• <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>

            S.l.e!ep.¢%

            像打了激速一樣,以四倍的速度運轉,開心的工作
            簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
            posts - 1098, comments - 335, trackbacks - 0, articles - 1
              C++博客 :: 首頁 :: 新隨筆 :: 聯系 :: 聚合  :: 管理

            About ShutDown of Windows(四)

            Posted on 2009-11-17 21:54 S.l.e!ep.¢% 閱讀(210) 評論(0)  編輯 收藏 引用 所屬分類: RootKit
            接著 About ShutDown of Windows(三)
            折騰著,沒多大收獲

            Create 了一個 MFC 的DLL

            CHookDLLApp?theApp;

            HHOOK?g_Hook?
            =?NULL;

            LRESULT?CALLBACK?MyKeyHook(
            int?code,?WPARAM?wParam,?LPARAM?lParam)
            {
            #if?(_WIN32_WINNT?<?0x0400)
            /*
            *?Structure?used?by?WH_KEYBOARD_LL
            ????
            */
            ????typedef?
            struct?tagKBDLLHOOKSTRUCT?{
            ????????DWORD???vkCode;
            ????????DWORD???scanCode;
            ????????DWORD???flags;
            ????????DWORD???time;
            ????????DWORD???dwExtraInfo;
            ????}?KBDLLHOOKSTRUCT,?FAR?
            *LPKBDLLHOOKSTRUCT,?*PKBDLLHOOKSTRUCT;
            #endif
            ????
            ????PKBDLLHOOKSTRUCT?kbDLLHOOK?
            =?(PKBDLLHOOKSTRUCT)lParam;
            ????
            ????
            const?char?*info?=?NULL;
            ????
            ????
            if?(wParam?==?WM_KEYDOWN)
            ????????info?
            =?"key?down";????
            ????
            else?if?(wParam?==?WM_KEYUP)
            ????????info?
            =?"key?up";
            ????
            else?if?(wParam?==?WM_SYSKEYDOWN)
            ????????info?
            =?"sys?key?down";????
            ????
            else?if?(wParam?==?WM_SYSKEYUP)
            ????????info?
            =?"sys?key?up";
            ????
            ????FILE
            *?f?=?fopen("hook.txt",?"a+");
            ????
            ????CString?strLog;
            ????strLog.Format(
            "%s?-?vkCode?[%04x],?[%c]?scanCode?[%04x]\n",?info,?kbDLLHOOK->vkCode,?kbDLLHOOK->vkCode,?kbDLLHOOK->scanCode);
            ????
            ????fwrite(strLog,?
            1,?strLog.GetLength(),?f);
            ????fclose(f);
            ????
            ????
            //?always?call?next?hook
            ????return?CallNextHookEx(g_Hook,?code,?wParam,?lParam);
            }??????


            void?Hook()
            {
            ????
            //?TODO:?Add?extra?initialization?here
            #ifndef?WH_KEYBOARD_LL
            #define?WH_KEYBOARD_LL?13
            #endif

            ????g_Hook?
            =?SetWindowsHookEx(WH_KEYBOARD_LL,?MyKeyHook,?AfxGetApp()->m_hInstance,?0);
            ????
            ????
            if(?g_Hook?==?NULL?)
            ????????AfxMessageBox(
            "Failed?to?Set?Hook");

            }

            ;?HookDLL.def?:?Declares?the?module?parameters?for?the?DLL.

            LIBRARY??????
            "HookDLL"
            DESCRIPTION??
            'HookDLL?Windows?Dynamic?Link?Library'

            EXPORTS
            ????;?Explicit?exports?can?go?here
            ????Hook?????????@
            1

            Create 了一個MFC的工程

            BOOL?CHookTestDlg::OnInitDialog()
            {
            ????CDialog::OnInitDialog();

            ????
            //?Add?"About"?menu?item?to?system?menu.

            ????
            //?IDM_ABOUTBOX?must?be?in?the?system?command?range.
            ????ASSERT((IDM_ABOUTBOX?&?0xFFF0)?==?IDM_ABOUTBOX);
            ????ASSERT(IDM_ABOUTBOX?
            <?0xF000);

            ????CMenu
            *?pSysMenu?=?GetSystemMenu(FALSE);
            ????
            if?(pSysMenu?!=?NULL)
            ????{
            ????????CString?strAboutMenu;
            ????????strAboutMenu.LoadString(IDS_ABOUTBOX);
            ????????
            if?(!strAboutMenu.IsEmpty())
            ????????{
            ????????????pSysMenu
            ->AppendMenu(MF_SEPARATOR);
            ????????????pSysMenu
            ->AppendMenu(MF_STRING,?IDM_ABOUTBOX,?strAboutMenu);
            ????????}
            ????}

            ????
            //?Set?the?icon?for?this?dialog.??The?framework?does?this?automatically
            ????
            //??when?the?application's?main?window?is?not?a?dialog
            ????SetIcon(m_hIcon,?TRUE);????????????//?Set?big?icon
            ????SetIcon(m_hIcon,?FALSE);????????//?Set?small?icon
            ????
            ????
            //?TODO:?Add?extra?initialization?here
            #ifndef?WH_KEYBOARD_LL
            ????
            #define?WH_KEYBOARD_LL?13
            #endif
            ????
            //?????g_Hook?=?SetWindowsHookEx(WH_KEYBOARD_LL,?MyKeyHook,?AfxGetApp()->m_hInstance,?0);
            //?????
            //?????if(?g_Hook?==?NULL?)
            //?????????AfxMessageBox("Failed?to?Set?Hook");

            ????TCHAR?szPath[MAX_PATH]?
            =?{0};
            ????GetModuleFileName(NULL,?szPath,?MAX_PATH);
            ????PathRenameExtension(szPath,?_T(
            ""));

            ????typedef?
            void?(*TYPE_pfnLoadLibrary)();
            ????TYPE_pfnLoadLibrary?pfnLoadLibrary?
            =?NULL;

            ????HMODULE?Module?
            =?LoadLibrary(szPath);
            ????pfnLoadLibrary?
            =?(TYPE_pfnLoadLibrary)GetProcAddress(Module,?"Hook");
            ????
            ????pfnLoadLibrary();

            ????
            return?TRUE;??//?return?TRUE??unless?you?set?the?focus?to?a?control
            }

            時間太緊,沒做一些異常判斷處理
            HOOK成功了,用 SysCheck 工具一看, 只看到了 HookTest.exe 里面加載了一個HookDLL.dll

            采用 injecteddll 工具也沒有看到所謂的“注入”DLL

            是否“注入”成功,不得所知
            所謂的“注入”又該怎么看到的呢?明天再解決它。
            亚洲午夜精品久久久久久app| 久久精品人人做人人爽电影| 久久久久国产一区二区三区| 欧美精品丝袜久久久中文字幕 | 国产真实乱对白精彩久久| 国产高潮国产高潮久久久91 | 久久久久亚洲av综合波多野结衣| 99精品国产免费久久久久久下载| 久久人人爽人人人人片av| 国产成人精品久久免费动漫| 久久精品成人欧美大片| 99久久精品国产一区二区| 国产精品日韩深夜福利久久 | 久久99精品久久久久久| 日韩十八禁一区二区久久| 精品久久久久久久久午夜福利| 久久99亚洲综合精品首页| www久久久天天com| 人人妻久久人人澡人人爽人人精品| 久久精品国产半推半就| 亚洲中文字幕无码久久精品1| 国内精品久久久久国产盗摄| 久久精品aⅴ无码中文字字幕重口| 久久性精品| 久久精品无码一区二区日韩AV| 久久精品人成免费| 亚洲欧美成人综合久久久| 少妇人妻综合久久中文字幕| 精品国产婷婷久久久| 久久国产一区二区| 久久99精品国产99久久6男男| 国产精品一久久香蕉国产线看观看| 7777精品伊人久久久大香线蕉| 久久国产视频99电影| 久久精品国产亚洲一区二区三区| 色综合久久88色综合天天| 99久久精品国产高清一区二区| 久久久久99精品成人片直播| 婷婷综合久久中文字幕蜜桃三电影| 精产国品久久一二三产区区别| 亚洲国产成人乱码精品女人久久久不卡 |