ÖèÓê´òкÉ
» ÓοÍ:  ×¢²á | µÇ¼ | »áÔ± | ÉçÇøÒøÐÐ | ¹ÉƱÖÐÐÄ | °ïÖú

 

×÷Õß:
±êÌâ: ·ÀÖ¹ºÚ¿ÍÈëÇÖ£ºDLLºóÃÅÍêÈ«Çå³ý·½·¨ ÉÏÒ»Ö÷Ìâ | ÏÂÒ»Ö÷Ìâ
fff000
³¬¼¶°æÖ÷




»ý·Ö 18503
·¢Ìû 2582
×¢²á 2006-5-27
״̬ ÀëÏß
#1  ·ÀÖ¹ºÚ¿ÍÈëÇÖ£ºDLLºóÃÅÍêÈ«Çå³ý·½·¨

·ÀÖ¹ºÚ¿ÍÈëÇÖ£ºDLLºóÃÅÍêÈ«Çå³ý·½·¨£¨1£©
¡¡¡¡Ç°ÑÔ

¡¡¡¡ºóÃÅ!ÏàÐÅÕâ¸ö´ÊÓï¶ÔÄúÀ´ËµÒ»¶¨²»»áİÉú£¬ËüµÄΣº¦²»È»¶øÓû£¬µ«Ëæ×ÅÈËÃǵݲȫÒâʶÖð²½ÔöÇ¿£¬ÓÖ¼ÓÉÏɱ¶¾Èí¼þµÄ"´óÁ¦Ö§³Ö"£¬Ê¹´«Í³µÄºóÃÅÎÞ·¨ÔÚÒþ²Ø×Ô¼º£¬ÈκÎÉÔ΢ÓÐµã¼ÆËã»ú֪ʶµÄÈË£¬¶¼ÖªµÀ"²é¶Ë¿Ú""¿´½ø³Ì"£¬ÒԱ㷢ÏÖһЩ"ÖëË¿Âí¼£"¡£ËùÒÔ£¬ºóÃŵıàдÕß¼°Ê±µ÷ÕûÁË˼·£¬°ÑÄ¿¹â·Åµ½Á˶¯Ì¬Á´½Ó³ÌÐò¿âÉÏ£¬Ò²¾ÍÊÇ˵£¬°ÑºóÃÅ×ö³ÉDLLÎļþ£¬È»ºóÓÉijһ¸öEXE×öÎªÔØÌ壬»òÕßʹÓÃRundll32.exeÀ´Æô¶¯£¬ÕâÑù¾Í²»»áÓнø³Ì£¬²»¿ª¶Ë¿ÚµÈÌØµã£¬Ò²¾ÍʵÏÖÁ˽ø³Ì¡¢¶Ë¿ÚµÄÒþ²Ø¡£±¾ÎÄÒÔ"DLLµÄÔ­Àí""DLLµÄÇå³ý""DLLµÄ·À·¶"ΪÖ÷Ì⣬²¢Õ¹¿ªÂÛÊö£¬Ö¼ÔÚÄÜÈôó¼Ò¶ÔDLLºóÃÅ"¿ìËÙÉÏÊÖ"£¬²»ÔÚ¿Ö¾å DLLºóÃÅ¡£ºÃÁË£¬½øÈëÎÒÃǵÄÖ÷Ìâ¡£

¡¡¡¡Ò»¡¢DLLµÄÔ­Àí

¡¡¡¡1£¬¶¯Ì¬Á´½Ó³ÌÐò¿â

¡¡¡¡¶¯Ì¬Á´½Ó³ÌÐò¿â£¬È«³Æynamic Link Library£¬¼ò³ÆLL£¬×÷ÓÃÔÚÓÚΪӦÓóÌÐòÌṩÀ©Õ¹¹¦ÄÜ¡£Ó¦ÓóÌÐòÏëÒªµ÷ÓÃDLLÎļþ£¬ÐèÒª¸úÆä½øÐÐ"¶¯Ì¬Á´½Ó";´Ó±à³ÌµÄ½Ç¶È£¬Ó¦ÓóÌÐòÐèÒªÖªµÀDLLÎļþµ¼³öµÄAPIº¯Êý·½¿Éµ÷Óá£Óɴ˿ɼû£¬DLLÎļþ±¾Éí²¢²»¿ÉÒÔÔËÐУ¬ÐèÒªÓ¦ÓóÌÐòµ÷Óá£ÕýÒòΪDLLÎļþÔËÐÐʱ±ØÐë²åÈëµ½Ó¦ÓóÌÐòµÄÄÚ´æÄ£¿éµ±ÖУ¬Õâ¾Í˵Ã÷ÁËLLÎļþÎÞ·¨É¾³ý¡£ÕâÊÇÓÉÓÚWindowsÄÚ²¿»úÖÆÔì³ÉµÄ:ÕýÔÚÔËÐеijÌÐò²»Äܹرա£ËùÒÔ£¬DLLºóÃÅÓɴ˶øÉú!

¡¡¡¡2£¬DLLºóÃÅÔ­Àí¼°ÌØµã

¡¡¡¡°ÑÒ»¸öʵÏÖÁ˺óÃŹ¦ÄܵĴúÂëд³ÉÒ»¸öDLLÎļþ£¬È»ºó²åÈëµ½Ò»¸öEXEÎļþµ±ÖУ¬Ê¹Æä¿ÉÒÔÖ´ÐУ¬ÕâÑù¾Í²»ÐèÒªÕ¼Óýø³Ì£¬Ò²¾ÍûÓÐÏà¶ÔÓ¦µÄPIDºÅ£¬Ò²¾Í¿ÉÒÔÔÚÈÎÎñ¹ÜÀíÆ÷ÖÐÒþ²Ø¡£DLLÎļþ±¾ÉíºÍEXEÎļþÏà²î²»´ó£¬µ«±ØÐëʹÓóÌÐò(EXE)µ÷ÓòÅÄÜÖ´ÐÐDLLÎļþ¡£DLLÎļþµÄÖ´ÐУ¬ÐèÒªEXEÎļþ¼ÓÔØ£¬µ«EXEÏëÒª¼ÓÔØDLLÎļþ£¬ÐèÒªÖªµÀÒ»¸öDLLÎļþµÄÈë¿Úº¯Êý(¼ÈDLLÎļþµÄµ¼³öº¯Êý)£¬ËùÒÔ£¬¸ù¾ÝDLLÎļþµÄ±àд±ê×¼:EXE±ØÐëÖ´ÐÐDLL ÎļþÖеÄDLLMain()×÷Ϊ¼ÓÔØµÄÌõ¼þ(ÈçͬEXEµÄmian())¡£×öDLLºóÃÅ»ù±¾·ÖΪÁ½ÖÖ:1)°ÑËùÓй¦Äܶ¼ÔÚDLLÎļþÖÐʵÏÖ;2)°ÑDLL ×ö³ÉÒ»¸öÆô¶¯Îļþ£¬ÔÚÐèÒªµÄʱºòÆô¶¯Ò»¸öÆÕͨµÄEXEºóÃÅ¡£

¡¡¡¡³£¼ûµÄ±àд·½·¨:

¡¡¡¡(1)£¬Ö»ÓÐÒ»¸öDLLÎļþ

¡¡¡¡ÕâÀàºóÃźܼòµ¥£¬Ö»°Ñ×Ô¼º×ö³ÉÒ»¸öDLLÎļþ£¬ÔÚ×¢²á±íRun¼üÖµ»òÆäËû¿ÉÒÔ±»ÏµÍ³×Ô¶¯¼ÓÔØµÄµØ·½£¬Ê¹ÓÃRundll32.exeÀ´×Ô¶¯Æô¶¯¡£ Rundll32.exeÊÇʲô?¹ËÃû˼Ò⣬"Ö´ÐÐ32λµÄDLLÎļþ"¡£ËüµÄ×÷ÓÃÊÇÖ´ÐÐDLLÎļþÖеÄÄÚ²¿º¯Êý£¬ÕâÑùÔÚ½ø³Ìµ±ÖУ¬Ö»»áÓÐ Rundll32.exe£¬¶ø²»»áÓÐDLLºóÃŵĽø³Ì£¬ÕâÑù£¬¾ÍʵÏÖÁ˽ø³ÌÉϵÄÒþ²Ø¡£Èç¹û¿´µ½ÏµÍ³ÖÐÓжà¸öRundll32.exe£¬²»±Ø¾ª»Å£¬ÕâÖ¤Ã÷Óà Rundll32.exeÆô¶¯Á˶àÉÙ¸öµÄDLLÎļþ¡£µ±È»£¬ÕâЩRundll32.exeÖ´ÐеÄDLLÎļþÊÇʲô£¬ÎÒÃǶ¼¿ÉÒÔ´Óϵͳ×Ô¶¯¼ÓÔØµÄµØ·½ÕÒµ½¡£

¡¡¡¡ÏÖÔÚ£¬ÎÒÀ´½éÉÜÒ»ÏÂRundll32.exeÕâ¸öÎļþ£¬Òâ˼ÉϱßÒѾ­Ëµ¹ý£¬¹¦ÄܾÍÊÇÒÔÃüÁîÐеķ½Ê½µ÷Óö¯Ì¬Á´½Ó³ÌÐò¿â¡£ÏµÍ³Öл¹ÓÐÒ»¸öRundll.exeÎļþ£¬ËûµÄÒâ˼ÊÇ"Ö´ÐÐ16λµÄDLLÎļþ"£¬ÕâÀïҪעÒâһϡ£ÔÚÀ´¿´¿´Rundll32.exeʹÓõĺ¯ÊýÔ­ÐÍ: ɱ¶¾Èí¼þµÄ"´óÁ¦Ö§³Ö"£¬Ê¹´«Í³µÄºóÃÅÎÞ·¨ÔÚÒþ²Ø×Ô¼º£¬ÈκÎÉÔ΢ÓÐµã¼ÆËã»ú֪ʶµÄÈË£¬¶¼ÖªµÀ"²é¶Ë¿Ú""¿´½ø³Ì"£¬ÒԱ㷢ÏÖһЩ"ÖëË¿Âí¼£"¡£ËùÒÔ£¬ºóÃŵıàдÕß¼°Ê±µ÷ÕûÁË˼·£¬°ÑÄ¿¹â·Åµ½Á˶¯Ì¬Á´½Ó³ÌÐò¿âÉÏ£¬Ò²¾ÍÊÇ˵£¬°ÑºóÃÅ×ö³ÉDLLÎļþ£¬È»ºóÓÉijһ¸öEXE×öÎªÔØÌ壬»òÕßʹÓà Rundll32.exeÀ´Æô¶¯£¬ÕâÑù¾Í²»»áÓнø³Ì£¬²»¿ª¶Ë¿ÚµÈÌØµã£¬Ò²¾ÍʵÏÖÁ˽ø³Ì¡¢¶Ë¿ÚµÄÒþ²Ø¡£±¾ÎÄÒÔ"DLLµÄÔ­Àí""DLLµÄÇå³ý""DLLµÄ·À·¶"ΪÖ÷Ì⣬²¢Õ¹¿ªÂÛÊö£¬Ö¼ÔÚÄÜÈôó¼Ò¶ÔDLLºóÃÅ"¿ìËÙÉÏÊÖ"£¬²»ÔÚ¿Ö¾åDLLºóÃÅ¡£ºÃÁË£¬½øÈëÎÒÃǵÄÖ÷Ìâ¡£

¡¡¡¡Ò»¡¢DLLµÄÔ­Àí

¡¡¡¡1£¬¶¯Ì¬Á´½Ó³ÌÐò¿â

¡¡¡¡¶¯Ì¬Á´½Ó³ÌÐò¿â£¬È«³Æynamic Link Library£¬¼ò³ÆLL£¬×÷ÓÃÔÚÓÚΪӦÓóÌÐòÌṩÀ©Õ¹¹¦ÄÜ¡£Ó¦ÓóÌÐòÏëÒªµ÷ÓÃDLLÎļþ£¬ÐèÒª¸úÆä½øÐÐ"¶¯Ì¬Á´½Ó";´Ó±à³ÌµÄ½Ç¶È£¬Ó¦ÓóÌÐòÐèÒªÖªµÀDLLÎļþµ¼³öµÄAPIº¯Êý·½¿Éµ÷Óá£Óɴ˿ɼû£¬DLLÎļþ±¾Éí²¢²»¿ÉÒÔÔËÐУ¬ÐèÒªÓ¦ÓóÌÐòµ÷Óá£ÕýÒòΪDLLÎļþÔËÐÐʱ±ØÐë²åÈëµ½Ó¦ÓóÌÐòµÄÄÚ´æÄ£¿éµ±ÖУ¬Õâ¾Í˵Ã÷ÁËLLÎļþÎÞ·¨É¾³ý¡£ÕâÊÇÓÉÓÚWindowsÄÚ²¿»úÖÆÔì³ÉµÄ:ÕýÔÚÔËÐеijÌÐò²»Äܹرա£ËùÒÔ£¬DLLºóÃÅÓɴ˶øÉú!

¡¡¡¡2£¬DLLºóÃÅÔ­Àí¼°ÌØµã

¡¡¡¡°ÑÒ»¸öʵÏÖÁ˺óÃŹ¦ÄܵĴúÂëд³ÉÒ»¸öDLLÎļþ£¬È»ºó²åÈëµ½Ò»¸öEXEÎļþµ±ÖУ¬Ê¹Æä¿ÉÒÔÖ´ÐУ¬ÕâÑù¾Í²»ÐèÒªÕ¼Óýø³Ì£¬Ò²¾ÍûÓÐÏà¶ÔÓ¦µÄPIDºÅ£¬Ò²¾Í¿ÉÒÔÔÚÈÎÎñ¹ÜÀíÆ÷ÖÐÒþ²Ø¡£DLLÎļþ±¾ÉíºÍEXEÎļþÏà²î²»´ó£¬µ«±ØÐëʹÓóÌÐò(EXE)µ÷ÓòÅÄÜÖ´ÐÐDLLÎļþ¡£DLLÎļþµÄÖ´ÐУ¬ÐèÒªEXEÎļþ¼ÓÔØ£¬µ«EXEÏëÒª¼ÓÔØDLLÎļþ£¬ÐèÒªÖªµÀÒ»¸öDLLÎļþµÄÈë¿Úº¯Êý(¼ÈDLLÎļþµÄµ¼³öº¯Êý)£¬ËùÒÔ£¬¸ù¾ÝDLLÎļþµÄ±àд±ê×¼:EXE±ØÐëÖ´ÐÐDLL ÎļþÖеÄDLLMain()×÷Ϊ¼ÓÔØµÄÌõ¼þ(ÈçͬEXEµÄmian())¡£×öDLLºóÃÅ»ù±¾·ÖΪÁ½ÖÖ:1)°ÑËùÓй¦Äܶ¼ÔÚDLLÎļþÖÐʵÏÖ;2)°ÑDLL ×ö³ÉÒ»¸öÆô¶¯Îļþ£¬ÔÚÐèÒªµÄʱºòÆô¶¯Ò»¸öÆÕͨµÄEXEºóÃÅ¡£

¡¡¡¡³£¼ûµÄ±àд·½·¨:

¡¡¡¡(1)£¬Ö»ÓÐÒ»¸öDLLÎļþ

¡¡¡¡ÕâÀàºóÃźܼòµ¥£¬Ö»°Ñ×Ô¼º×ö³ÉÒ»¸öDLLÎļþ£¬ÔÚ×¢²á±íRun¼üÖµ»òÆäËû¿ÉÒÔ±»ÏµÍ³×Ô¶¯¼ÓÔØµÄµØ·½£¬Ê¹ÓÃRundll32.exeÀ´×Ô¶¯Æô¶¯¡£ Rundll32.exeÊÇʲô?¹ËÃû˼Ò⣬"Ö´ÐÐ32λµÄDLLÎļþ"¡£ËüµÄ×÷ÓÃÊÇÖ´ÐÐDLLÎļþÖеÄÄÚ²¿º¯Êý£¬ÕâÑùÔÚ½ø³Ìµ±ÖУ¬Ö»»áÓÐ Rundll32.exe£¬¶ø²»»áÓÐDLLºóÃŵĽø³Ì£¬ÕâÑù£¬¾ÍʵÏÖÁ˽ø³ÌÉϵÄÒþ²Ø¡£Èç¹û¿´µ½ÏµÍ³ÖÐÓжà¸öRundll32.exe£¬²»±Ø¾ª»Å£¬ÕâÖ¤Ã÷Óà Rundll32.exeÆô¶¯Á˶àÉÙ¸öµÄDLLÎļþ¡£µ±È»£¬ÕâЩRundll32.exeÖ´ÐеÄDLLÎļþÊÇʲô£¬ÎÒÃǶ¼¿ÉÒÔ´Óϵͳ×Ô¶¯¼ÓÔØµÄµØ·½ÕÒµ½¡£

¡¡¡¡ÏÖÔÚ£¬ÎÒÀ´½éÉÜÒ»ÏÂRundll32.exeÕâ¸öÎļþ£¬Òâ˼ÉϱßÒѾ­Ëµ¹ý£¬¹¦ÄܾÍÊÇÒÔÃüÁîÐеķ½Ê½µ÷Óö¯Ì¬Á´½Ó³ÌÐò¿â¡£ÏµÍ³Öл¹ÓÐÒ»¸öRundll.exeÎļþ£¬ËûµÄÒâ˼ÊÇ"Ö´ÐÐ16λµÄDLLÎļþ"£¬ÕâÀïҪעÒâһϡ£ÔÚÀ´¿´¿´Rundll32.exeʹÓõĺ¯ÊýÔ­ÐÍ:
¡¤·ÀÖ¹ºÚ¿ÍÈëÇÖ£ºDLLºóÃÅÍêÈ«Çå³ý·½·¨£¨2£©
¡¡¡¡ÆäÃüÁîÐÐϵÄʹÓ÷½·¨Îª:Rundll32.exe DLLname,Functionname [Arguments]

¡¡¡¡Void CALLBACK FunctionName (

¡¡¡¡HWND hwnd,

¡¡¡¡HINSTANCE hinst,

¡¡¡¡LPTSTR lpCmdLine,

¡¡¡¡Int nCmdShow

¡¡¡¡);

¡¡¡¡DLLnameΪÐèÒªÖ´ÐеÄDLLÎļþÃû;FunctionnameΪǰ±ßÐèÒªÖ´ÐеÄDLLÎļþµÄ¾ßÌåÒý³öº¯Êý;[Arguments]ΪÒý³öº¯ÊýµÄ¾ßÌå²ÎÊý¡£

¡¡¡¡(2)£¬Ì滻ϵͳÖеÄDLLÎļþ

¡¡¡¡ÕâÀàºóÞͱÈÉϱߵÄÏȽøÁËһЩ£¬Ëü°ÑʵÏÖÁ˺óÃŹ¦ÄܵĴúÂë×ö³ÉÒ»¸öºÍϵͳƥÅäµÄDLLÎļþ£¬²¢°ÑÔ­À´µÄDLLÎļþ¸ÄÃû¡£Óöµ½Ó¦ÓóÌÐòÇëÇóÔ­À´µÄDLLÎļþʱ£¬ DLLºóÃÅ¾ÍÆôÒ»¸öת·¢µÄ×÷Ó㬰Ñ"²ÎÊý"´«µÝ¸øÔ­À´µÄDLLÎļþ;Èç¹ûÓöµ½ÌØÊâµÄÇëÇóʱ(±ÈÈç¿Í»§¶Ë)£¬DLLºóÞͿªÊ¼£¬Æô¶¯²¢ÔËÐÐÁË¡£¶ÔÓÚÕâÀàºóÃÅ£¬°ÑËùÓвÙ×÷¶¼ÔÚDLLÎļþÖÐʵÏÖ×îΪ°²È«£¬µ«ÐèÒªµÄ±à³Ì֪ʶҲ·Ç³£¶à£¬Ò²·Ç³£²»ÈÝÒ×±àд¡£ËùÒÔ£¬ÕâÀàºóÃÅÒ»°ã¶¼ÊǰÑDLLÎļþ×ö³ÉÒ»¸ö"Æô¶¯"Îļþ£¬ÔÚÓöµ½ÌØÊâµÄÇé¿öÏÂ(±ÈÈç¿Í»§¶ËµÄÇëÇó)£¬¾ÍÆô¶¯Ò»¸öÆÕͨµÄEXEºóÃÅ;ÔÚ¿Í»§¶Ë½áÊøÁ¬½ÓÖ®ºó£¬°ÑEXEºóÃÅÍ£Ö¹£¬È»ºóDLLÎļþ½øÈë"ÐÝÏ¢"״̬£¬ÔÚÏ´οͻ§¶ËÁ¬½Ó֮ǰ£¬¶¼²»»áÆô¶¯¡£µ«Ëæ×Å΢ÈíµÄ"Êý×ÖÇ©Ãû"ºÍ"Îļþ»Ö¸´"µÄ¹¦Äܳǫ̈£¬ÕâÖÖºóÃÅÒѾ­Öð²½Ë¥Âä¡£

¡¡¡¡Ìáʾ:

¡¡¡¡ÔÚWINNT\system32Ŀ¼Ï£¬ÓÐÒ»¸ödllcacheÎļþ¼Ð£¬Àï±ß´æ·Å×ÅÖÚ¶àDLLÎļþ(Ò²°üÀ¨Ò»Ð©ÖØÒªµÄEXEÎļþ)£¬ÔÚDLLÎļþ±»·Ç·¨ÐÞ¸ÄÖ®ºó£¬ÏµÍ³¾Í´ÓÕâÀïÀ´»Ö¸´±»Ð޸ĵÄDLLÎļþ¡£Èç¹ûÒªÐÞ¸Äij¸öDLLÎļþ£¬Ê×ÏÈÓ¦¸Ã°ÑdllcacheĿ¼ÏµÄͬÃûDLLÎļþɾ³ý»ò¸üÃû£¬·ñÔòϵͳ»á×Ô¶¯»Ö¸´¡£

¡¡¡¡(3)£¬¶¯Ì¬Ç¶Èëʽ

¡¡¡¡Õâ²ÅÊÇDLLºóÃÅ×î³£Óõķ½·¨¡£ÆäÒâÒåÊǽ«DLLÎļþǶÈëµ½ÕýÔÚÔËÐеÄϵͳ½ø³Ìµ±ÖС£ÔÚWindowsϵͳÖУ¬Ã¿¸ö½ø³Ì¶¼ÓÐ×Ô¼ºµÄ˽ÓÐÄÚ´æ¿Õ¼ä£¬µ«»¹ÊÇÓÐÖÖÖÖ·½·¨À´½øÈëÆä½ø³ÌµÄ˽ÓÐÄÚ´æ¿Õ¼ä£¬À´ÊµÏÖ¶¯Ì¬Ç¶Èëʽ¡£ÓÉÓÚϵͳµÄ¹Ø¼ü½ø³ÌÊDz»ÄÜÖÕÖ¹µÄ£¬ËùÒÔÕâÀàºóÃŷdz£Òþ±Î£¬²éɱҲ·Ç³£À§ÄÑ¡£³£¼ûµÄ¶¯Ì¬Ç¶ÈëʽÓÐ:"¹Ò½ÓAPI""È«¾Ö¹³×Ó(HOOK)""Ô¶³ÌÏß³Ì"µÈ¡£

¡¡¡¡Ô¶³ÌÏ̼߳¼ÊõÖ¸µÄÊÇͨ¹ýÔÚÒ»¸ö½ø³ÌÖд´½¨Ô¶³ÌÏ̵߳ķ½·¨À´½øÈëÄǸö½ø³ÌµÄÄÚ´æµØÖ·¿Õ¼ä¡£µ±EXEÔØÌå(»òRundll32.exe)ÔÚÄǸö±»²åÈëµÄ½ø³ÌÀï´´½¨ÁËÔ¶³ÌỊ̈߳¬²¢ÃüÁîËüÖ´ÐÐij¸öDLLÎļþʱ£¬ÎÒÃǵÄDLLºóÞ͹ÒÉÏÈ¥Ö´ÐÐÁË£¬ÕâÀï²»»á²úÉúеĽø³Ì£¬ÒªÏëÈÃDLLºóÃÅÍ£Ö¹£¬Ö»ÓÐÈÃÕâ¸öÁ´½ÓDLL ºóÃŵĽø³ÌÖÕÖ¹¡£µ«Èç¹ûºÍijЩϵͳµÄ¹Ø¼ü½ø³ÌÁ´½Ó£¬ÄǾͲ»ÄÜÖÕÖ¹ÁË£¬Èç¹ûÄãÖÕÖ¹ÁËϵͳ½ø³Ì£¬ÄÇWindowsÒ²Ëæ¼´±»ÖÕÖ¹!!! ÄÚ´æ¿Õ¼ä£¬µ«»¹ÊÇÓÐÖÖÖÖ·½·¨À´½øÈëÆä½ø³ÌµÄ˽ÓÐÄÚ´æ¿Õ¼ä£¬À´ÊµÏÖ¶¯Ì¬Ç¶Èëʽ¡£ÓÉÓÚϵͳµÄ¹Ø¼ü½ø³ÌÊDz»ÄÜÖÕÖ¹µÄ£¬ËùÒÔÕâÀàºóÃŷdz£Òþ±Î£¬²éɱҲ·Ç³£À§ÄÑ¡£³£¼ûµÄ¶¯Ì¬Ç¶ÈëʽÓÐ:"¹Ò½ÓAPI""È«¾Ö¹³×Ó(HOOK)""Ô¶³ÌÏß³Ì"µÈ¡£

¡¡¡¡Ô¶³ÌÏ̼߳¼ÊõÖ¸µÄÊÇͨ¹ýÔÚÒ»¸ö½ø³ÌÖд´½¨Ô¶³ÌÏ̵߳ķ½·¨À´½øÈëÄǸö½ø³ÌµÄÄÚ´æµØÖ·¿Õ¼ä¡£µ±EXEÔØÌå(»òRundll32.exe)ÔÚÄǸö±»²åÈëµÄ½ø³ÌÀï´´½¨ÁËÔ¶³ÌỊ̈߳¬²¢ÃüÁîËüÖ´ÐÐij¸öDLLÎļþʱ£¬ÎÒÃǵÄDLLºóÞ͹ÒÉÏÈ¥Ö´ÐÐÁË£¬ÕâÀï²»»á²úÉúеĽø³Ì£¬ÒªÏëÈÃDLLºóÃÅÍ£Ö¹£¬Ö»ÓÐÈÃÕâ¸öÁ´½ÓDLLºóÃŵĽø³ÌÖÕÖ¹¡£µ«Èç¹ûºÍijЩϵͳµÄ¹Ø¼ü½ø³ÌÁ´½Ó£¬ÄǾͲ»ÄÜÖÕÖ¹ÁË£¬Èç¹ûÄãÖÕÖ¹ÁËϵͳ½ø³Ì£¬ÄÇWindowsÒ²Ëæ¼´±»ÖÕÖ¹!!!

¡¤·ÀÖ¹ºÚ¿ÍÈëÇÖ£ºDLLºóÃÅÍêÈ«Çå³ý·½·¨£¨3£©
¡¡¡¡3£¬DLLºóÃŵįô¶¯ÌØÐÔ

¡¡¡¡Æô¶¯DLLºóÃŵÄÔØÌåEXEÊDz»¿ÉȱÉٵģ¬Ò²ÊǷdz£ÖØÒªµÄ£¬Ëü±»³ÆÎªoader¡£Èç¹ûûÓÐLoader£¬ÄÇÎÒÃǵÄDLLºóÃÅÈçºÎÆô¶¯ÄØ?Òò´Ë£¬Ò»¸öºÃµÄDLLºóÃŻᾡÁ¦±£»¤×Ô¼ºµÄLoader²»±»²éɱ¡£LoaderµÄ·½Ê½Óкܶ࣬¿ÉÒÔÊÇΪÎÒÃǵÄDLLºóÃŶø×¨ÃűàдµÄÒ»¸öEXEÎļþ;Ò²¿ÉÒÔÊÇϵͳ×Ô´øµÄRundll32.exe£¬¼´Ê¹Í£Ö¹ÁËRundll32.exe£¬DLLºóÃŵÄÖ÷Ì廹ÊÇ´æÔڵġ£3721ÍøÂçʵÃû¾ÍÊÇÒ»¸öÀý×Ó£¬ËäÈ»Ëü²¢²»ÊÇ"ÕæÕý" µÄºóÃÅ¡£

¡¡¡¡¶þ¡¢DLLµÄÇå³ý

¡¡¡¡±¾½ÚÒÔÈý¿î±È½ÏÓÐÃûµÄDLLºóÃÅÀý£¬·Ö±ðΪ "SvchostDLL.dll""BITS.dll""QoServer.dll"¡£Ïêϸ½²½âÆäÊÖ¹¤Çå³ý·½·¨¡£Ï£Íû´ó¼ÒÔÚ¿´¹ýÕâÈý¿îDLLºóÃŵÄÇå³ý·½·¨Ö®ºó£¬Äܹ»¾ÙÒ»·´Èý£¬Áé»îÔËÓã¬ÔÚ²»¾åÅÂDLLºóÃÅ¡£Æäʵ£¬ÊÖ¹¤Çå³ýDLLºóÃÅ»¹ÊDZȽϼòµ¥µÄ£¬Î޷ǾÍÊÇÔÚ×¢²á±íÖÐ×öÎÄÕ¡£¾ßÌåÔõô×ö£¬Çë¿´ÏÂÎÄ¡£

¡¡¡¡1£¬PortLess BackDoor

¡¡¡¡ÕâÊÇÒ»¿î¹¦Äܷdz£Ç¿´óµÄDLLºóÃųÌÐò£¬³ýÁË¿ÉÒÔ»ñµÃLocal SystemȨÏÞµÄShellÖ®Í⣬»¹Ö§³ÖÈç"¼ì²â¿Ë¡ÕÊ»§""°²×°ÖÕ¶Ë·þÎñ"µÈһϵÁй¦ÄÜ(¾ßÌå¿ÉÒԲμû³ÌÐò°ïÖú)£¬ÊÊÓà Windows2000/xp/2003µÈϵͳ¡£³ÌÐòʹÓÃsvchost.exeÀ´Æô¶¯£¬Æ½³£²»¿ª¶Ë¿Ú£¬¿ÉÒÔ½øÐз´ÏòÁ¬½Ó(×î´óµÄÌØµãŶ)£¬¶ÔÓÚÓзÀ»ðǽµÄÖ÷»úÀ´Ëµ£¬Õâ¸ö¹¦ÄÜÔںò»¹ýÁË¡£

¡¡¡¡ÔÚ½éÉÜÇå³ý·½·¨Ö®Ç°£¬ÎÒÃÇÏÈÀ´¼òµ¥µÄ½éÉÜÒ»ÏÂsvchost.exeÕâ¸öϵͳµÄ¹Ø¼ü·þÎñ:

¡¡¡¡SvchostÖ»ÊÇ×öΪ·þÎñµÄËÞÖ÷£¬±¾Éí²¢²»ÊµÏÖʲô¹¦ÄÜ£¬Èç¹ûÐèҪʹÓÃSvchostÀ´Æô¶¯·þÎñ£¬Ôòij¸ö·þÎñÊÇÒÔDLLÐÎʽʵÏֵ쬏ÃDLLµÄÔØÌå LoaderÖ¸Ïòsvchost£¬ËùÒÔ£¬ÔÚÆô¶¯·þÎñµÄʱºòÓÉsvchostµ÷Óø÷þÎñµÄDLLÀ´ÊµÏÖÆô¶¯µÄÄ¿µÄ¡£Ê¹ÓÃsvchostÆô¶¯Ä³¸ö·þÎñµÄDLL ÎļþÊÇÓÉ×¢²á±íÖеIJÎÊýÀ´¾ö¶¨µÄ£¬ÔÚÐèÒªÆô¶¯·þÎñµÄϱ߶¼ÓÐÒ»¸öParameters×Ó¼ü£¬ÆäÖеÄServiceDll±íÃ÷¸Ã·þÎñÓÉÄĸöDLLÎļþ¸ºÔ𣬲¢ÇÒÕâ¸öDLLÎļþ±ØÐëµ¼³öÒ»¸öServiceMain()º¯Êý£¬Îª´¦Àí·þÎñÈÎÎñÌṩ֧³Ö¡£

¡¡¡¡ºÇºÇ!¿´ÁËÉϱߵÄÀíÂÛ£¬ÊDz»ÊÇÓеãÃÉ (ÎÒ¶¼¿ì˯×ÅÁË)£¬±ð׿±£¬ÎÒÃÇÀ´¿´¿´¾ßÌåµÄÄÚÈÝ¡£HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\RpcSsϵÄParameters×Ó¼ü£¬Æä¼üֵΪ%SystemRoot%\system32\rpcss.dll¡£Õâ¾Í˵Ã÷:Æô¶¯ RpcSs·þÎñʱ¡£Svchostµ÷ÓÃWINNT\system32Ŀ¼ÏµÄrpcss.dll¡£

¡¡¡¡×¢²á±íµÄ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost£¬Àï±ß´æ·Å×ÅSvchostÆô¶¯µÄ×éºÍ×éÄڵĸ÷¸ö·þÎñ£¬ÆäÖÐnetsvcs×éµÄ·þÎñ×î¶à¡£ÒªÊ¹Óà SvchostÆô¶¯Ä³¸ö·þÎñ£¬Ôò¸Ã·þÎñÃû¾Í»á³öÏÖÔÚHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvchostÏ¡£ÕâÀïÓÐËÄÖÖ·½·¨À´ÊµÏÖ:

¡¡¡¡1£¬ Ìí¼ÓÒ»¸öеÄ×飬ÔÚ×éÀïÌí¼Ó·þÎñÃû

¡¡¡¡2£¬ ÔÚÏÖÓÐ×éÀïÌí¼Ó·þÎñÃû

¡¡¡¡3£¬ Ö±½ÓʹÓÃÏÖÓÐ×éÀïµÄÒ»¸ö·þÎñÃû£¬µ«ÊDZ¾»úûÓа²×°µÄ·þÎñ

¡¡¡¡4£¬ ÐÞ¸ÄÏÖÓÐ×éÀïµÄÏÖÓзþÎñ£¬°ÑËüµÄServiceDllÖ¸Ïò×Ô¼ºµÄDLLºóÃÅ

¡¡¡¡ÎÒ²âÊÔµÄPortLess BackDoorʹÓõĵÚÈýÖÖ·½·¨¡£

¡¡¡¡ºÃÁË£¬ÎÒÏë´ó¼Ò¿´ÍêÁËÉϱߵÄÔ­Àí£¬Ò»¶¨¿ÉÒÔÏëµ½ÎÒÃÇÇå³ýPortLess BackDoorµÄ·½·¨ÁË£¬¶Ô£¬¾ÍÊÇÔÚ×¢²á±íµÄSvchost¼üÏÂ×öÎÄÕ¡£ºÃ£¬ÎÒÃÇÏÖÔÚ¿ªÊ¼¡£

¡¡¡¡×¢:ÓÉÓÚ±¾ÎÄÖ»ÊǽéÉÜÇå³ý·½·¨£¬Ê¹Ó÷½·¨ÔÚ´ËÂÔ¹ý¡£

¡¤·ÀÖ¹ºÚ¿ÍÈëÇÖ£ºDLLºóÃÅÍêÈ«Çå³ý·½·¨£¨4£©

¡¡¡¡ºóÃŵÄLoader°ÑSvchostDLL.dll²åÈëSvchost½ø³Ìµ±ÖУ¬ËùÒÔ£¬ÎÒÃÇÏÈ´ò¿ªWindowsÓÅ»¯´óʦÖеÄWindows½ø³Ì¹ÜÀí 2.5£¬²é¿´Svchost½ø³ÌÖеÄÄ£¿éÐÅÏ¢£¬SvchostDLL.dllÒѾ­²åÈëµ½Svchost½ø³ÌÖÐÁË£¬ÔÚ¸ù¾Ý"Ö±½ÓʹÓÃÏÖÓÐ×éÀïµÄÒ»¸ö·þÎñÃû£¬µ«ÊDZ¾»úûÓа²×°µÄ·þÎñ"µÄÌáʾ£¬ÎÒÃÇ¿ÉÒԶ϶¨£¬ÔÚ"¹ÜÀí¹¤¾ß"¡ª"·þÎñ"ÖлáÓÐÒ»ÏîеķþÎñ¡£´Ë·þÎñÃû³ÆÎª:IPRIP£¬ÓÉSvchostÆô¶¯£¬-k netsvcs±íʾ´Ë·þÎñ°üº¬ÔÚnetsvcs·þÎñ×éÖС£

¡¡¡¡ÎÒÃǰѸ÷þÎñÍ£µô£¬È»ºó´ò¿ª×¢²á±í±à¼­Æ÷(¿ªÊ¼¡ªÔËÐÐ-- regedit)£¬À´µ½HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPRIPÏ£¬²é¿´ÆäParameters×Ó¼ü¡£Program¼üµÄ¼üÖµSvcHostDLL.exeΪºóÃŵÄLoader;ServiceDllµÄ¼üÖµC:\WINNT \system32\svchostdll.dllΪµ÷ÓõÄDLLÎļþ£¬ÕâÕýÊǺóÃŵÄDLLÎļþ¡£ÏÖÔÚÎÒÃÇɾ³ýIPRIP×Ó¼ü(»òÕßÓÃSCÀ´É¾³ý)£¬È»ºóÔÚÀ´µ½HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvchostÏ£¬±à¼­netsvcs·þÎñ×飬°Ñ49 00 70 00 72 00 69 00 70 00 00 00ɾ³ý£¬ÕâÀï¶ÔÓ¦µÄ¾ÍÊÇIPRIPµÄ·þÎñÃû£¬¾ßÌåÈçͼ6Ëùʾ¡£È»ºóÍ˳ö£¬ÖØÆô¡£ÖØÆôÖ®ºóɾ³ýWINNT\system32Ŀ¼ÏµĺóÃÅÎļþ¼´¿É¡£

¡¡¡¡2£¬BITS.dll

¡¡¡¡ÕâÊÇéŸçµÄ×÷Æ·£¬Ò²ÊÇDLLºóÃÅ£¬ºÍSvchostDLL.dllÔ­Àí»ù±¾Ò»Ñù£¬²»¹ýÕâÀïʹÓõÄÊÇÉϱ߽éÉܵĵÚËÄÖÖ·½·¨£¬¼´"ÐÞ¸ÄÏÖÓÐ×éÀïµÄÏÖÓзþÎñ£¬°ÑËüµÄServiceDllÖ¸Ïò×Ô¼ºµÄDLLºóÃÅ"¡£»»¾ä»°Ëµ£¬¸ÃºóÃÅÐÞ¸ÄÏÖÓеÄijһ¸ö·þÎñ£¬°ÑÆäÔ­ÓзþÎñµÄDLLÖ¸Ïò×Ô¼º(Ò²¾ÍÊÇBITS.dll)£¬ÕâÑù¾Í´ïµ½ÁË×Ô¶¯¼ÓÔØµÄÄ¿µÄ;Æä´Î£¬¸ÃºóÃÅûÓÐ×Ô¼ºµÄLoader£¬¶øÊÇʹÓÃϵͳ×Ô´øµÄRundll32.exeÀ´¼ÓÔØ¡£ÎÒÃÇ»¹ÊÇÓÃWindows ½ø³Ì¹ÜÀí2.5À´²é¿´£¬´Óͼ7ÖУ¬ÎÒÃÇ¿ÉÒÔ¿´µ½bits.dllÒѾ­²åÈëµ½Svchost½ø³Ìµ±ÖС£

¡¡¡¡ºÃ£¬ÏÖÔÚÎÒÃÇÀ´¿´¿´¾ßÌåµÄÇå³ý·½·¨£¬ÓÉÓڸúóÃÅÊÇÐÞ¸ÄÏÖÓзþÎñ£¬¶øÎÒÃDz¢²»ÖªµÀ¾ßÌåÊÇÐÞ¸ÄÁËÄĸö·þÎñ£¬ËùÒÔ£¬ÔÚ×¢²á±íÖÐËÑË÷bits.dll£¬×îºóÔÚ HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAutoÏÂËÑË÷µ½ÁË bits.dll£¬²é¿´Parameters×Ó¼üϵÄServiceDll£¬Æä¼üֵΪC:\WINNT\system32\bits.dll¡£Ô­À´£¬¸ÃºóÃŰÑRasAuto·þÎñÔ­À´µÄDLLÎļþÌæ»»Îªbits.dllÁË£¬ÕâÑùÀ´ÊµÏÖ×Ô¶¯¼ÓÔØ¡£ÖªµÀÁËÔ­Òò¾ÍºÃ°ìÁË£¬ÏÖÔÚÎÒÃǰÑServiceDllµÄ¼üÖµÐÞ¸ÄΪRasAuto·þÎñÔ­ÓеÄDLLÎļþ£¬¼´%SystemRoot%\System32\rasauto.dll£¬Í˳ö£¬ÖØÆô¡£Ö®ºóɾ³ýWINNT\ system32Ŀ¼ÏµÄbits.dll¼´¿É¡£

¡¡¡¡3£¬NOIR--QUEEN

¡¡¡¡NOIR--QUEEN(ÊØ»¤Õß)ÊÇÒ»¸öDLLºóÃÅ&ľÂí³ÌÐò£¬·þÎñ¶ËÒÔDLLÎļþµÄÐÎʽ²åÈ뵽ϵͳµÄLsass.exe½ø³ÌÀÓÉÓÚLsass.exeÊÇϵͳµÄ¹Ø¼ü½ø³Ì£¬ËùÒÔ²»ÄÜÖÕÖ¹¡£ÔÚÀ´½éÉÜÇå³ý·½·¨Ö®Ç°£¬ÎÒÏȽéÉÜÒ»ÏÂLsass.exe½ø³Ì:

¡¡¡¡ÕâÊÇÒ»¸ö±¾µØµÄ°²È«ÊÚȨ·þÎñ£¬²¢ÇÒËü»áΪʹÓÃWinlogon·þÎñµÄÊÚȨÓû§Éú³ÉÒ»¸ö½ø³Ì£¬Èç¹ûÊÚȨÊdzɹ¦µÄ£¬Lsass¾Í»á²úÉúÓû§µÄ½øÈëÁîÅÆ£¬ÁîÅÆÊ¹ÓÃÆô¶¯³õʼ µÄShell¡£ÆäËûµÄÓÉÓû§³õʼ»¯µÄ½ø³Ì»á¼Ì³ÐÕâ¸öÁîÅÆ¡£

¡¡¡¡´ÓÉϱߵĽéÉÜÎÒÃǾͿÉÒÔ¿´³öLsass¶ÔϵͳµÄÖØÒªÐÔ£¬ÄǾßÌåÔõôÇå³ýÄØ?Çë¿´ÏÂÎÄ¡£

¡¡¡¡ºóÃÅÔÚ°²×°³É¹¦ºó£¬»áÔÚ·þÎñÖÐÌí¼ÓÒ»¸öÃûΪQoSserverµÄ·þÎñ£¬²¢°ÑQoSserver.dllºóÃÅÎļþ²åÈëµ½Lsass½ø³Ìµ±ÖУ¬Ê¹Æä¿ÉÒÔÒþ²Ø½ø³Ì²¢×Ô¶¯Æô¶¯¡£ÏÖÔÚÎÒÃÇ´ò¿ª×¢²á±í£¬À´µ½HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \QoSserver£¬Ö±½Óɾ³ýQoSserver¼ü£¬È»ºóÖØÆô¡£ÖØÆôÖ®ºó£¬ÎÒÃÇÔÚÀ´µ½·þÎñÁбíÖУ¬»á¿´µ½QoSserver·þÎñ»¹ÔÚ£¬µ«Ã»ÓÐÆô¶¯£¬Àà±ðÊÇ×Ô¶¯£¬ÎÒÃǰÑËûÐÞ¸ÄΪ"ÒѽûÓÃ";È»ºóÍùÉÏ¿´£¬»á·¢ÏÖÒ»¸ö·þÎñÃûΪAppCPIµÄ·þÎñ£¬Æä¿ÉÖ´ÐгÌÐòÖ¸ÏòQoSserver.exe(Ô­Òòºó±ßÎÒ»á˵µ½)¡£ÎÒÃÇÔٴδò¿ª×¢²á±í£¬À´µ½HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ AppCPI£¬É¾³ýAppCPI¼ü£¬ÖØÆô£¬ÔÙɾ³ýQoSserver£¬×îºóɾ³ýWINNT\system32Ŀ¼ÏµĺóÃÅÎļþ¡£

¡¤·ÀÖ¹ºÚ¿ÍÈëÇÖ£ºDLLºóÃÅÍêÈ«Çå³ý·½·¨£¨5£©
¡¡¡¡±¾È˺ÍÕâ¸öºóÃÅ"²«¶·"ÁË3¸ö¶àСʱ£¬ÖØÆôN´Î¡£Ô­ÒòÔÚÓÚ¼´Ê¹É¾³ýÁËQoSserver·þÎñ£¬ºóÃÅ»¹ÊÇÔÚÔËÐУ¬¶øÇÒ·þÎñÁбíÖеÄQoSserver·þÎñÓÖ"ËÀ»Ò¸´È¼"¡£ºóÀ´²ÅÖªµÀÔ­Òò:ÔÚÎÒɾ³ýÁËQoSserver·þÎñ²¢ÖØÆôÖ®ºó£¬²åÈëµ½Lsass½ø³Ìµ±ÖеÄQoSserver.dllÎļþÓÖ»Ö¸´ÁË QoSserver·þÎñ£¬²¢ÇÒÉú³ÉÁËÁíÍâÒ»¸ö·þÎñ£¬¼´AppCPI£¬ËùÒÔÎÒÃDZØÐëÔÚµ½×¢²á±íÖÐɾ³ýAppCPI·þÎñ²ÅËãÊǰѸúóÃÅÇå³ý¡£ÓÉ´Ë¿ÉÒÔ¿´³ö£¬ÏÖÔڵĺóÃŵı£»¤´ëÊ©£¬ÕæÊÇÒ»»·¿Û»·¡£

¡¡¡¡×¢Òâ:ÔÚɾ³ýQoSserver·þÎñ²¢ÖØÆôÖ®ºó£¬»Ö¸´µÄQoSserverµÄÆô¶¯Àà±ðÒªÐÞ¸ÄΪ"ÒѽûÓÃ"£¬·ñÔò¼´±ãɾ³ýÁËAppCPI·þÎñ£¬QoSserver·þÎñÓÖÔËÐÐÁË¡£¡¡¡¡

  Èý¡¢DLLµÄ·À·¶

¡¡¡¡¿´ÁËÉϱߵÄÀý×Ó£¬ÎÒÏë´ó¼Ò¶ÔÇå³ýDLLºóÃŵķ½·¨ÓÐÁËÒ»¶¨µÄÁ˽⣬µ«ÔÚÏÖʵÖУ¬DLLºóÃŲ¢²»»áʹÓÃĬÈϵÄÎļþÃû£¬ËùÒÔÄãÒ²¾Í²»Äܿ϶¨ÊÇ·ñÖÐÁËDLLºóÃÅ¡£¶ÔÓÚDLLºóÃÅ£¬system32Ŀ¼ÏÂÊǸöºÃµØ·½£¬´ó¶àÊýºóÃÅÒ²ÊÇÈç´Ë£¬ËùÒÔÕâÀïÒª·Ç³£×¢Òâ¡£ÏÂÃæÎÒÀ´¾ßÌå½éÉÜÒ»ÏÂÔõô·¢ÏÖDLLºóÃÅ£¬Ï£Íû¶Ô´ó¼ÒÓÐËù°ïÖú¡£

¡¡¡¡1£¬°²×°ºÃϵͳºÍËùÓеÄÓ¦ÓóÌÐòÖ®ºó£¬±¸·Ýsystem32Ŀ¼ÏµÄEXEºÍDLLÎļþ:´ò¿ªCMD£¬À´µ½WINNT \system32Ŀ¼Ï£¬Ö´ÐÐ:dir *.exe>exe.txt & dir *.dll>dll.txt£¬ÕâÑù£¬¾Í»á°ÑËùÓеÄEXEºÍDLLÎļþ±¸·Ýµ½exe.txtºÍdll.txtÎļþÖÐ;ÈÕºó£¬Èç·¢ÏÖÒì³££¬¿ÉÒÔʹÓÃÏàͬµÄÃüÁîÔٴα¸·ÝEXEºÍDLLÎļþ(ÕâÀïÎÒÃǼÙÉèÊÇexe0.txtºÍdll0.txt)£¬²¢Ê¹ÓÃ:fc exe.txt exe0.txt>exedll.txt & fc dll.txt dll0.txt>exedll.txt£¬ÆäÒâ˼ΪʹÓÃFCÃüÁî±È½ÏÁ½´ÎµÄEXEÎļþºÍDLLÎļþ£¬²¢½«±È½Ï½á¹û±£´æµ½exedll.txtÎļþÖС£Í¨¹ýÕâÖÖ·½·¨£¬ÎÒÃǾͿÉÒÔ·¢ÏÖ¶à³öÀ´µÄEXEºÍDLLÎļþ£¬²¢Í¨¹ýÎļþ´óС£¬´´½¨Ê±¼äÀ´ÅжÏÊÇ·ñÊÇDLLºóÃÅ¡£

¡¡¡



2006-9-4 13:07
²é¿´×ÊÁÏ  ·ÃÎÊÖ÷Ò³  ·¢¶ÌÏûÏ¢   ±à¼­Ìû×Ó  ÒýÓûظ´
fff000
³¬¼¶°æÖ÷




»ý·Ö 18503
·¢Ìû 2582
×¢²á 2006-5-27
״̬ ÀëÏß
#2  

2£¬Ê¹ÓÃÄÚ´æ/Ä£¿é¹¤¾ßÀ´²é¿´½ø³Ìµ÷ÓõÄDLLÎļþ£¬±ÈÈçWindowsÓÅ»¯´óʦÖÐµÄ Windows ½ø³Ì¹ÜÀí 2.5¡£ÕâÑù£¬¿ÉÒÔ·¢ÏÖ½ø³Ìµ½µ×µ÷ÓÃÁËʲôDLLÎļþ£¬ÔÚ½áºÏÉϱßÓÃFCÃüÁî±È½Ï³öÀ´µÄ½á¹û£¬ÓÖÄܽøÒ»²½À´È·¶¨ÊÇ·ñÖÐÁËDLLºóÃÅ¡£Èç¹ûûÓÐÓÅ»¯´óʦ£¬¿ÉÒÔʹÓÃTaskList£¬Õâ¸öС¹¤¾ßÒ²¿ÉÒÔÏÔʾ½ø³Ìµ÷ÓõÄDLLÎļþ£¬¶øÇÒ»¹ÓÐÔ´´úÂ룬·½±ãÐ޸ġ£

¡¡¡¡3£¬ÆÕͨºóÃÅÁ¬½ÓÐèÒª´ò¿ªÌض¨µÄ¶Ë¿Ú£¬DLLºóÃÅÒ²²»ÀýÍ⣬²»¹ÜËüÔõôÒþ²Ø£¬Á¬½ÓµÄʱºò¶¼ÐèÒª´ò¿ª¶Ë¿Ú¡£ÎÒÃÇ¿ÉÒÔÓÃnetstat -anÀ´²é¿´ËùÓÐTCP/UDP¶Ë¿ÚµÄÁ¬½Ó£¬ÒÔ·¢ÏÖ·Ç·¨Á¬½Ó¡£´ó¼ÒƽʱҪ¶Ô×Ô¼º´ò¿ªµÄ¶Ë¿ÚÐÄÖÐÓÐÊý£¬²¢¶Ônetstat -anÖеÄstateÊôÐÔÓÐËùÁ˽⡣µ±È»£¬Ò²¿ÉÒÔʹÓÃFportÀ´ÏÔʾ¶Ë¿Ú¶ÔÓ¦µÄ½ø³Ì£¬ÕâÑù£¬ÏµÍ³ÓÐʲô²»Ã÷µÄÁ¬½ÓºÍ¶Ë¿Ú£¬¶¼¿ÉÒÔ¾¡ÊÕÑ۵ס£

¡¡¡¡4£¬¶¨ÆÚ¼ì²éϵͳ×Ô¶¯¼ÓÔØµÄµØ·½£¬±ÈÈç:×¢²á±í£¬Winstart.bat£¬Autoexec.bat£¬win.ini£¬system.ini£¬ wininit.ini£¬Autorun.inf£¬Config.sysµÈ¡£Æä´ÎÊǶԷþÎñ½øÐйÜÀí£¬¶ÔϵͳĬÈϵķþÎñÒªÓÐËùÁ˽⣬ÔÚ·¢ÏÖÓÐÎÊÌâµÄ·þÎñʱ£¬¿ÉÒÔʹÓÃWindows 2000 Server Resource KitÖеÄSCÀ´É¾³ý¡£ÒÔÉÏÕâЩµØ·½¶¼¿ÉÒÔÓÃÀ´¼ÓÔØDLLºóÃŵÄLoader£¬Èç¹ûÎÒÃǰÑDLLºóÃÅLoaderɾ³ýÁË£¬ÊÔÎÊ?DLLºóÃÅ»¹ÔõôÔËÐÐ?!

¡¡¡¡Í¨¹ýʹÓÃÉϱߵķ½·¨£¬ÎÒÏë´ó¶àÊýDLLºóÃŶ¼¿ÉÒÔ"ÏÖÐÎ"£¬Èç¹ûÎÒÃÇÆ½Ê±¶à×öһЩ±¸·Ý£¬ÄǶԲéÕÒDLLºóÃÅ»áÆôµ½Ê°빦±¶µÄЧ¹û¡£



2006-9-4 13:08
²é¿´×ÊÁÏ  ·ÃÎÊÖ÷Ò³  ·¢¶ÌÏûÏ¢   ±à¼­Ìû×Ó  ÒýÓûظ´


¿É´òÓ¡°æ±¾ | ÍÆ¼ö¸øÅóÓÑ | ¶©ÔÄÖ÷Ìâ | ÊÕ²ØÖ÷Ìâ



ÂÛÌ³Ìø×ª:  



[ ÁªÏµÎÒÃÇ - ÖèÓê´òÐ弃 ]

Powered by Discuz! 2.5 © 2001-2005 Comsenz Technology Ltd.