<dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><small id="yhprb"></small><dfn id="yhprb"></dfn><small id="yhprb"><delect id="yhprb"></delect></small><small id="yhprb"></small><small id="yhprb"></small> <delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"></dfn><dfn id="yhprb"></dfn><s id="yhprb"><noframes id="yhprb"><small id="yhprb"><dfn id="yhprb"></dfn></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><small id="yhprb"></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn> <small id="yhprb"></small><delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn>

新聞中心

EEPW首頁(yè) > 嵌入式系統 > 設計應用 > 木馬/后門(mén)程序在WINNT中進(jìn)程隱藏及查找的方法

木馬/后門(mén)程序在WINNT中進(jìn)程隱藏及查找的方法

作者: 時(shí)間:2012-07-02 來(lái)源:網(wǎng)絡(luò ) 收藏

 // 計算目前有多少, aProcesses[]用來(lái)存放有效的PIDs

本文引用地址:http://dyxdggzs.com/article/148821.htm

  if ( !EnumProcesses( aProcesses, sizeof(aProcesses), cbNeeded ) ) return 0;

  cProcesses = cbNeeded / sizeof(DWORD);

  // 按有效的PID遍歷所有的

  for ( i = 0; i cProcesses; i++ )

  {

  // 打開(kāi)特定PID的進(jìn)程

  hProcess = OpenProcess( PROCESS_QUERY_INFORMATION |

  PROCESS_VM_READ,

  FALSE, aProcesses[i]);

  // 取得特定PID的進(jìn)程名

  if ( hProcess )

  {

  if ( EnumProcessModules( hProcess, hMod, sizeof(hMod), cbNeeded) )

  {

  GetModuleBaseName( hProcess, hMod,

  szProcessName, sizeof(szProcessName) );

  //將取得的進(jìn)程名與輸入的進(jìn)程名比較,如相同則返回進(jìn)程PID

  if(!_stricmp(szProcessName, InputProcessName)){

  CloseHandle( hProcess );

  return aProcesses[i];

  }

  }

  }//end of if ( hProcess )

  }//end of for

  //沒(méi)有找到相應的進(jìn)程名,返回0

  CloseHandle( hProcess );

  return 0;

  }//end of ProcessToPID

  //錯誤處理函數CheckError()

  //如果iReturnCode等于iErrorCode,則輸出pErrorMsg并退出

  void CheckError(int iReturnCode, int iErrorCode, char *pErrorMsg)

  {

  if(iReturnCode==iErrorCode) {

  printf(%s Error:%dnn, pErrorMsg, GetLastError());

  //清場(chǎng)處理

  if (pszLibFileRemote != NULL)

  VirtualFreeEx(hRemoteProcess, pszLibFileRemote, 0, MEM_RELEASE);

  if (hRemoteThread != NULL) CloseHandle(hRemoteThread );

  if (hRemoteProcess!= NULL) CloseHandle(hRemoteProcess);

  exit(0);

  }

  }//end of CheckError()

  //使用說(shuō)明函數usage()

  void usage(char * pErrorMsg)

  {

  printf(%snn,pErrorMsg);

  printf(ttRemote Process DLL by Shotgunn);

  printf(tThis program can inject a DLL into remote processn);

  printf(Email:n);

  printf(tShotgun@Xici.Netn);

  printf(HomePage:n);

  printf(thttp://It.Xici.Netn);

  printf(thttp://www.Patching.Netn);

  printf(USAGE:n);

  printf(tRmtDLL.exe PID[|ProcessName] DLLFullPathNamen);

  printf(Example:n);

  printf(tRmtDLL.exe 1024 C:System32MyDLL.dlln);

  printf(tRmtDLL.exe Explorer.exe C:MyDLL.dlln);

  exit(0);

  }//end of usage()


上一頁(yè) 1 2 3 下一頁(yè)

評論


相關(guān)推薦

技術(shù)專(zhuān)區

關(guān)閉
国产精品自在自线亚洲|国产精品无圣光一区二区|国产日产欧洲无码视频|久久久一本精品99久久K精品66|欧美人与动牲交片免费播放
<dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><small id="yhprb"></small><dfn id="yhprb"></dfn><small id="yhprb"><delect id="yhprb"></delect></small><small id="yhprb"></small><small id="yhprb"></small> <delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"></dfn><dfn id="yhprb"></dfn><s id="yhprb"><noframes id="yhprb"><small id="yhprb"><dfn id="yhprb"></dfn></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><small id="yhprb"></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn> <small id="yhprb"></small><delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn>