÎö±£»¤·½Ê½-×ܹ²12Сʱ£¬3Ì죬ÿÌì4Сʱ
¡¾±¸¡¡¡¡×¢¡¿ÀÏÊÖÎð¿´£¬±ðÀË·ÑÄãµÄʱ¼ä
¡¾µç¡¡¡¡ÓÊ¡¿machinesy@163.com
¡¾ÆÆ½â¹ý³Ì¡¿
Ê×ÏÈ£¬ÒªÖªµÀÆä¶ÔÓÚÃÜÂëµÄ±£»¤·½Ê½¡£ÆäÓüüÅ̼Ǽ¾«Áé |
2008-08-22 17:13
½üÈÕ£¬µÃµ½ÁËÒ»¸öÈí¼þ£¬ÔÚÕâ¸öÈí¼þexeµÄ×ÊÔ´ÖУ¬±£´æ×ÅÁíÍâµÄ¿ÉÖ´ÐÐÄ£¿é£¬ÎÒÏëÌæ»»ÆäÖеÄÄ£¿é£¬Ì滻Ϊ×Ô¼ºµÄÄ£¿é¡£
ΪÁ˱ãÓÚÃèÊö£¬ÎÒ°ÑÒªÐÞ¸Ä×ÊÔ´µÄexe£¬³Æ×÷Ô´Îļþ£¬°ÑÒªÌæ»»½øÈ¡µÄÄ£¿éexe£¬³ÉΪĿ±êÄ£¿é¡£
°ì·¨ÈçÏ£º
1¡£ ±¸·ÝÏÂÔ´Îļþ£¬È»ºóÓÃvc´ò¿ªÒÔ×ÊÔ´µÄ·½Ê½´ò¿ªÔ´Îļþexe, ÕÒµ½ÒªÌæ»»µÄ×ÊÔ´¡£ÕÒµ½ºó£¬Ë«»÷´ò¿ª¡£
2¡£ ÓÃvcÒÔ¶þ½øÖƵķ½Ê½´ò¿ªÄ¿±êÄ£¿é£¬ÓÃÄ¿±êÄ£¿éµÄ¶þ½øÖÆÄÚÈÝ£¬Ìæ»»µ½1¡£
3¡£ Ìæ»»Íêºó£¬±£´æÔ´Îļþ¡£Í˳öÄ¿±êÄ£¿é¡£
4¡£ ÓÃStud_PE´ò¿ª±¸·ÝµÄÔ´ÎļþºÍÐ޸ĺóµÄÔ´Îļþ¡£¶ÔÕÕ×ű¸ |
2008-08-12 11:12
; ÅжÏÊÇ·ñÓÐÄں˵÷ÊÔÆ÷ÔÚµ÷ÊÔ, Èç¹ûÓе÷ÊÔÆ÷£¬Ôò¶Ï¿ª
; Èç¹ûûÓУ¬ÔòÖ±½Ó·µ»Ø
IsKernelDebugger proc near
jmp short L2
L1:
c |
2008-06-28 00:38
½ÓÉÏÆª£¬µ¥²½µ÷ÊÔÔĶÁmh1_.exe´úÂ룬»á·¢ÏÖ´ÓexeµÄ×ÊÔ´ÖÐÊͷųöÒ»¸ödllµ½ÏµÍ³Ä¿Â¼ÖУ¬exeµÄÖ÷Òª¹¦ÄܾÍÊÇͨ¹ý×¢²á±íдÈ뵱ǰexeµÄȫ·¾¶Ãû£¬Éú³ÉµÄdllµÄȫ·¾¶Ãû£¬»¹ÓÐÒ»¸öeventÃû¡£È»ºó¾ÍÊÇÖÕÖ¹µô "Twister.exe"£¬"FilMsg.exe"£¬ "my.exe"ÕâÈý¸ö½ø³Ì£¬½ÓÏÂÀ´¾ÍÊÇÆô¶¯Ò»¸öɱÈðÐǵÄỊ̈߳¬Æô¶¯Ò»¸öɱ¿¨°ÍµÄỊ̈߳¬×îºóµ÷ÓÃloadlibrary¼ÓÔØÉú³ÉµÄdll.
½ÓÏÂÀ´£¬ÎÒÃǾÍÊDZ¼ÈëÖ÷Ì⣬À´¿´ÏÂÓÐexeÉú³ÉµÄÕâ¸ö¾ßÓкËÐŦÄܵÄdll.ͬÑùÊÊÓÃpeid²ì¿Ç£¬·¢ÏÖ¸úexeÊÇͬÑùµÄ¿Ç¡£²½ÖèÈçÏ£º
1¡£ÓÃodÔØÈëϵͳĿ |
2008-06-27 23:30
1¡£ÓÃpeid¼ì²â¿Ç¡£

2¡£odÔØÈë
ºöÂÔµ¯³öµÄ´íÎóÌáʾ¡£¼ÌÐø¡£³ÌÐò¶ÏÔÚ
µ¥²½F8,ÔÙF8, À´µ½ÏÂͼλÖãº
|
|
|