- ¡¤ÉÏһƪÎÄÕ£ºÅú´¦Àí×îÍêÕûÈËÐÔ»¯½Ì³Ì
- ¡¤ÏÂһƪÎÄÕ£ºÅú´¦ÀíÒþ²ØÔËÐеÄ10ÖÖ˼·
- ¡¤°Ù¶ÈÖÐËÑË÷¸ü¶àµÄ¹ØÓÚ¡°Åú´¦Àí½Å±¾ÊµÏÖÎļþÏÂÔØ¹¦ÄÜ¡±Ïà¹ØÄÚÈÝ
- ¡¤¹È¸èÖÐËÑË÷¸ü¶àµÄ¹ØÓÚ¡°Åú´¦Àí½Å±¾ÊµÏÖÎļþÏÂÔØ¹¦ÄÜ¡±Ïà¹ØÄÚÈÝ
- ******ÉêÃ÷******
- ±¾Õ¾ÎÄÕÂÄÚÈÝÓв¿·ÖΪÊÕÂ¼ÍøÂçÖÐÆäËûÍøÓÑÄÚÈÝ£¬DOS×ÊÔ´Õ¾²»±£Ö¤ËùÓеĴúÂë¶¼ÊʺÏÄãʹÓá£
- ÓÉÓڱ༴Òæ£¬ÓпÉÄÜÔì³ÉijЩ½Å±¾Îļþ³öÏÖ¶ªÊ§´úÂë»ò´úÂëÎÞ·¨ÔËÐеÄÇé¿ö£¬ÇëÍøÓѸù¾ÝÇé¿ö×ÔÐÐÐ޸ġ£
- Èç¹ûÄܽ«³ö´í²¿·Ö·´À¡¸øÎÒ£¬ÄǾ͸üºÃÁË¡£
Åú´¦Àí½Å±¾ÊµÏÖÎļþÏÂÔØ¹¦ÄÜ
Ŀ¼:
Ò».дÔÚÇ°ÃæµÄ»°
¶þ.¹ÊÊÂµÄÆðÒò
Èý.½â¾ö-¸¹¸å
ËÄ.½â¾ö-ʵս
Îå.½â¾ö-´òÔì
Áù.°ü×°
Æß.С½Ú
°Ë.ºó¼Ç
¾Å,²Î¿¼ÎÄÏ×
ÕýÎÄ¿ªÊ¼:
Ò».дÔÚÇ°ÃæµÄ»°
ÕâÆªÎĵµ½²ÊöµÄ²¢²»ÊÇʲôÐÂÏʵļ¼Êõ,ÎÒÖ»ÊÇÆðµ½½«ËûÃÇ»ìºÍÆðÀ´ÊµÏÖÁË×Ô¼ºÐèÒªµÄ¹¦ÄܵÄ×÷ÓÃ,Èç¹ûÄã¶ÔÅú´¦ÀíºÍPE¸ñʽÏ൱Á˽â,ÄÇÎÒµÄÕâÆªÎĵµ¾ÍȨÇÒµ±×÷ä¯ÀÀÎÂϰ°É...^_^...
ÁíÍâ,ÓÉÓÚÎÒ±¾ÈË·Ï»°±È½Ï¶à,ÕâÒ²ÊDz»Ïë¸øÔÓ־д¸å×ÓµÄÖ÷ÒªÔÒò,¸øÎҸɱñ±ñµÄ3000×ÖÄܽ²³öʲôÀ´,²»ÈçÕâÑùûÓÐÏÞÖÆµÄˬ¿ì(µ±È»Ò²Ã»Ê²Ã´±¨³ê...Ò»_Ò»..),ËùÒÔҲΪÁË·ÀÖ¹ÄãÔÚ¿´ÎÄÕµÄ;ÖÐ˯×Å,Çë×Ô±¸Ð¡×¶×ÓÒ»°Ñ.....
×îºó,ÕâÆªÎĵµËµÊÇÓÃÅú´¦ÀíÏÂÔØÎļþ,ÆäʵËü°üº¬ÁËºÜ¶à·½ÃæµÄ֪ʶ,Èç¹ûÓÐʱ¼ä,²»·ÁÒ»¿´¹þ,^_^,¿ªÊ¼Âò¹ÏÁË..
¶þ.¹ÊÊÂµÄÆðÒò
×î³õÃÈ·¢Õâ¸öÏë·¨µÄÊDz»¾Ãǰ,ÔÚÂÛ̳(¹ã¸æÒ»ÏÂ:http://www.s8s8.net)ÉϵÄUNIX SHELL°å¿éÓиö»áÔ±·¢ÁËһƪÌû×Ó,ÄÚÈÝÊÇÓÃBASH SHELLдµÄÒ»¸ö³ÉÅúÏÂÔØÍ¼Æ¬µÄ½Å±¾(ÆäʵÊÇHͼƬ...Ò»_Ò»..),½ÓÏÂÀ´¸úÌùÄǸö¶à°¡...,Óз±ÑܳöPHPµÄ,VBSµÄ,CµÄ,C#µÄ,JAVAµÄ,ÉõÖÁ½»Á÷µ½¶àÏß³Ì,¶ÏµãÐø´«....ÒýÓû¨´ó¸çµÄÒ»¾ä»°"ÎÞÓΪÁËMMÕÕÆ¬£¬´ó¼ÒµÄ¶¯Á¦¶¼ºÜ×ã°¡£¡"...º¹~~..
ÔÚ·¢ÁËÒ»·ÝPHPºÍCµÄ´úÂëºó(¸Ð¾õÎÒ¶¯Á¦ÌØ×ã~´óÉ«ÀÇ...Ò»_Ò»..),¾õµÃºÜ¼òµ¥(ÒòΪÓÃC»òÕßPHPµÈ½Å±¾À´ÊµÏÖÎļþµÄÏÂÔØ±¾À´¾ÍÊǺܻù´¡µÄ¶«Î÷)ÎҾͿªÊ¼ÏëÓÃ΢Èí×îÔʼµÄ½Å±¾--Batch(Åú´¦Àí)À´³¢ÊÔʵÏÖ(±¾ÎıêÌâÖеÄ"ÏÐÀ´ÎÞÊÂ"¾ÍÊǼÍÄî´Ë´¦,Ò»_Ò».),ÕâËÆºõÓе㲻¿É˼Òé,ÒòΪÅú´¦Àí¼¸ºõûÓÐʵÏÖµÄÖ§³ÖÍøÂçµÄ¹¦ÄÜ(µ±È»,Èç¹ûÄã˵ÄãÄÜÓÃTELNETÏÂÔØµ½ÎļþµÄÎÒÊǺÜÅå·þµÄ..Ò»_Ò»..),µ«Ò²²»ÊÇÍêȫûÓа취,±Ï¾¹WINDOWSÀïÃæÄÜÓõĶ«Î÷Õâô¶à,ûÓÐÍê²»³ÉµÄÊÂÇé....ÔÚÕâÖÖÌôÕ½µÄ¹´ÒýÏÂ,ÎÒÍê³ÉÁËÓÃÅú´¦ÀíÏÂÔØÎļþµÄ¹¦ÄÜ....ÏÖÔÚÈÃÎÒÒ»²½Ò»²½»Ø·ÅÎÒµÄ˼·,½Ò¿ªÓÃÅú´¦ÀíÏÂÔØÎļþµÄ°ÂÃØ...
Èý.½â¾ö-¸¹¸å
Èç¹ûÓÃÅú´¦ÀíÀ´ÏÂÔØÎļþµÄ»°,¿Ï¶¨»áÂíÉÏÏëµ½Cscript½Å±¾(»òÕßÊÇJAVA½Å±¾),ÄÇÊǵ±È»,Ì«¶àµÄÅú´¦Àí½Å±¾ÊµÏÖһЩ±¾Éí²¢²»¿ÉÄÜʵÏֵŦÄܵÄʱºò¶¼ÊDzÉÓÃECHO³öÒ»¸öÆäËû½Å±¾µÄ·½·¨À´½â¾ö.¿ÉÊÇÎÒÃǵÄÄ¿µÄ¾ÍÔÚÓÚÓÃÅú´¦ÀíʵÏÖÏÂÔØµÄ¹¦ÄÜ,Èç¹ûÒªÓÃVBSÀ´°ïæµÄ»°²»ÈçÖ±½ÓдVBSÁË.Õâ¸öÏ뷨˳¼´¸æ´µ....
ÔÙÀ´,¼ÇµÃÒÔǰÓÐÁ÷ÐйýÒ»ÕóÓÃRUNDLL32À´¼ÓÔØDLLÖеÄAPI,ËÆºõºÍÎÒÃÇÐèÒªµÄÄ¿µÄÕ´±ß,ÒòΪÏÂÔØÎļþÄÜÓõÄAPIÌ«¶àÁË,Èç¹ûRUNDLLÄܵ÷ÓÃ,ÄÇ×îºÃ²»¹ýÁË.ÓÚÊÇÎÒ´ò¿ªMSDN,ÕÒÁËÒ»¸öAPI: URLDownloadToFile
URLDownloadToFileº¯ÊýÔÐÍ:
´úÂë
HRESULT URLDownloadToFile(
LPUNKNOWN pCaller,
LPCTSTR szURL,
LPCTSTR szFileName,
DWORD dwReserved,
LPBINDSTATUSCALLBACK lpfnCB
);
URLDownloadToFileº¯ÊýµÄһЩÐÅÏ¢:
ÒýÓÃ
Header Urlmon.h
Import library Urlmon.lib
Minimum availability Internet Explorer 3.0
Minimum operating systems Windows NT 4.0, Windows 95
¸ù¾ÝÕâЩ,ÎÒÃÇ¿ÉÒÔÖªµÀ,Õâ¸öAPIÊÇÔÚURLMON.DLLÎļþÖеÄÒ»¸öµ¼³öº¯Êý,¼òµ¥µÄʵÏÖÁ˰ÑÒ»¸öÎļþ´ÓWEB·þÎñÆ÷ÏÂÔØ±¾»úµÄ¹¦ÄÜ,ÆäʵÓÃÕâ¸öº¯Êý»¹²»´íµÄ,ÖÁÉÙËü°ïÎÒÃÇ´¦ÀíÁ˶ϵãÐø´«,»º´æµÈµÈµÄ¹¦ÄÜ,±ÈÆðÖ±½ÓʹÓÃSOCKETº¯ÊýÀ´ÊµÏÖ»òÕßÓÃWININETÀïµÄº¯ÊýÀ´ÊµÏÖ¼òµ¥¶àµÃ¶àÁË.
URLDownloadToFileÓÐÎå¸ö²ÎÊý:
µÚÒ»¸ö²ÎÊýÊǽöµ±µ÷ÓÃÕßÊÇÒ»¸öActiveX¶ÔÏó²ÅʹÓÃ,Ò»°ãΪNULL.
µÚ¶þ¸ö²ÎÊý¾ÍÊÇÒªÏÂÔØÎļþµÄÄ¿±êURL,ÍêÕû·¾¶.
µÚÈý¸öÊDZ¾µØ±£´æÂ·¾¶,Ò²ÊÇÍêÕû·¾¶
µÚËĸöÊDZ£Áô,±ØÐëΪ0
µÚÎå¸öÊÇÖ¸ÏòÒ»¸öIBindStatusCallback½Ó¿ÚµÄÖ¸Õë,Õâ¾ÍÀàËÆÒ»Öֻص÷»úÖÆ,Äã¿ÉÒԲο¼ÕâЩÀ´»î¶¯µ±Ç°ÏÂÔØ½ø¶È,Ñ¡ÔñÊÇ·ñ¼ÌÐøÏÂÔØµÈµÈ.
ÕâÀïÃæÎÒÃÇÖ»¹ØÐĵڶþºÍµÚÈý¸ö²ÎÊý.ÆäËûµÄͨͨÉèÖóÉ0.(µ±È»ÄãдCµÄʱºò×îºÃÉèÖÃΪNULL)
àÅ,ÇÃÁ˵ã¼üÅ̽éÉÜÁËÕâ¸öº¯Êý,ÊÇÒòΪÕûƪµÄÎĵµ¶¼ºÍÕâ¸öº¯ÊýϢϢÏà¹Ø,ÓÐÁËÕâ¸öº¯Êý,¾Í¿ÉÒÔºô½ÐRUNDLL32À´µ÷ÓÃËü,µ«ÊǺܿÉϧ,Õâ¸öÃÀºÃµÄ¼Æ»®ÂíÉÏÒ²ÆÆÁÑÁË...
ÎÒȥ΢Èí¿´ÁËËûÃǵÄ164787ºÅÎĵµ(http://support.microsoft.com/default.aspx?...kb;en-us;164787),¸ÃÎĵµ²ûÊöÁËRUNDLL32µÄµ÷Ó÷½Ê½ºÍÄܱ»Ëûµ÷Óõĺ¯ÊýµÄ¸ñʽ:
ËüÃÇÊÇÕâô˵µÄ:
ÒýÓÃ
Rundll and Rundll32 programs do not allow you to call any exported function from any DLL. For example, you can not use these utility programs to call the Win32 API (Application Programming Interface) calls exported from the system DLLs. The programs only allow you to call functions from a DLL that are explicitly written to be called by them.
Õâ¸öÊǹ涨µÄ¸ñʽ:
´úÂë
void CALLBACK
EntryPoint(HWND hwnd, HINSTANCE hinst, LPSTR lpszCmdLine, int nCmdShow);
ºÜ²»ÐÒ,ÎÒÃǵÄURLDownloadToFileСÐֵܲ¢Ã»ÓзûºÏÕâЩÌõ¼þ,±»RUNDLL32ÎÞÇéµÄÅׯúÁË(º¹Ò»µÎ..)...µ«ÊÇÎÒÃDz¢Ã»ÓÐÒò´Ë¶øÏÓÆúËü(º¹Ò»µÎAGAIN..),±Ï¾¹,ÔÚºóÀ´ÊµÏֵĹý³ÌÀï,ËüÊÇΪÎÒÃǵŤ×÷Ê¡ÏÂÁ˲»ÉÙ¹¦·ò.
µ½´Ë,ÓÃRUNDLL32ÔËÐмƻ®Á÷²ú....(º®...)
ÏëÁËÒ»¸ùÑ̹¦·ò,ÏÖÔÚURLDownloadToFileÓÐÁË,Ôõô²ÅÄܵ÷ÓÃÕâ¸öº¯ÊýÄØ?×ܲ»ÄÜÄ£·Â»ã±àPUSH 5¸ö²ÎÊý½øÕ»,È»ºóCALL°É,ÄÇÕâ¸öº¯ÊýµÄµØÖ·»¹ÒªÓÃLoadLibrary()ºÍGetProcAddress()¼ÆËãµÃÀ´,ÄÇÕâÁ½¸öº¯ÊýµÄµØÖ·.....»¹ÊÇ·ÅÆú...µÈµÈ,Èç¹ûÓÃÒ»¸öEXEÀ´ÊµÏֵϰ¾Í¼òµ¥ºÜ¶àÁË(ÖÁÉÙEXEÊDz»ÐèÒªÈκνâÊÍÆ÷µÄ),¶Ô,дһ¸öEXEÀ´ÏÂÔØÎļþ.¿ÉÎÒÃǵÄÄ¿µÄÊÇÓÃBATÀ´ÏÂÔØÄØ,BATÎļþÄܰü¹üEXEµÄÊý¾ÝÂð?´ð°¸Êǿ϶¨µÄ...ÍùÏ¿´..
¼ÇµÃÒÔǰ¿´¹ýһƪÎĵµ<<Do All in Cmd Shell>>ÀïÃæ½éÉܹýÒ»ÖÖ·½·¨.ÏÈÂô¸ö¹Ø×Ó.´ó¼Ò¶¼ÖªµÀ,Èç¹ûÓÃECHO¼ÓÉÏÖØ¶¨Ïò·ûÀ´Ð´ÎļþµÄ»°,Ö»ÄÜдÈëASCIIµÄÒ»²¿·Ö,Ò²¾Í¿ÉÒÔÏÔʾ³öÀ´µÄÄÇЩASCII(Ò²¾ÍÊÇASCIIֵСÓÚ128µÄÄÇЩ),¶ÔÓÚÄÇЩÎÞ·¨ÏÔʾµÄ×Ö·û¾ÍûÓа취ÁË.µ«ÊÇÕâÈÃÎÒÃÇÏëÆðÒ»¸ö¹¤¾ß,Ò»¸ö΢ÈíÀúÊ·ÉÏͬÑù¹ÅÀϵÄ,Åú´¦ÀíµÄÐÖµÜ--DEBUG!
ÏÖÔÚ˼·ÇåÎúÁË:¿ÉÒÔÈÃÅú´¦Àí°ÑECHO²»ÄÜÏÔʾµÄ×Ö·ûת»¯Îª16½øÖÆÊý¾Ý(±ÈÈçEXEÖеÄÄÇЩÊý¾Ý)±£´æÔÚÅú´¦ÀíÖÐ,È»ºóÓÃDEBUGдµÀÎļþÀï,×îºóÓÃBATµ÷ÓÃÉú³ÉµÄEXE,ÏÂÔØÎļþ!(ÏëÍêÁËÕâÀï,ÎҸоõ»¹ÊÇÌ«Âé·³,²»ÖªµÀÄÄλţÈ˶ÔÕâ¸öʵÏÖ»¹ÓÐʲô¸ü¼Ó¼òµ¥µÄ°ì·¨Âð??)
ËÄ.½â¾ö-ʵս
ÌÈÈô¾Í´Ë±àдһ¸ö¿ÉÏÂÔØÎļþµÄEXE,È»ºóÖ±½ÓÓÃBAT°ü¹ü,¶¨È»»á±»Í¬ÐгÜЦ,²»µ¥ÊÇÒòΪÄǼ¸Ç§¸ö×Ö½ÚµÄÊý¾ÝÍÏ×Å´ó´óÓ·Ö×µÄBATÎļþ,¸ü¼ÓÈÃΪÕâÖÖ¼òµ¥µÄÏë·¨Á¢¿ÌÏÖÐÎ,ΪÁ˲»´ïµ½ÕâЩ¸ºÃæÐ§¹û,ҲΪÁËÈÃÕâÆªÎĵµ²»ÖÁÓڸɱñ±ñµÄÈÃÈ˸оõûʲô¿´Í·(ÊÂʵÉÏÊÇÒòΪÔçЩʱºò¿´¹ýwatercloudµÄһƪ´ó×÷¸ÐÎòÆÄÉî),ÎÒ¾ö¶¨ÊÖ¹¤Ð´Ò»´®16½øÖÆ´úÂëÀ´´úÌæ»úÆ÷±àÒëµÄEXE.¼ÈÃÀ¹ÛÁ˽çÃæ,ÓÖÔöÇ¿Á˼¼ÊõÐÔ.....(Ò»_Ò»...¼òÖ±ÊÇÔÚÂô×÷...)
ÏÖÔÚµ±ÎñÖ®¼±ÊÇÒªÒ»¸ö¿ÉÒÔÏÂÔØÎļþµÄEXE³ÌÐò,ʵÏÖÕâ¸öÄ¿±êÖ»ÒªÒ»¸öURLDownloadToFile¼´¿É,·ÅÔÚ×îºóʵÏÖ,ÏÈÀ´Ð´Ò»¸öPE¿ò¼Ü:´ó¼Ò¶¼ÖªµÀPEÎļþµÄ¸ñʽ°É,²»¶®µÄ¾ÍÈ¥¿´¿´ÄǸöÖøÃûµÄµçÐźڿÍÂÞijijµÄÊé.(Who!?...~)
Ïȸø³öÎÒÃǵÄPE¿ò¼Ü,»ùÓÚXPµÄFileAlignment¶ÔÆë´óС×îС¾ÍÖ§³Öµ½0x200(Ò²¾ÍÊÇ10½øÖƵÄ512×Ö½Ú,ÒÔÏÂÓÐÔÚÇ°Ãæ¼ÓÉÏ0xµÄ¶¼±íʾ16½øÖÆÊýÖµ),ÎÒÃǵĿò¼Ü¾Í´ò³ö512×Ö½Ú(×¢Òâ,ÎÒÏÂÃæÁôÓпհױíʾ¸÷¸öPE²¿·Ö,½áºÏÏÂÃæµÄÎĵµ,´ó¼Ò·½±ãÀí½â),Õâ¸ö¿ò¼ÜÀïûÓÐÈκεĴúÂë»òÕßÊý¾Ý:
(ZVÓÑÇéÌáʾ:ÏÂÃæÊÇ×î¿ÝÔïµÄ²¿·Ö,¸÷λÊÖÎÕ×¶×Ó,ÒªÓÐÒ»²»Å¿à,¶þ²»ÅÂÍ´µÄ¾«Éñ¿´ÍêËü....)
(Èç¹û¶¨Á¦²»¸ßµÄÅóÓÑ,»òÕß¶ÑPEÎļþÔÙÊìϤ²»¹ýµÄÅóÓÑ,¿ÉÒÔ×Ö½Úתµ½"JMP S1"´¦ÍùÏ¿´.)
(Èç¹ûÖ»ÏëÖªµÀµ½µ×Ôõô»ØÊÂ,»òÕß¶ÔÕâÆª×÷Îı¨ä¯ÀÀ̬¶ÈµÄÅóÓÑ,¿ÉÒÔÖ±½Óתµ½"JMP S2"´¦¼ÌÐøä¯ÀÀ)
(˯×ÅÁ˵ļÌÐøË¯¾õ....)
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000000 4D 5A 00 00 00 00 00 00 00 00 00 00 00 00 00 00 MZ..............
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000030 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 ............@...
==============================================================================
00000040 50 45 00 00 4C 01 02 00 00 00 00 00 00 00 00 00 PE..L...........
00000050 00 00 00 00 70 00 0F 01
0B 01 00 00 00 02 00 00 ....p...........
00000060 00 00 00 00 00 00 00 00 79 01 00 00 00 00 00 00 ........y.......
00000070 00 00 00 00 00 00 40 00 00 10 00 00 00 02 00 00 ......@.........
00000080 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 ................
00000090 00 30 00 00 00 02 00 00 00 00 00 00 02 00 00 00 .0..............
000000A0 00 01 00 00 00 00 00 00 00 01 00 00 00 10 00 00 ................
000000B0 00 00 00 00 02 00 00 00
00 00 00 00 00 00 00 00 ................
000000C0 28 11 00 00 28 00 00 00
==============================================================================
00 00 00 00 00 00 00 00 (...(...........
000000D0 00 02 00 00 00 10 00 00 00 02 00 00 00 01 00 00 ................
000000E0 00 00 00 00 00 00 00 00 00 00 00 00 60 00 00 60 ............`..`
000000F0 00 00 00 00 00 00 00 00 02 00 00 00 00 20 00 00 ............. ..
00000100 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000110 00 00 00 00 60 00 00 60 00 00 00 00 00 00 00 00 ....`..`........
00000120 58 11 00 00 00 00 00 00 50 11 00 00 00 00 00 00 X.......P.......
00000130 00 00 00 00 6E 11 00 00 20 11 00 00 00 00 00 00 ....n... .......
00000140 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000150 58 11 00 00 00 00 00 00
00 00 00 00 00 00 00 00 ................
00000160 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000170 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000180 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000190 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001B0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
ÕâÀï¼òµ¥½éÉÜÒ»ÏÂPEÎļþ¸ñʽµÄ×é³É:
´óÖÂÀ´·ÖÄØ,PE¸ñʽÎļþ¿ÉÒÔ·ÖΪÕâÈý¸ö²¿·Ö(¾ÍÊÇÉÏÊö¿ò¼ÜÖÐÓÃ"=="·Ö¸îµÄÈý¸ö²¿·Ö):
ÒýÓÃ
++++++++++++++++++++++++
+DOSÐÅÏ¢²¿·Ö +
++++++++++++++++++++++++
++++++++++++++++++++++++
+PEÐÅÏ¢²¿·Ö +
++++++++++++++++++++++++
++++++++++++++++++++++++
+Êý¾Ý²¿·Ö +
++++++++++++++++++++++++
ÏÂÃæÀ´¼òµ¥½éÉÜÿһ²¿·ÖµÄ½á¹¹,Ê×ÏȵÄ"DOSÐÅÏ¢²¿·Ö":
ÒýÓÃ
+++++++++++++++++++++++++++++++++++++++++++++
+ +++++++++++++++++++++++++++++++++++++++ +
+ +[DOSÎļþÍ·][0x40] + +
+ +++++++++++++++++++++++++++++++++++++++ +
+ + <==DOSÐÅÏ¢²¿·Ö
+ +++++++++++++++++++++++++++++++++++++++ +
+ +[DOS¿é][0x70,¿É±ä] + +
+ +++++++++++++++++++++++++++++++++++++++ +
+++++++++++++++++++++++++++++++++++++++++++++
Õⲿ·ÖÎÒ¾õµÃÊÇ×îÈßÓàµÄµØ·½,Ê×ÏÈDOSÎļþÍ·µÄ½á¹¹:
´úÂë
typedef struct _IMAGE_DOS_HEADER { // DOS .EXE header
WORD e_magic; // Magic number
WORD e_cblp; // Bytes on last page of file
WORD e_cp; // Pages in file
WORD e_crlc; // Relocations
WORD e_cparhdr; // Size of header in paragraphs
WORD e_minalloc; // Minimum extra paragraphs needed
WORD e_maxalloc; // Maximum extra paragraphs needed
WORD e_ss; // Initial (relative) SS value
WORD e_sp; // Initial SP value
WORD e_csum; // Checksum
WORD e_ip; // Initial IP value
WORD e_cs; // Initial (relative) CS value
WORD e_lfarlc; // File address of relocation table
WORD e_ovno; // Overlay number
WORD e_res[4]; // Reserved words
WORD e_oemid; // OEM identifier (for e_oeminfo)
WORD e_oeminfo; // OEM information; e_oemid specific
WORD e_res2[10]; // Reserved words
LONG e_lfanew; // File address of new exe header
} IMAGE_DOS_HEADER, *PIMAGE_DOS_HEADER;
ÆäÖÐ×îÖØÒªµÄ¾ÍÊÇe_lfanew,ËüÖ¸ÏòÁËÏÂÃæµÄ"PEÐÅÏ¢²¿·Ö"µÄÆðʼµØÖ·(Ò²¾ÍÊÇË׳ƵÄPEÍ·²¿).ÆäËûµÄÊÇһЩDOSÏÂÔËÐÐÕâ¸öPEÎļþ±ØÐëµÄ½á¹¹,±ÈÈç¿´×¢½â¾ÍÃ÷°×,ʲô´úÂë³õʼ»¯¶ÑÕ»¶Î,³õʼ»¯¶ÑÕ»Ö¸Õë,Èë¿ÚIP,CSµÈµÈ,¶¼ÊÇÔÚWIN32ÉÏûÓÐÓõĶ«Î÷,ÎҾͲ»·ÒëÀ,ÕâЩ¶¼ÊÇ˵DOSϵÄ,Èç¹ûÕâ¸öPEÎļþÒ»¿ªÊ¼¾Í´ò¶¨ÔÚWINDOWSÏÂÔËÐÐ,ÕâЩÂÒд¶¼ÎÞËùν,ÄãÉõÖÁ¿ÉÒÔ°ÑÄãµÄÃû×Ö¶¼Ð´½øÈ¥(.....Ò»_Ò»..).µ±È»,ÄãÕâô×÷ºóÕâ¸öÎļþ¾Í²»ÄÜÔÚDOSÏÂÔËÐÐÁË..²»È»µ±»úÊǼ¸ºõ¿ÉÒԿ϶¨µÄ....(º®....).
ÐèÒª¼ÇµÄ³ýÁËe_lfanewÊÇÖ¸ÏòPEÍ·µÄÖ¸ÕëÍ⻹Ҫ¼ÇµÃÕâ¸öDOSÎļþÍ·½á¹¹³¤0x40,Ò²¾ÍÊÇ64¸ö×Ö½Ú.»¹ÓеÚÒ»¸ö²ÎÊýe_magic,Õâ¸öµØ·½ÓÀÔ¶ÊÇ"0x40 0x5a",Ò²¾ÍÊÇ×Ö·ûµÄ"MZ".
DOS¿é²¿·Ö±£´æµÄ¾ÍÊÇÒ»¶ÎDOSÏ¿ÉÒÔÖ´ÐеĴúÂë,±ÈÈçÏÖÔÚ´ó¶à±àÒëÆ÷¾Í¼òµ¥µÄÊä³öÒ»¸ö"This program cannot be run in DOS mode"µÄ×Ö·û´®,ºÍ"DOSÐÅÏ¢²¿·Ö"Ò»Ñù,Èç¹ûÄã²»´òËãÔÚDOSÖ´ÐÐÕâ¸öEXEÎļþ,ÄÇôÕâÀïÍêÈ«¿ÉÒÔɾ³ý,Ϊʲô?ÒòΪWIN32µÄPE×°ÔØÆ÷Ö»¹ØÐÄ"DOSÐÅÏ¢²¿·Ö"µÄe_lfanewÖ¸ÏòµÄ¶øÒÑ.
×ÛÉÏËùÊö,"DOSÐÅÏ¢²¿·Ö"¶ÔÓ¦¿ò¼ÜµÄ´úÂëΪ:
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000000 4D 5A 00 5B D5 E2 C0 EF B6 BC C3 BB D3 C3 2C 2C MZ.[ÕâÀﶼûÓÃ,,
00000010 B1 C8 C8 E7 CE D2 D0 B4 3A CE D2 D2 B2 D6 BB 2C ±ÈÈçÎÒд:ÎÒÒ²Ö»,
00000020 CA C7 D2 BB B0 E3 CB A7 2C B2 BB CA C7 CC D8 2C ÊÇÒ»°ã˧,²»ÊÇÌØ,8
00000030 B1 F0 CB A7 B5 C4 C0 B2 5D 00 00 00 40 00 00 00 ±ð˧µÄÀ²]...@...
¿ÉÒÔ¿´µ½×îºóµÄ4¸ö×Ö½Ú"40000000"Ò²¾ÍÊÇ00000040H(ÏÂÃæÈç¹ûÖ±½ÓÔÚÊýÖµºó¼Ó"H"µÄ¼´±íʾΪ16½øÖÆ)ÊÇÖ¸ÏòËûĩβµÄÖ¸Õë,Ò²¾ÍÊÇ˵Ã÷,ÎÒÃǰÑ"DOS¿é"µÄ²¿·Ö¸øÈ¥µôÁË.
½ÓÏÂÀ´ÊÇ"PEÐÅÏ¢²¿·Ö",ËûµÄ½á¹¹¿ÉÒÔÓÃÏÂÃæµÄͼÀ´±íʾ:
ÒýÓÃ
+++++++++++++++++++++++++++++++++++++++++++++
+ +++++++++++++++++++++++++++++++++++++++ +
+ +[PE±êÖ¾][0x04] + +
+ +++++++++++++++++++++++++++++++++++++++ +
+ + <==PEÐÅÏ¢²¿·Ö
+ +++++++++++++++++++++++++++++++++++++++ +
+ +[PEÎļþÍ·][0x18] + +
+ +++++++++++++++++++++++++++++++++++++++ +
+ +
+ +++++++++++++++++++++++++++++++++++++++ +
+ +[×Ô¶¨ÒåÊý¾Ý½á¹¹][0x0e] + +
+ +++++++++++++++++++++++++++++++++++++++ +
+++++++++++++++++++++++++++++++++++++++++++++
Õû¸ö"PEÐÅÏ¢²¿·Ö"½á¹¹ÊÇÕâÑùµÄ:
´úÂë
typedef struct _IMAGE_NT_HEADERS {
DWORD Signature; //"PE±êÖ¾"¶Î,×ÜÊÇ"PE00"
IMAGE_FILE_HEADER FileHeader; //"PEÎļþÍ·"¶Î,Ö¸ÏòIMAGE_FILE_HEADER½á¹¹
IMAGE_OPTIONAL_HEADER OptionalHeader; //"×Ô¶¨ÒåÊý¾Ý"¶Î,Ö¸ÏòIMAGE_OPTIONAL_HEADER½á¹¹
} IMAGE_NT_HEADERS, *PIMAGE_NT_HEADERS;
IMAGE_FILE_HEADER½á¹¹(PEÎļþÍ·)ºÍIMAGE_OPTIONAL_HEADER½á¹¹ÈçÏÂ:
´úÂë
typedef struct _IMAGE_FILE_HEADER {
WORD Machine; //ÔËÐÐÆ½Ì¨,386µÄ»°ÊÇ104CH
WORD NumberOfSections; //Îļþ½ÚÊýÄ¿,×îÉÙΪ2
DWORD TimeDateStamp; //Îļþ´´½¨Ê±¼ä,Ëæ±ãÉèÖÃ(²»¹ýΪÁË×îºóÉú³É·½±ã,Ëæ±ãÉèÖõĵط½×îºÃ¶¼ÉèÖÃΪ0)
DWORD PointerToSymbolTable; //ÕâÀïÁ½Ïî¼ÇÓÃÓÚµ÷ÊÔ,Ò²Ëæ±ãÉèÖÃ
DWORD NumberOfSymbols;
WORD SizeOfOptionalHeader; //ÏÂÃæÄǸöIMAGE_OPTIONAL_HEADER½á¹¹µÄ³¤¶È,Ò»°ãΪ000EH(°üÀ¨16¸öIMAGE_DATA_DIRECTORY½á¹¹),ÎÒÃÇÖ»Òª2¸ö½á¹¹,ËùÒÔÉèÖÃΪ0070H
WORD Characteristics; //ÎļþÊôÐÔ,PEÎļþÊÇ010H,DLLµÄ»°ÊÇ210H
} IMAGE_FILE_HEADER, *PIMAGE_FILE_HEADER;
IMAGE_FILE_HEADER˵Ã÷ÁËPEÎļþµÄ»ù±¾ÔËÐÐÐÅÏ¢,¿ÉÊǹ⿿Õâ¶Ì¶ÌµÄ½á¹¹²¢²»ÄÜÂú×ãÎÒÃǵÄÐèÒª,±Ï¾¹Î¢ÈíÉè¼ÆµÄ¶«Î÷»¹ÊÇ¿¼ÂǵĺÜÖÜÈ«µÄ,ÓÚÊÇÔÚËüÏÂÃæ¸úÉÏÁËÒ»¸ö³¤³¤µÄ½á¹¹(OptionHeader½á¹¹)À´×÷Ϊ¸½¼ÓÐÅÏ¢¹©¸øÏµÍ³.
´úÂë
OptionHeader½á¹¹(×Ô¶¨ÒåÊý¾Ý½á¹¹)¶¨ÒåÈçÏÂ:
typedef struct _IMAGE_OPTIONAL_HEADER {
WORD Magic; //EXEÎļþµÄ»°ÕâÀïÊÇ10B
BYTE MajorLinkerVersion; //Á¬½ÓÆ÷°æ±¾,Ëæ±ã
BYTE MinorLinkerVersion;
DWORD SizeOfCode; //ËùÓдúÂë½Ú×Ü´óС,ÎÒÃǾÍÒ»¸ö½Ú,ËùÒÔÊÇ512,Ò²¾ÍÊÇ200H
DWORD SizeOfInitializedData; //....δ³õʼ»¯Êý¾Ý½Ú....ûÓÐÕâ¸ö,ÉèÖÃΪ0
DWORD SizeOfUninitializedData; //....ÒÑ................................
DWORD AddressOfEntryPoint; //´úÂëÖ´ÐÐÆðʼµØÖ·,×¢Òâ,Õâ¸öÊÇÄã´úÂë´æ·ÅµÄλÖÃ,[ÕâÀï×¢Òâµã1]
DWORD BaseOfCode; //´úÂë¶Î......(ÕâÀïÈý¸ö¶¼ÊÇÄÚ´æµØÖ·),ÕâÀïÊÇ0
DWORD BaseOfData; //Êý¾Ý¶Î......(²¢·ÇÓ²ÅÌÎļþµØÖ·),ÕâÀïÊÇ0
DWORD ImageBase; //½¨Òé¼ÓÔØÎ»ÖÃ,ͨ³£ÊÇ00400000H,9XµÄϵͳ¿ÉÄÜÂÔСÓÚÕâ¸öÖµ,¼Ç²»µÃÁË..
DWORD SectionAlignment; //ÄÚ´æÖÐ¶ÔÆë´óС,Ò»°ãΪ1000H,Ò²¾ÍÊÇNTµÄÒ»¸öÄÚ´æÆ¬,4KB
DWORD FileAlignment; //Îļþ..........,ÕâÀïÉèÖÃ×îСµÄ,200H,¼æÈÝÈ«²¿ÏµÍ³
WORD MajorOperatingSystemVersion; //һϼ¸¸ö¶¼ÊÇϵͳ°æ±¾Ïà¹ØµÄ,Ëæ±ãÉèÖÃ
WORD MinorOperatingSystemVersion;
WORD MajorImageVersion;
WORD MinorImageVersion;
WORD MajorSubsystemVersion; //ÕâÀïÒªÉèÖÃΪ04H
WORD MinorSubsystemVersion;
DWORD Win32VersionValue; //δÓÃ
DWORD SizeOfImage; //PEÎļþÕ¼ÓõÄÄÚ´æ¿Õ¼ä,ÎÒÃÇÉèÖÃΪ3000H
DWORD SizeOfHeaders; //PEÎļþÍ·´óС(º¬½Ú±í),ÕâÀïÊÇ200H
DWORD CheckSum; //ЧÑéºÍ(ÎÒ²»ÖªµÀÓÃÀ´¸ÉÂï,PE¼¸ºõ¶¼ÊÇ000000000,¿ÉÄÜºÍÆäËû·½ÃæÓйØ,±ÈÈçµ÷ÊÔ?)
WORD Subsystem; //Îļþ×Óϵͳ,×ÓϵͳµÄº¬Òå´ó¼Ò¿ÉÒÔÈ¥²Î¿¼NTÄÚºË,ÕâÀïÉèÖÃΪ02,03¾ù¿É(¿ØÖÆÌ¨ºÍ´°¿Ú×Óϵͳ)
WORD DllCharacteristics;
DWORD SizeOfStackReserve; //һϼ¸¸öÊÇÓйضѺÍÕ»µÄÉèÖÃ,»ù±¾ÉÏËæ±ã,²»¹ý×îºÃÉèÖù»ÓþÍÐÐ(²»ÊÇ0°¡!)
DWORD SizeOfStackCommit;
DWORD SizeOfHeapReserve;
DWORD SizeOfHeapCommit;
DWORD LoaderFlags; //δÓÃ
DWORD NumberOfRvaAndSizes; //ÏÂÃæµÄIMAGE_DATA_DIRECTORY½á¹¹µÄÊýÁ¿,ÔÀ´ÊÇ16¸ö,×îÉÙΪ2¸ö
IMAGE_DATA_DIRECTORY DataDirectory[IMAGE_NUMBEROF_DIRECTORY_ENTRIES];
} IMAGE_OPTIONAL_HEADER, *PIMAGE_OPTIONAL_HEADER;
ÓÐÁËÕâ¸öIMAGE_OPTIONAL_HEADER½á¹¹,PEÎļþµÄ×÷ÓúͰüº¬ÁËʲô×ÊÔ´¶¼Ò»Ä¿ÁËÈ»ÁË.
IMAGE_DATA_DIRECTORY½á¹¹ÈçÏÂ,PEÎļþÖаüº¬Á˺ܶàÊý¾ÝÀàÐÍ,±ÈÈçµ¼³ö,µ¼È뺯Êý,×ÊÔ´,ÖØ¶¨Î»,µ÷ÊԺͰæÈ¨ÐÅÏ¢µÈµÈ,Õâ¸ö½á¹¹×î¶à¿ÉÒÔÓÐ16¸ö,¾ÍÊÇÓÃÀ´¶¨Î»ÕâЩÊý¾ÝµÄ:
´úÂë
typedef struct _IMAGE_DATA_DIRECTORY {
DWORD VirtualAddress;
DWORD Size;
} IMAGE_DATA_DIRECTORY, *PIMAGE_DATA_DIRECTORY;
IMAGE_DATA_DIRECTORY½á¹¹¾ÍÊÇÖ¸³öÁËÄãÿ¸öÊý¾ÝÀàÐ͵ÄÔÚÄÚ´æÖеÄ×°ÔØÎ»Öúͳ¤¶È.×¢Òâ,Õâ¸ö½á¹¹ºÍÏÂÃæÒªËµµÀµÄ½Ú±í²»Í¬,ËäÈ»ËûÃÇ¿ÉÄÜÖ¸ÏòµÄÊÇͬһ¸öµØÖ·,µ«ÊÇ,IMAGE_DATA_DIRECTORYÇø·ÖµÄÊÇÑϸñµÄÊý¾ÝÀàÐÍ,¶ø½Ú±íÖ»ÊǸù¾ÝÈËΪµÄ¶¨ÒåÀ´»®·ÖÊý¾ÝµÄÖÖÀà,Èç¹ûÊÇÕý³£µÄEXE,ͨ³£°Ñ¸÷¸öÊý¾ÝÖÖÀà·Ö¿ª´æ·Å,¶øÕâЩÊý¾Ýͨ³£ÓÖºÍÊý¾ÝÀàÐÍÓÃÒ»ÑùµÄ·½·¨·ÖÀà,ËùÒÔIMAGE_DATA_DIRECTORY½á¹¹ºÍ½Ú±íÖ¸ÏòµÄµØÖ·¿ÉÄÜÊÇÒ»ÑùµÄ,µ«ÊDZ¾ÎÄÕâÆªÀý×Ó²»Í¬,ÒòΪÎÒÃÇÊÖдµÄPE±ØÐ뾡¿ÉÄܵÄС,ËùÒÔÎҰɼ¸¸ö½Ú±íµÄÊý¾ÝÈ«²¿·ÅÔÚÁËÒ»¸ö½Ú,ÕâÑù,½Ú±í¾ÍÖ»ÓÐÒ»¸ö,¶øIMAGE_DATA_DIRECTORY½á¹¹Òª´Ó»ìºÍµÄÊý¾ÝÖÐÖ¸ÏòÕýÈ·µÄÊý¾ÝÀàÐ͵ØÖ·,¾ÍºÍ½Ú±íÖ¸ÏòµÄ²»Ò»ÑùÁË.
×ÛÉÏËùÊö,"PEÐÅÏ¢²¿·Ö"¶ÔÓ¦¿ò¼ÜµÄ´úÂëΪ:
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000040 50 45 00 00 4C 01 02 00 00 00 00 00 00 00 00 00 PE..L...........
00000050 00 00 00 00 70 00 0F 01
0B 01 00 00 00 02 00 00 ....p...........
00000060 00 00 00 00 00 00 00 00 79 01 00 00 00 00 00 00 ........y.......
00000070 00 00 00 00 00 00 40 00 00 10 00 00 00 02 00 00 ......@.........
00000080 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 ................
00000090 00 30 00 00 00 02 00 00 00 00 00 00 02 00 00 00 .0..............
000000A0 00 01 00 00 00 00 00 00 00 01 00 00 00 10 00 00 ................
000000B0 00 00 00 00 02 00 00 00
00 00 00 00 00 00 00 00 ................
000000C0 28 11 00 00 28 00 00 00
ÕâÉÏÃæµÄÊý¾Ý´ó¶à¶¼½âÊ͹ýÁË,ÕâÀïÒª¿´µØÖ·"000000C0"´¦µÄ"28 11 00 00 28 00 00 00",Õâ¸öÊÇIMAGE_DATA_DIRECTORY½á¹¹µÄµÚ¶þ¸ö,Ò²¾ÍÊǵ¼Èë±íµÄµØÖ·,"00 00 00 28"Õâ¸öÊdz¤¶È,²»±È¶à˵,"00 00 11 28"Õâ¸öÓÖΪºÎ?´ø×ÅÕâ¸öÎÊÌâ¿´ÏÂÈ¥...[ÕâÀïËã×÷×¢Òâµã2]
×îºóÒª½éÉܵÄÊÇ"Êý¾Ý²¿·Ö":
ÒýÓÃ
+++++++++++++++++++++++++++++++++++++++++++++
+ +++++++++++++++++++++++++++++++++++++++ +
+ +[Êý¾Ý½Ú±í][0x24*N+1] + +
+ +++++++++++++++++++++++++++++++++++++++ +
+ + <==PEÊý¾Ý²¿·Ö
+ +++++++++++++++++++++++++++++++++++++++ +
+ +[Êý¾Ý½Ú][²»¶¨] + +
+ +++++++++++++++++++++++++++++++++++++++ +
+++++++++++++++++++++++++++++++++++++++++++++
ÆäÖÐIMAGE_SECTION_HEADER½á¹¹(Êý¾Ý½Ú±í)ÈçÏÂ:
´úÂë
typedef struct _IMAGE_SECTION_HEADER {
BYTE Name[IMAGE_SIZEOF_SHORT_NAME];//Õâ¸ö8×ֽڵĿռä¾ÍÊǸøÄãÀ´¶¨ÒåÕâ¸ö½ÚµÄÃû³Æ,±ÈÈç´ó¼Ò³£¼ûµÄ".text .data .code"µÈµÈ,ÎÒÕâÀïΪÁËÒÔºóµÄÌî³ä·½±ã,ÉèÖÃÁ˿հ×..(00000000H),ÆäʵÕâÀïÊÇ¿ÉÒÔËæ±ãдµÄ,±ÈÈçÄ㶨Òå".zvrop"Ò²¿ÉÒÔ
union {
DWORD PhysicalAddress; //ÕâÊǸöÁªºÏ½á¹¹,˵Ã÷Á˸ýڵĴóС,ÎÒÃÇÕû¸öPEÎļþ¾ÍÊÇÒ»¸ö½Ú,ËùÒÔÊÇ200H
DWORD VirtualSize;
} Misc;
DWORD VirtualAddress; //¶¨Î»¸Ã½ÚÔÚÄÚ´æÖеĵØÖ·(Ïà¶ÔÓÚ¼ÓÔØÎ»ÖÃµÄÆ«ÒƵØÖ·)ÎÒÃÇÕâÀïÊÇÏȲ»ËµÕâЩ.[ÕâÀïËã×÷×¢Òâµã3]
DWORD SizeOfRawData; //ÎļþÖеijߴç,ÕâÀïºÍÉÏÃæµÄÁªºÏ½á¹¹²»Í¬,ÕâÀïÊÇ¶ÔÆëºóµÄµØÖ·,ÎÒÃÇÉèÖÃΪ200H
DWORD PointerToRawData; //¸Ã½ÚÔÚÎļþÖеÄλÖÃ,Ïà¶ÔÓÚÎļþÍ·,ÕâÀï¿ÉÒÔËæ±ãÉèÖÃ,²»¹ýÉèÖÃÁ˺óÃæµÄ´úÂëÖ¸ÕëÒ²Òª¸ú×ű䶯,ÎÒÃÇÕâÀïÉèÖÃ100H
DWORD PointerToRelocations; //ÏÂÃæËĸöÊǸøÁ¬½ÓÆ÷ÓõIJÎÊý,Ëæ±ã
DWORD PointerToLinenumbers;
WORD NumberOfRelocations;
WORD NumberOfLinenumbers;
DWORD Characteristics; //½ÚµÄÊôÐÔ,×Ô¼ºÇø²é±í,»ùÓÚÆª·ù,ÕâÕűíÎҾͲ»ÌṩÁË,ÐèÒªµÄ¿ÉÒÔPMÎÒ,Ò»°ã´úÂë½ÚΪ60000020H(40000000&2000000&00000020),¼´ÊÇ¿ÉÖ´ÐÐ,¿É¶ÁµÄ´úÂë¶Î,ÎÒÃÇÉèÖÃΪ60000060H,ÒòΪÎÒÃǼȰüº¬ÁËÊý¾ÝÓÖ°üº¬ÁË´úÂë.
} IMAGE_SECTION_HEADER, *PIMAGE_SECTION_HEADER;
¿ÉÒÔ¿´µ½Õâ¸ö½á¹¹µÄÊýÁ¿ÊDz»¶¨µÄ,Ò²¾ÍÊÇÄãÏÂÃæÓжàÉÙ¸ö½Ú,¾ÍÓжàÉÙ¸öIMAGE_SECTION_HEADER+1µÄ½á¹¹,ÒòΪϵͳÐèÒªÒ»¸öÈ«0µÄIMAGE_SECTION_HEADER½á¹¹À´±êʶÒѾ½áÊø.ÁíÍâ,XP×îÉÙÒªÁ½¸öIMAGE_SECTION_HEADER½á¹¹,,²»È»»á±¨·Ç·¨32λ³ÌÐòµÄ(Õâ¸öÊìϤµÄÌáʾÎÒÔÚÍê³ÉÕâ¸ö¶«Î÷µÄʱºò²»ÖªµÀ³öÏÖÁËNN´Î,´Ó´ËÉî¶ñÍ´¾ø!),2KÔòûÓÐÕâ¸öÏÞÖÆ(Òý×ÔwatercloudµÄÑо¿,ÎÒû¶àÉÙʱ¼äÈ¥ÉîÍÚÕâ¸ö¹þ...).
ÏÂÃæ¾ÍÊǾßÌåµÄ"Êý¾Ý½Ú"µÄÄÚÈÝÁË(ÎÒÃÇÕâÆªÎĵµÕû¸öPEÎļþ¾ÍÊÇÒ»¸ö½Ú),Õû¸öPEÎļþ½á¹¹ÄÚÈÝ´ó¸Å¾ÍÊÇÕâô¶à.
×ÛÉÏËùÊö,"Êý¾Ý²¿·Ö"¶ÔÓ¦¿ò¼ÜµÄ´úÂëΪ:
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00 00 00 00 00 00 00 00 (...(...........
000000D0 00 02 00 00 00 10 00 00 00 02 00 00 00 01 00 00 ................
000000E0 00 00 00 00 00 00 00 00 00 00 00 00 60 00 00 60 ............`..`
000000F0 00 00 00 00 00 00 00 00 02 00 00 00 00 20 00 00 ............. ..
00000100 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000110 00 00 00 00 60 00 00 60 00 00 00 00 00 00 00 00 ....`..`........
[THIS IS JMP S1]
ÈÆÁËÕâô´ó¸öȦ×ӲŻص½ÕýÌâ....(Ò»_Ò»....ÆäʵÎÒÊÇÏë°ÑÎÊÌâдµÄÏêϸ,ÕâÑù´ó¼Ò¿´Á˾ÍûÓÐ̬¶ÈµÄÒÉÂÇÂï..),»¹¼ÇµÃÉÏÃæËµ¹ýµÄÊý¾ÝÀàÐÍÂð,ÆäÖÐ×îÖØÒªµÄ¾ÍÊǵ¼Èë±í,ÎÒÃǵÄURLDownloadToFileСÅóÓÑÒѾÔÚ°åµÊÉÏ×øÁ˺ܾÃÁË.......Õâ¸öµ¼Èë±í¾ÍÊÇΪËûÁ¿Éí¶¨×öµÄ.ÎÒÃǵÄÄ¿µÄ¾ÍÊÇÈÃPEÎļþÖ´ÐÐURLDownloadToFileµÄ¹¦ÄÜ,×ÔÈ»µÃ°ÑURLDownloadToFileÕâ¸öº¯Êý¼ÓÈëµ¼Èë±í.
˵µÀµ¼Èë±íµÄ¶¨ÒåÄØ?¾Í²»µÃ²»ÏÈ˵˵WINDOWS¼ÓÔØ¿ÉÖ´ÐгÌÐòʱºò¶ÔIAT(IMPORT ADDRESS TABLE,µ¼ÈëµØÖ·±í)µÄÐÞ¸Ä,ÎÒÃÇÖªµÀ,¸÷¸öϵͳµÄÿ¸öº¯ÊýÔÚÄÚ´æÖеÄλÖö¼ÊDz»Í¬µÄ(ÖÁÉÙ2K,XP,2003»ù±¾É϶¼²»Ò»Ñù),ËùÒÔ²ÅÓкܶàдÈËSHELLCODEµÄʱºò,λÖüÆËã¸ö°ëÌì..ÕâÑùÀ´ËµµÄ»°,ÔÚÎÒÃDZàÒëEXEµÄʱºò¾Í²»¿ÉÄÜÈ·¶¨Ä³¸öº¯ÊýµÄµØÖ·.ÒªÖ´ÐÐÕâ¸öº¯Êý,±ØÐëÕÒµ½ËûµÄÈë¿ÚµØÖ·,¶øÕâ¸öµØÖ·¾ÍÓÉϵͳÔÚ¼ÓÔØPEÎļþµÄʱºò°ïÄã"Ìî¿Õ",Õ⶯̬µÄÍê³Éº¯ÊýµØÖ·µÄÌî³äÒ²¾ÍÊÇ"¶¯Ì¬Á¬½Ó"Õâ¸öÃû´ÊµÄÓÉÀ´.
ÏÖÔÚÎÒ¼òµ¥µÄÄ£ÄâÒ»ÏÂÏµÍ³×ªÔØPEÎļþ²¢¸ø³öº¯ÊýµØÖ·µÄ²½Öè,Ê×ÏÈ,ÎÒÃǸø³öÒ»¸öPEÎļþÖеĵ¼Èë±í:
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000120 58 11 00 00 00 00 00 00
50 11 00 00 00 00 00 00 X.......P.......
00000130 00 00 00 00 6E 11 00 00 20 11 00 00
00 00 00 00 ....n... .......
00000140 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000150 58 11 00 00 00 00 00 00
¿ÉÒÔ¿´µ½,Õâ¸ö±í±»·ÖΪËĸö²¿·Ö,ÆäÖÐÖмäÁ½¸öµÈ³¤Îª0x14µÄÁ½¶Î¾ÍÊǵ¼Èë±íÖеÄIMAGE_IMPORT_DESCRIPTOR½á¹¹,¸Ã½á¹¹ÈçÏÂ:
´úÂë
typedef struct _IMAGE_IMPORT_DESCRIPTOR {
union {
DWORD Characteristics;
DWORD OriginalFirstThunk; //Ö¸ÏòÒ»¸ö"º¯ÊýÁбíµÄÖ¸Õë½á¹¹".
};
DWORD TimeDateStamp; //ÔÝʱ¿ÉÒÔ¿´×÷ûÓÃ,0
DWORD ForwarderChain; //ÔÝʱ¿ÉÒÔ¿´×÷ûÓÃ,0
DWORD Name; //Ö¸ÏòÒ»¸öDLL,Õâ¸ö½á¹¹ÀïÃæµÄº¯Êý±ØÐë¶¼ÊÇÕâ¸öDLLÀïÃæµÄ
DWORD FirstThunk; //Ö¸ÏòÒ»¸öIAT±í,×îºó²Ù×÷ϵͳÐ޸ĵľÍÊÇÕâ¸ö
} IMAGE_IMPORT_DESCRIPTOR;
×¢Òâ,¸Ã½á¹¹Ò²±ØÐëÓÐN+1¸ö,ÒòΪÎÒÃÇÖ»ÐèÒªÒ»¸öº¯Êý"URLDownloadToFile",ËùÒÔÎÒÃÇÖ»ÓÐÕâÒ»¸ö½á¹¹,µÚ¶þ¸ö½á¹¹ÊÇÈ«0µÄ.±íʾ½áÊø.
Õâ¸ö"º¯ÊýÁбíÖ¸Õë½á¹¹"¾ÍÊÇIMAGE_THUNK_DATA32½á¹¹:
´úÂë
typedef struct _IMAGE_THUNK_DATA32 {
union {
PBYTE ForwarderString;
PDWORD Function;
DWORD Ordinal;
PIMAGE_IMPORT_BY_NAME AddressOfData;
} u1;
} IMAGE_THUNK_DATA32;
ËûÖ»ÓÐÒ»¸öË«×ÖÀàÐ͵ÄÖµ,Õâ¸öÖµÈç¹ûÊÇ1XXXXXXXHµÄ,ÄÇô˵Ã÷¸Ãº¯ÊýÊÇÒ»ÐòºÅ·½Ê½µ¼ÈëµÄ,ÐòºÅ¾ÍÊdzýÁË1ÍâµÄʣϵÄ7λ,Èç¹ûÊÇ0XXXXXXXHµÄ,ÄÇôÕâ¸ö³ýÁË0ÍâµÄ7λ¾ÍÊÇ×÷Ϊһ¸öÐéÄâµØÖ·Ö¸ÏòÕâ¸öº¯ÊýµÄÃû×Ö.
¹ØÓÚʲôÊÇÐòºÅµ¼ÈëʲôÊÇÃû×Öµ¼Èë,ÎҾͲ»ËµÁË,ÕâÐ©Éæ¼°µ½µ¼³ö±íµÄ¸ÅÄî.±¾ÎIJ»ÐèÒª.
¼ÙÉèÎÒÊÇWINDOWS²Ù×÷ϵͳµÄPE×°ÔØÆ÷,ÎÒ´ÓÕâ¸öPEÎļþ¸ñʽµÄijЩ²ÎÊýÖж¨Î»µ½ÁËÕâ¸ö00000128HµÄµØÖ·Êǵ¼Èë±íµØÖ·,ÏÖÔÚÎÒµÄÄ¿µÄÊÇÒª°Ñ"58 11 00 00"Õâ¸öµØÖ·Ì滻ΪÕýÈ·µÄº¯ÊýµØÖ·(×¢Òâ,ÊÇ00000120H´¦µÄ,00000150H´¦µÄÄǸö"58 11 00 00"ÊǸøÏµÍ³Ìṩ"URLDownloadToFile"Õâ¸ö×Ö·û´®Î»ÖõÄÖ¸Õë,Õâ¸öµØÖ·²»»á±ä¶¯,»á±äµÄÊÇ00000120H´¦µÄ"58 11 00 00",Æäʵ00000120H´¦µÄ"58 11 00 00"¿ÉÒÔËæ±ãÉèÖõÄ.).
ÎÒ¿ªÊ¼¶¨Î»µ½ÁË:
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
50 11 00 00 00 00 00 00 X.......P.......
00000130 00 00 00 00 6E 11 00 00 20 11 00 00
µÄµØ·½,·¢ÏÖÕâ¸öº¯ÊýµÄλÖÃÊÇ"50 11 00 00",Ïà¹ØµÄDLLÊÇ"6E 11 00 00",ÓÚÊÇÎÒÕÒµ½PEÎļþµÄÕâ¸öλÖÃ(ÊÇÄÚ´æÖеÄÏà¶ÔλÖÃ),·¢ÏÖ"50 11 00 00"λÖô¦µÄIMAGE_THUNK_DATA32½á¹¹µÄÖµÊÇ"58 11 00 00",Õâ¸öÖµ²»ÊÇ1¿ªÍ·µÄ,ÓÚÊÇÎÒÓÃÕâ¸öÖµ×÷ΪµØÖ·²éÕÒ,·¢ÏÖÕâ¸öÖµÖ¸ÏòµÄλÖõÄÄÚÈÝÊÇ"31 00 URLDownloadToFile",³ýÈ¥Ç°ÃæµÄÁ½¸öÐòºÅ,ÕÒµ½ÁËÕâ¸öº¯ÊýµÄÃû³Æ,½ÓÏÂÀ´ÎÒ¸ù¾ÝÔÚ"6E 11 00 00"λÖÃÕÒµ½µÄ×Ö·û´®"URLMON.DLL",ÓÃLoadLibrary()ºÍGetProcAddress()ÕÒµ½Á˺¯Êý"URLDownloadToFile"ÔÚÄÚ´æÖеÄλÖÃ,¼ÙÉèÊÇ"XX XX XX XX",È»ºó°Ñ"XX XX XX XX",ÌîÈëµ½"20 11 00 00"Ö¸ÏòµÄλÖÃÖÐ...Íê±Ï.
ÕâÑùÀ´Ëµ,´ó¼Ò¾ÍÃ÷°×ÁË,URLDownloadToFileÕâ¸öº¯ÊýµÄ´æ·ÅλÖÃÓ¦¸Ã¸ù¾Ý"50 11 00 00"(È·ÇеÄ˵Ӧ¸ÃÊÇ"50 11 00 00"Ö¸ÏòµÄλÖõÄÖ¸Õë)ºÍ"6E 11 00 00"À´È·¶¨(È·¶¨Õâ¸öº¯Êý´æÔÚµÄDLL).
Îå.½â¾ö-´òÔì
[THIS IS JMP S2]
ÏÖÔÚÎÒÃÇÔÙ»ØÍ·ÕûÀíÒ»ÏÂÕû¸ö¹ý³Ì...½áºÏÕâÕűí:
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000000 4D 5A 5B 00 00 00 00 00 00 00 00 00 00 00 00 00 MZ[.............
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000030 00 00 00 00 00 00 00 00 00 00 00 5D 40 00 00 00 ...........]@...
00000040 50 45 00 00 4C 01 02 00 00 00 00 00 00 00 00 00 PE..L...........
00000050 00 00 00 00 70 00 0F 01 0B 01 00 00 00 02 00 00 ....p...........
00000060 00 00 00 00 00 00 00 00 79 01 00 00 00 00 00 00 ........y.......
00000070 00 00 00 00 00 00 40 00 00 10 00 00 00 02 00 00 ......@.........
00000080 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 ................
00000090 00 30 00 00 00 02 00 00 00 00 00 00 02 00 00 00 .0..............
000000A0 00 01 00 00 00 00 00 00 00 01 00 00 00 10 00 00 ................
000000B0 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................
000000C0 28 11 00 00 28 00 00 00 00 00 00 00 00 00 00 00 (...(...........
000000D0 00 02 00 00 00 10 00 00 00 02 00 00 00 01 00 00 ................
000000E0 00 00 00 00 00 00 00 00 00 00 00 00 60 00 00 60 ............`..`
000000F0 00 00 00 00 00 00 00 00 02 00 00 00 00 20 00 00 ............. ..
00000100 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000110 00 00 00 00 60 00 00 60 00 00 00 00 00 00 00 00 ....`..`........
00000120 58 11 00 00 00 00 00 00 50 11 00 00 00 00 00 00 X.......P.......
00000130 00 00 00 00 6E 11 00 00 20 11 00 00 00 00 00 00 ....n... .......
00000140 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000150 58 11 00 00 00 00 00 00 5B 00 00 00 00 00 00 00 ........[.......
00000160 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000170 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000180 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000190 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001B0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
000001E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5D ...............]
ÕâÕÅPEÎļþÊý¾Ýͼ¾ÍÊÇÒ»¸öºÜ´óµÄ"Ìî¿Õ",³ýÈ¥ÖØÒªµÄÊý¾Ý²¿·Ö,ÎÒÃÇ¿ÉÒÔËæ±ãдÈëÊý¾ÝµÄµØ·½ÓÐ2¸ö(Ò²¾ÍÊÇÁ½¸ö´ó¹ÒºÅ¹ÒÆðÀ´µÄÖмä).
µÚÒ»¸öÊÇ´ÓµØÖ·00000002¿ªÊ¼µÄ,µ½µØÖ·0000003B½áÊøµÄ56×Ö½Ú.
µÚ¶þ¸öÊÇ´ÓµØÖ·00000160¿ªÊ¼µÄ,µ½PEÎļþ½áβµÄ160×Ö½Ú.(Ò²¿ÉÒÔ´Ó000000158¿ªÊ¼,ÕâÑù¾ÍÓÐ168×Ö½Ú)
ÒòΪÎÒÃǵijÌÐòºÜ¶Ì,ËùÒÔµÚ¶þ¸ö168×Ö½Ú»ù±¾ÉÏ¿ÉÒÔÂú×ãÒªÇóÈ«²¿,¾Í²»ÐèÒªµÚÒ»¸ö56×Ö½ÚµÄÊý¾ÝÁË.°ÑÊý¾ÝºÍÔÚÒ»ÆðÒ²·½±ãÄØ,²»ÊÇô?^_^.
ÄÇÕâЩµØ·½¾ßÌåÌîдЩʲô¶«Î÷ÄØ?´óÖÂÀ´Ëµ·ÖΪÈý¸ö²¿·Ö:
1.µ¼Èë±í,°üÀ¨"URLDownloadToFile"Õâ¸öº¯ÊýµÄ×Ö·û´®ºÍ"URLMON.DLL"Õâ¸öDLLµÄ×Ö·û´®.
2.ÎļþµÄ¿ÉÖ´ÐлúÆ÷Âë.
3.º¯ÊýÐèÒªµÄÊý¾Ý.
Ê×ÏÈÊǵ¼Èë±í,¸ù¾ÝÉÏÒ»½Ú˵µÄÄÇЩ,ÎÒÃÇ¿ÉÒÔºÜÈÝÒ×µÄÅжϳöÕâ¸ö"URLDownloadToFile"¸ÃÌîÔÚ"58 11 00 00"µÄλÖÃ.µ±È»Äã¿ÉÒÔ¸ÄÕâ¸öÖµ,Õâ¸öÖµÖ»ÊÇÎÒдµÄ.×ÜÖ®ÄãÏë°ÉÕâ¸öµ¼Èë±í·ÅÔÚʲôλÖÃ,Õâ¸ö"58 11 00 00"¾ÍÒªÖ¸ÏòÕâ¸öλÖÃ.ÓÚÊÇÎÒÃÇÔÚPEÎļþµÄ00000158λÖÃдÈë"31 00 URLDownloadToFile"×Ö·û´®,Ç°ÃæÁ½¸ö16½øÖÆÊÇÐòºÅÊǸø×ªÔØÆ÷ÌṩÐÅÏ¢×÷ΪÔÚDLLÖе¼³öµØÖ·µÄÒÀ¾Ý.
(¶ÔÁË,ÕâÀï˵Ã÷Ò»¸öÎÊÌâ,ÕâÆªÎĵµÒ²×¢ÊÍÁ˺ܶà"×¢Òâµã",ÎªÊ²Ã´ÄØ,×Ðϸ¿´¿´ÕâЩעÒâµã,·¢ÏÖ¶¼ÊǺÍλÖÃÓйصÄ,ÄÇÊÇÒòΪ:PEÎļþÖеľø´ó¶àÊýµÄµØÖ·,¶¼ÊDzÉÓÃÎļþ¼ÓÔØºóÄÚ´æÖеĵØÖ·µÄ,ÕâÑùÒ»·½Ãæ¼Ó¿ìÁ˼ÓÔØËÙ¶È,ÁíÍâÒ»·½ÃæÒ²Ê¡Á˲»ÉÙ¼ÓÔØÆ÷µÄ¹¤×÷,±ÈÈçÕâ¸ö"58 11 00 00"µÄµØÖ·,ÒòΪÎÒÃǼÓÔØµÄλÖÃÊÇ1000H,ËùÒÔ¸ù¾ÝÕâ¸öλÖÃ,ÎÒÃÇÔÚÎļþÖеÄλÖþÍÊÇ158H,ÕâÀïÒªÉêÃ÷µÄÒ»µã,²¢²»ÊÇËùÓеĵØÖ·¶¼¿ÉÒÔÕâô¼ÆËãµÄ,ÒòΪÎÒÃÇÔÚPointerToRawDataÄÇÀïÉèÖÃÁË100H,ΪµÄ¾ÍÊÇÕâÑù·½±ãµÄ¼ÆËãÏà¶ÔµØÖ·,¶ÔÓÚÆäËûµÄPEÎļþ,Èç¹ûÒª¸ù¾ÝÕâÖÖÄÚ´æµØÖ·¼ÆËã³öPEÎļþµØÖ·,»¹²»ÊÇÕâô¼òµ¥ÊÇÊÂÇé,^_^..µ±È»,ÍøÂçÉÏÒ²ÓкܶàÕâÖÖת»»º¯Êý,RVAµ½OFFSETµÄ)
È»ºó°ÑURLMON.DLLÕâ¸ö×Ö·û´®ÌîÈë"6E 11 00 00"Ö¸ÏòµÄµØÖ·,µ±È»Õâ¸öÖµÒ²ÊÇ¿ÉÒÔ±äµÄ.
×îºó,ÎÒÃÇÒªÓñʼǼһÏÂ×îºóÕâ¸öº¯Êý±»µ¼³öµÄµØÖ·µÄ´æ·Å´¦,Ò²¾ÍÊÇ"20 11 00 00".
[×¢Òâ,ÒÔÉϵÄÕâЩ²Ù×÷¶¼ºÍIMAGE_IMPORT_DESCRIPTOR½á¹¹ºÍIMAGE_THUNK_DATA32½á¹¹Ïà¹Ø,¿´²»Ã÷°×µÄ¶à¿´¿´ÕâÁ½¸ö½á¹¹]
½ÓÏÂÀ´ÊÇ¿ÉÖ´ÐÐÂë.ÎÒÃǵÄÄ¿µÄºÜ¼òµ¥,Ö»ÒªÕâ¸öPEÎļþÄÜÏÂÔØÎļþ¾ÍÐÐ,ËùÒÔÎÒÃÇÖ»Òªµ÷ÓÃURLDownloadToFileº¯Êý¼´¿É,дһС¶Î»ã±àÂë(»¹¼ÇµÃÇ°ÃæËµ¹ýµÄURLDownloadToFileµÄµ÷Ó÷½·¨Âð,»¨Á˵ã±ÊÄ«µÄÄǸö):
´úÂë
PUSH 0 ;6A 00
PUSH 0 ;6A 00
PUSH XXXXXXXX ;68 XXXXXXXX
PUSH XXXXXXXX ;68 XXXXXXXX
PUSH 0 ;6A 00
CALL XXXXXXXX ;E8 XXXXXXXX
ÓÉÓÚº¯ÊýµÄµ÷ÓÃÊÇ·ûºÏPASCALµ÷ÓÃ,Ò²¾ÍÊÇSTDCALL,×ÔÓÒÏò×óѹջ,ËùÒÔÎÒÃǵIJÎÊýÒ²ÊÇ×îºóÒ»¸öÏÈÈëÕ».×îºóCALL³öÕâ¸öURLDownloadToFileº¯Êý.
ǰÁ½¸öXXXXXXXXµØÖ·ÊÇÁ½¸ö×Ö·û´®µÄµØÖ·,Ò²¾ÍÊÇURLDownloadToFileº¯ÊýµÄÁ½¸öÖØÒª²ÎÊý,×îºóÒ»¸öXXXXXXXXÊÇÕâ¸öº¯ÊýÔÚÄÚ´æÖеĵØÖ·(²Ù×÷ϵͳÒѾ°ïÎÒÃÇÌî³äÁË,»¹¼ÇµÃÉÏÃæËµµÄÄǸöÓñʼǼµÄ"20 11 00 00"ô?)
Ö÷ÒªµÄ´úÂë¾ÍÊÇÕâô¶à,¿ÉÊDz»ÐÒµÄÊÂÇé·¢ÉúÁË,µ±ÎÒÓÃWINHEX°ÑÕâЩ´úÂëÌîÈëPE¿ò¼Ü²¢ÇÒ±£´æµÄʱºò,¾ÓÈ»±»É±¶¾Èí¼þɾ³ýÁË!!!!ËûÃǰÑÕâ¸ö¿´×÷²¡¶¾????ÏëÀ´Ð´²¡¶¾ÔÀ´ÊÇÕâôÈÝÒ×µÄÊÂÇé(.....Ò»_Ò».)....
ÐÒºÃÓб¸·Ý(Èç¹ûûÓÐ,ÎÒ¿ÉÊÇÒª¿ÞËÀÁË.....),ÎÒÐÞ¸ÄÁËÕâЩ´úÂë,¼ÓÈëÁËһЩÀ¬»ø(±ÈÈçMOV EAX,1Ö®ÁеÄ)...×îÖյijɯ·´úÂëÊÇ:
´úÂë
B8 01000000 ;mov eax,1
6A 00 ;push 0
6A 00 ;push 0
68 D0114000 ;push D0114000 ;Ö¸ÏòÄã±£´æµÄ±¾µØÂ·¾¶×Ö·û´®µÄλÖÃ,±¾ÎÄÖÐÊÇ"c:\\gl123\\00204.jpg",×¢ÒâÊÇË«¸Ü.
68 A0114000 ;push A0114000 ;Ö¸ÏòÒªÏÂÔØµÄURL×Ö·û´®±£´æµÄλÖÃ
6A 00 ;push 0
E8 02000000 ;call 02000000 ;Ò²¾ÍÊǺô½ÐÏÂÁ½¸ö×ֽڵĵØÖ·,ÕâÊÇ»úÆ÷Öе÷Óú¯ÊýµÄͨ³£×ö·¨
C9 ;leave
C3 ;ret
FF25 20114000 ;jmp 20114000 ;Õâ¸öÌø×ªµØÖ·¾ÍÊÇ"20 11 00 00",ÖÁÓÚÄǸö"40",
;¾ÍÊdzÌÐòµÄ½¨ÒéÆðʼ¼ÓÔØµØÖ·"00400000".ÁíÍâ,ÕâÀïÊǷ»úÆ÷¸ñʽ.
00
00
00
00
½«ËûÃÇдÈëÄÄÀïÄØ?Õâ¸ö¾ÍËæ±ãÄãÁË,²»¹ýÇë··ÉÏÃæËµµÄ,ÓиöµØÖ·ÊÇ(Ò²¾ÍÊÇ×¢Òâ1ËùÔÚµÄλÖÃ)AddressOfEntryPoint:Õâ¸ö¾ÍÊÇÓÃÀ´¶¨Î»Äã´úÂëµÄÖ´ÐÐÈë¿ÚµÄ,ÎÒÃǾͷÅÔÚµ¼Èë±íµÄºóÃæ,Ò²¾ÍÊÇ"00000179H"µÄλÖÃ.
×îºó¾ÍÊÇÄÇÁ½¸ö×Ö·û´®µÄµØÖ·ÁË,ÎÒÃÇÔÚ³ÌÐòÖÐÒѾ¸ø³ö
´úÂë
68 D0114000
68 A0114000
ÄÇÕâÁ½¸ö×Ö·û´®µÄλÖþÍÈ·¶¨ÁË,Ò»¸öÊÇ"000001D0H",ÎÒÃÇÒªÏÂÔØµÄÎļþµØÖ·"http://www.sergeaura.net/TGP/002/images/04.jpg"¾ÍÊÇ·ÅÔÚÕâÀï,ÁíÍâÒ»¸öÊÇ"0000010A"µÄλÖÃ,ÎÒÃÇÒª±£´æµ½µÄ±¾µØÂ·¾¶"C:\\GL123\\00204.JPG"¾ÍÊDZ£´æµ½ÕâÀï..ÕâÀïÎÒÿ¸ö·ÖÅäÁË48×Ö½Ú´æ´¢ÇøÓò,´ó¼ÒÒ²¿ÉÒÔ¸ù¾Ý¾ßÌåÐèÒªÉèÖÃ.±ðÍüÁË»¹ÓÐdosÍ·²¿¿ÉÒÔ±£´æ56×ֽڵĿհ׿ÉÒÔдÊý¾Ý,Èç¹ûÐèÒªµÄ»°,ÐÞ¸ÄÖ¸Ïò¾ÍÊÇ.
¶ÔÓÚÉÏÃæµÄÕâÒ»¶Ñ·Ï»°,ÎÒµÄÄ¿µÄÊÇÏëÈôó¼ÒÃ÷°×,¶ø¹ÊÒâ½éÉܵĸñʽ,¼´ÊÇ˵,Èç¹ûÈÃÄã»»×öÆäËûµÄAPIº¯ÊýÒ²ÄÜÇáÒ׵ĵ÷ÓÃ,¶ø²»ÊǾÖÏÞÓÚURLDownloadToFile.^_^...±ÈÈçÄÇЩ...ÄÇЩ...¹¦Äܰ¡....(ÎÒ¿Éû˵°¡...ºÙºÙ)..
OK,Õâ¸öPEÎļþ×îºóµÄ³ÉÐÎPE¿ò¼ÜÊÇÕâÑùµÄ:
´úÂë
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000000 4D 5A 00 00 00 00 00 00 00 00 00 00 00 00 00 00 MZ..............
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000030 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 ............@...
00000040 50 45 00 00 4C 01 02 00 00 00 00 00 00 00 00 00 PE..L...........
00000050 00 00 00 00 70 00 0F 01 0B 01 00 00 00 02 00 00 ....p...........
00000060 00 00 00 00 00 00 00 00 79 01 00 00 00 00 00 00 ........y.......
00000070 00 00 00 00 00 00 40 00 00 10 00 00 00 02 00 00 ......@.........
00000080 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 ................
00000090 00 30 00 00 00 02 00 00 00 00 00 00 02 00 00 00 .0..............
000000A0 00 01 00 00 00 00 00 00 00 01 00 00 00 10 00 00 ................
000000B0 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................
000000C0 28 11 00 00 28 00 00 00 00 00 00 00 00 00 00 00 (...(...........
000000D0 00 02 00 00 00 10 00 00 00 02 00 00 00 01 00 00 ................
000000E0 00 00 00 00 00 00 00 00 00 00 00 00 60 00 00 60 ............`..`
000000F0 00 00 00 00 00 00 00 00 02 00 00 00 00 20 00 00 ............. ..
00000100 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000110 00 00 00 00 60 00 00 60 00 00 00 00 00 00 00 00 ....`..`........
00000120 58 11 00 00 00 00 00 00 50 11 00 00 00 00 00 00 X.......P.......
00000130 00 00 00 00 6E 11 00 00 20 11 00 00 00 00 00 00 ....n... .......
00000140 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000150 58 11 00 00 00 00 00 00 31 00 55 52 4C 44 6F 77 X.......1.URLDow
00000160 6E 6C 6F 61 64 54 6F 46 69 6C 65 41 00 00 75 72 nloadToFileA..ur
00000170 6C 6D 6F 6E 2E 64 6C 6C 00 B8 01 00 00 00 6A 00 lmon.dll.?...j.
00000180 6A 00 68 D0 11 40 00 68 A0 11 40 00 6A 00 E8 02 j.h?@.h?@.j.?
00000190 00 00 00 C9 C3 FF 25 20 11 40 00 00 00 00 00 00 ...ÉÃÿ% .@......
000001A0 68 74 74 70 3A 2F 2F 77 77 77 2E 73 65 72 67 65 http://www.serge
000001B0 61 75 72 61 2E 6E 65 74 2F 54 47 50 2F 30 30 32 aura.net/TGP/002
000001C0 2F 69 6D 61 67 65 73 2F 30 34 2E 6A 70 67 00 00 /images/04.jpg..
000001D0 43 3A 5C 5C 47 4C 31 32 33 5C 5C 30 30 32 30 34 C:\\GL123\\00204
000001E0 2E 4A 50 47 00 00 00 00 00 00 00 00 00 00 00 00 .JPG............
000001F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
¼òµ¥µÄÔËÐÐÒ»ÏÂÕâ¸öPEÎļþ,ͼƬÒѾ±»ÏÂÔØµ½CÅ̵ÄGL123Îļþ¼Ð,˵Ã÷ÎÒÃǵŤ×÷»¹Êdzɹ¦µÄ¹þ.(ÍÛ,ºÃsexµÄMM°¡,¿ÚË®Á÷°¡Á÷.....)
Áù.°ü×°
µ½ÕâÀ↑ʼ,ÎÒÃǵÄEXEÊÇÓÐÁË,ÏÖÔÚ¿ªÊ¼DEBUG³ö³¡,ÎÒÃǵļƻ®ÊÇÓÃEÃüÁîдÈëÕû¸öPEÎļþÊý¾Ý,È»ºóÓÃWÃüÁî±£´æµ½ÁÙʱÎļþÖÐ,ÓÚÊǾͳɾÍÁËÕâ¸öÔʼBATÎļþ:
´úÂë
;echo off
;DEBUG<%~s0>nul2>nul
;GOTO BEGIN
E 100 4D 5A 00 00 00 00 00 00 00 00 00 00 00 00 00 00
E 110 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
......
......ÕâÀïÊ¡ÂÔÈô¸É
......
RCX
200
N E:\tmp\tmp99.TMP
W
Q
:BEGIN
rename E:\tmp\tmp99.TMP tmp99.EXE>nul2>nul
call E:\tmp\tmp99.EXE
del E:\tmp\tmp99.EXE>nul2>nul
²»¹ýÕâÑùºÜ²»ÃÀ¹Û...ÓÚÊÇÎÒÓÖÏëÁËÒ»¸ö°ì·¨ÓÅ»¯,ÓÃFÃüÁîÏòÌî³ä512¸ö00,È»ºóÔÙÔÚÏà¶ÔλÖÃдÈëÐèÒªµÄÊý¾Ý,ÓÚÊǺõ¾ÍÉú³ÉÁËÏÂÔØbat½Å±¾µÄbate1°æ±¾,Õâ¸öÊÇÍêÕûµÄÅú´¦ÀíÎļþÁË:
´úÂë
;ECHO OFF
;DEBUG<%~s0>nul2>nul
;GOTO BEGIN
E 100 4D 5A
F 102 2FF 00
E 13C 40 00 00 00 50 45 00 00 4C 01 02
E 154 70 00 0F 01 0B 01 00 00 00 02
E 168 79 01
E 176 40 00 00 10 00 00 00 02
E 188 04 00 00 00 00 00 00 00 00 30 00 00 00 02
E 19C 02 00 00 00 00 01
E 1A9 01 00 00 00 10 00 00 00 00 00 00 02
E 1C0 28 11 00 00 28
E 1D1 02 00 00 00 10 00 00 00 02 00 00 00 01
E 1EC 60 00 00 60
E 1F8 02 00 00 00 00 20 00 00 00 02
E 214 60 00 00 60
E 220 58 11 00 00 00 00 00 00 50 11
E 234 6E 11 00 00 20 11
E 250 58 11 00 00 00 00 00 00 31 00 55 52 4C 44 6F 77
E 260 6E 6C 6F 61 64 54 6F 46 69 6C 65 41 00 00 75 72
E 270 6C 6D 6F 6E 2E 64 6C 6C 00 B8 01 00 00 00 6A 00
E 280 6A 00 68 D0 11 40 00 68 A0 11 40 00 6A 00 E8 02
E 293 C9 C3 FF 25 20 11 40
E 2A0 "http://www.sergeaura.net/TGP/002/images/04.jpg"
E 2D0 "C:\\GL123\\00204.JPG"
RCX
200
N E:\tmp\tmp99.TMP
W
Q
:BEGIN
rename E:\tmp\tmp99.TMP tmp99.EXE>nul2>nul
call E:\tmp\tmp99.EXE
del E:\tmp\tmp99.EXE>nul2>nul
ÔËÐÐÕâ¸öBAT,ÔںܿìµÄÒ»ÉÁ¶ø¹ýµÄÆÁÄ»ºó,ͼƬ±»°²È»µÄÏÂÔØµ½ÎÒµÄÓ²ÅÌÉÏ....´ó¹¦¸æ³ÉÁË...¸ßÐËÄÇ..
ÕâÆªÎĵµÕâÀïҪ˵µÄ¶«Î÷ÒѾȫ²¿ËµÍêÁË,ÓÃÉÏÃæÕâ¸öÅú´¦ÀíÎĵµ¾Í¿ÉÒÔʵÏÖÈÎÒâµÄÏÂÔØÍøÂçÉϵĶ«Î÷,µ«ÊÇҪעÒâµÄ¼¸µã¾ÍÊÇ,ÏÂÔØµØÖ·µÄURLµÄ³¤¶È,Èç¹ûÄã¾õµÃºÜ³¤,ÄÇôҪµ÷ÕûPE¸ñʽÀ´´ïµ½¼æÈÝÄãURL³¤¶ÈµÄÄ¿µÄ,±£´æµØÖ·»ù±¾ÉϺÍURLÊÇÒ»ÑùµÄ.
Æß.С½Ú
ÌÈÈôÕâÑù½áÊøµÄ»°,´ó¶àÊýÈËҲûÓÐÒâ¼û,¿ÉϧÕâÆªÎĵµ¾ÍÏԵò»ÍêÕûÁË...ΪÁËÈÃÕâ¼Ç¼ʽµÄÎĵµ¸ü¼ÓÍêÕû,ÎÒ¾ÍÓÃÏÂÔØMMÕâ¸öʼþ×÷ʾÀý,À´ÑÝʾÈçºÎÓÃÉÏÃæµÄÕâ¸öBATʵÏÖÅúÁ¿ÏÂÔØµÄ¹¦ÄÜ,×÷Ϊ¶ÔÕâ¸öÎĵµµÄС½Ú,ÒÔο᧸÷λ¿´¹ÙÐÁÇÚµÄË«ÑÛ.(...^_^)
Ê×Ïȸø³öÕû¸öÅú´¦Àí´úÂë:
´úÂë
echo off
setlocal
cd\
cd %~d0%~p0
mkdir tmp >nul 2>nul
mkdir c:\gl123 >nul 2>nul
set szTEMPfile=tmp99
set szTEMPpath=%~d0%~p0tmp
echo @ECHO OFF>gf.bat
echo SETLOCAL>>gf.bat
echo cd\>>gf.bat
echo cd %%^~d0%%^~p0>>gf.bat
echo SET szURLfolder=00%%1>>gf.bat
echo SET szURLfolder=%%szURLfolder:^~-3%%>>gf.bat
echo SET szURLfile=0%%2>>gf.bat
echo SET szURLfile=%%szURLfile:^~-2%%>>gf.bat
echo SET szURLgetfile=http://www.sergeaura.net/TGP/%%szURLfolder%%/images/%%szURLfile%%.jpg>>gf.bat
echo SET szLOCALfile=C:\\GL123\\%%szURLfolder%%%%szURLfile%%.JPG>>gf.bat
echo ECHO;echo off^>dl.bat>>gf.bat
echo ECHO;DEBUG^^^<%%%%^^^~s0^^^>nul2^^^>nul^>^>dl.bat>>gf.bat
echo ECHO;GOTO RUN^>^>dl.bat>>gf.bat
echo ECHO E 100 4D 5A^>^>dl.bat>>gf.bat
echo ECHO F 102 2FF 00^>^>dl.bat>>gf.bat
echo ECHO E 13C 40 00 00 00 50 45 00 00 4C 01 02^>^>dl.bat>>gf.bat
echo ECHO E 154 70 00 0F 01 0B 01 00 00 00 02^>^>dl.bat>>gf.bat
echo ECHO E 168 79 01^>^>dl.bat>>gf.bat
echo ECHO E 176 40 00 00 10 00 00 00 02^>^>dl.bat>>gf.bat
echo ECHO E 188 04 00 00 00 00 00 00 00 00 30 00 00 00 02^>^>dl.bat>>gf.bat
echo ECHO E 19C 02 00 00 00 00 01^>^>dl.bat>>gf.bat
echo ECHO E 1A9 01 00 00 00 10 00 00 00 00 00 00 02^>^>dl.bat>>gf.bat
echo ECHO E 1C0 28 11 00 00 28^>^>dl.bat >>gf.bat
echo ECHO E 1D1 02 00 00 00 10 00 00 00 02 00 00 00 01^>^>dl.bat>>gf.bat
echo ECHO E 1EC 60 00 00 60^>^>dl.bat>>gf.bat
echo ECHO E 1F8 02 00 00 00 00 20 00 00 00 02^>^>dl.bat>>gf.bat
echo ECHO E 214 60 00 00 60^>^>dl.bat>>gf.bat
echo ECHO E 220 58 11 00 00 00 00 00 00 50 11^>^>dl.bat>>gf.bat
echo ECHO E 234 6E 11 00 00 20 11^>^>dl.bat>>gf.bat
echo ECHO E 250 58 11 00 00 00 00 00 00 31 00 55 52 4C 44 6F 77^>^>dl.bat>>gf.bat
echo ECHO E 260 6E 6C 6F 61 64 54 6F 46 69 6C 65 41 00 00 75 72^>^>dl.bat>>gf.bat
echo ECHO E 270 6C 6D 6F 6E 2E 64 6C 6C 00 B8 01 00 00 00 6A 00^>^>dl.bat>>gf.bat
echo ECHO E 280 6A 00 68 D0 11 40 00 68 A0 11 40 00 6A 00 E8 02^>^>dl.bat>>gf.bat
echo ECHO E 293 C9 C3 FF 25 20 11 40^>^>dl.bat>>gf.bat
echo ECHO E 2A0 "%%szURLgetfile%%"^>^>dl.bat>>gf.bat
echo ECHO E 2D0 "%%szLOCALfile%%"^>^>dl.bat>>gf.bat
echo ECHO RCX^>^>dl.bat>>gf.bat
echo ECHO 200^>^>dl.bat>>gf.bat
echo ECHO N %szTEMPpath%\%szTEMPfile%.TMP^>^>dl.bat>>gf.bat
echo ECHO W^>^>dl.bat>>gf.bat
echo ECHO Q^>^>dl.bat>>gf.bat
echo ECHO :RUN^>^>dl.bat>>gf.bat
echo ECHO rename %szTEMPpath%\%szTEMPfile%.TMP %szTEMPfile%.EXE^^^>nul2^^^>nul^>^>dl.bat>>gf.bat
echo ECHO call %szTEMPpath%\%szTEMPfile%.EXE^>^>dl.bat>>gf.bat
echo ECHO del %szTEMPpath%\%szTEMPfile%.EXE^^^>nul2^^^>nul^>^>dl.bat>>gf.bat
echo ECHO DOWNLOAD %%szURLgetfile%% ==^^^> %%szLOCALfile%%>>gf.bat
echo CALL dl.bat>>gf.bat
echo ECHO ...OK!>>gf.bat
echo ENDLOCAL>>gf.bat
:echo @ECHO ON>>gf.bat
for /l %%i in (1,1,162) do for /l %%j in (1,1,12) do call gf.bat %%i %%j
del gf.bat>nul 2>nul
del dl.bat>nul 2>nul
rmdir tmp>nul 2>nul
echo ALL OK!
endlocal
echo on
Èç¹û¿´¶®ÁËÇ°ÃæµÄÄǸöµ±¸öÏÂÔØµÄÅú´¦Àí´úÂë,ÄÇÕâ¸ö»ù±¾ÉÏÊÇûÓÐÎÊÌâµÄÁË.
Õâ¸öÅú´¦ÀíµÄ¹¤×÷²½Öè:
1.ÔËÐкó»áÔÚÄãcÅ̽¨Á¢Ò»¸ö"gl123"µÄÎļþ¼Ð,ÓÃÀ´±£´æÏÂÔØµÄͼƬµÄ(ÕâÒ²ÊÇΨһµÄȱµã,ÎÒÎÞ·¨Ð´³É×Ô¶¨ÒåÎļþ¼Ð... )
2.½Ó×Å»áÔÚµ±Ç°Ä¿Â¼ÅÉÉú³öÁ½¸ö×ÓÅú´¦ÀíÎļþºÍÒ»¸ö"tmp"µÄÁÙʱĿ¼...
3.Ö®ºó¿ªÊ¼Ñ»·ÏÂÔØËùÓеÄͼƬ,²¢ÏÔʾ½ø¶È,Íê³ÉºóÏÔʾ"ALL OK".
4.ɾ³ýËùÓеÄÁÙʱÎļþ.
¶ÔÕâ¸öbat»ìºÍÉÏÒ»¸öÖеÄһЩµØ·½,ÎÒͳһ½âÊÍÒ»ÏÂ:
1.RCXÊÇDEBUGµÄд¼Ä´æÆ÷CXÃüÁî,°ÑÎÒÃÇҪдÈëµÄÎļþ´óС¸³Öµ¸øËû,È»ºóµ÷ÓÃNÃüÁî¸ø³öÎļþÃûºóÓÃWдÈë»òÕßL¼ÓÔØ,
2.QºóÃæÒª±£Áô»Ø³µ(Äã×ܲ»ÏëbatÎļþ»Ø²»À´°É...),
3.>nulºÍ2>nulÊÇ˵°ÑÊä³öºÍ´íÎóÊä³öÈ«²¿ÆÁ±Î...ÄãÒ²²»ÏëÔÚÏÂÔØµÄʱºò³öÏÖ"1 file(s) copy.."ÕâÑùµÄÌáʾ°É..
4.Èç¹ûÊÇÌØÊâ×Ö·ûÒªÔÚÇ°Ãæ¼ÓÉÏתÒåµÄ"^"·ûºÅ·½¿ÉдÈëÎļþ
5.¶ÔÓÚÎļþµØÖ·µÝÔöÀàÐͺ¬0µÄµØÖ·,±ÈÈçhttp://www.xxx.com/0001.jpg,http://www.xxx.com/0002.jpg......ÕâÑùµÄ¸ñʽ,ºÜ¶àÈËÓÃÅжÏÕâ¸öÖµÊÇСÓÚ9,¼ÓÈý¸ö0,´óÓÚ9,СÓÚ99,¾Í¼Ó2¸ö0,´óÓÚ99,СÓÚ999,¾Í¼ÓÈý¸ö0.....¶øÎҵķ½·¨ÊÇͳһÔÚÕâ¸öÊýÖµÇ°Ãæ¼ÓÉÏ×ã¹»µÄ0,È»ºóÔÙ½ØÈ¡Õû¸ö×Ö·û´®µÄ×îºó4λ,Ïà¶ÔÀ´Ëµ±È½ÏÊ¡´úÂë.
6.for¿ÉÒÔǶÌ×ʹÓÃ,¹¹³ÉNÖØÑ»·,µ«ÊÇÓиöȱµã,FORÄÚ²»¿ÉÒÔÓÃSET...(¾ßÌå¿´°ïÖú,×ÜÖ®ºÜÂé·³...Ò»_Ò»..ÕâÒ²ÊÇÎÒÓöà¸öBATʵÏÖµÄÔÒò)
7.ÓÃÅú´¦ÀíÎļþ´¦ÀíÎļþ²¿·Ö(°üÀ¨Ð½¨ºÍɾ³ýĿ¼)֮ǰ×îºÃÏȽøÈ뵱ǰĿ¼һ´Î,±¾Åú´¦ÀíÓÃcd\ºÍcd %~d0%~p0À´Íê³É
8.cd %~d0%~p0ÖеÄ%~d0»·¾³±äÁ¿ÊǶÔ%0±äÁ¿µÄÀ©Õ¹,À©Õ¹Îªµ±Ç°Çý¶¯Æ÷ÅÌ·û,%~p0ÊÇÀ©Õ¹Îªµ±Ç°Ä¿Â¼,ÆäËûµÄ¾Í¿´windowÃüÁîÐаïÖúÎĵµ.
9.Ñø³Éϰ¹ßÓÃSETLOCALºÍENDLOCAL°ü¹üÕû¸öÅú´¦Àí.
10.ÒòΪ±¾µØ×Ö·û´®ÔÚÄÚ´æÖÐÊÇÒÔË«¸Ü±£´æµÄ,¶øÔÚÅú´¦ÀíÖÐÊÇÒÔµ¥¸Ü±£´æµÄ,ҪʵÏÖÕâ¸öת»»±ØÐëÒªÏ൱¶àµÄ´úÂë(Åú´¦Àí¶ÔÎı¾µÄ´¦ÀíÄÜÁ¦¼«Èõ...Ò»_Ò»..),ËùÒÔÎÒ¾ÍûÓÐд.
°Ë.ºó¼Ç
Æäʵ±¾ÎĵıêÌâÍêÈ«¿ÉÒÔ¸ÄΪ:ÓÃÅú´¦Àíµ÷ÓÃAPI,µ«ÊÇÎÒ¾õµÃÕâÑù̫ûÊÂÕÒÊÂÁË,±Ï¾¹µ÷ÓÃAPI»¹ÊÇд³ÌÐòÀ´µÄ·½±ã.ÁíÍâΪÁËÈû±¥ÕâÆªÎĵµ,¼ÓÈëÁËÏ൱¶àµÄPE¸ñʽ·ÖÎö,ËäÈ»ºÍ±¾ÎÄÓÐÒ»µãµã¹ØÏµ...µ«»¹ÊǾõµÃÓеãÐú±ö¶áÖ÷¹þ...
Íê³ÉÁËÕâЩ¹¦Äܺó,Éî¿ÌµÄ¸ÐÊܵ½ÄÇЩÔڵײ㹤×÷µÄÈËÔ±ÊǶàôµÄÐÁ¿à°¡......ÏëÀ´ÎÒÄÜÓÃVCд³ÌÐò,ÕâÒѾÊÇÒ»¼þ·Ç³£ÐÒ¸£µÄËĶùÁË...(˵µ½ÕâÀïZV͵͵µÄÄóöСÊÖ¾î²ÁÁ˲Á....Òª³ÉΪ¸ßÊÖ!¾ÍÒªÈÌÊܱðÈ˲»ÄÜÈÌÊܵĿà,ÓÚÊÇZVÓÃÑÌÍ·ÔÚÊÖ±ÛÉÏ....º¹,ºÜÍ´µÄ,µ±È»Ã»ÓÐ~~~¹þ¹þ)..
ÎÄÕÂÀïÓõ½µÄÁ½¸öÖ÷ÒªµÄ¹¤¾ß¶¼ÊÇ΢ÈíÀúÊ·ÉϵÄÀÏǰ±².³¤Äê²»¼ûËûÃǻ,´ø³öÀ´ÁïÁï½ÅÒ²ËãÊǶÔÕâЩ¿ì±»ÒÅÍüµÄ¼¼ÊõµÄ»³Äî(¾Ý˵µ±ÄêUCDOSϵÄWPS¾ÍÊÇijţÈËÓÃDEBUGд³öÀ´µÄ,PFµÄ½ô°¡,,Ò»_Ò»...),ÆäʵWindowsËäÈ»²»¿ª·Å,»¹ÊǺÜÓÐÒâ˼µÄ,ºÇºÇ.
×îºó,ÔÚÕâÆªÈß³¤µÄ,Ó·Ö×µÄ,¼ÐÔÓ×ÅÎÞÊý´íÎó,À¬»ø,³Ï®,ºýŪ,³Â´ÊÀĵ÷,ÓïÑÔ²»Í¨µÄ1.5Íò×ÖÀï,µÄµÄÈ·È·°üº¬ÁË×÷ÕßµÄһЩÐÄѪ,¸Ðл´ó¼Ò»¨ÁËÕâô¶àʱ¼ä¿´µ½ÕâÀï,Èç¹û¾õµÃÓÐÄÄÅÂÓÐÄÇôһµãµãµÄÊÕ»ñ,»Ø¸öÌû×ÓËãÊǶÔÎҵĹÄÀø°É,²»È»Ð´¸ö"ÐÁ¿àÁË",Ò²ÊǶÔÎÒµÄÒ»µãµã°²Î¿..^_^..

