程序中还有几处,没有全列出来,但与此类似.
0012F4F0 100022FF /CALL 到 CreateFileA 来自 win32dll.100022FD
0012F4F4 0012F620 |FileName = "\\.\NTICE"
0012F4F8 80000000 |Access = GENERIC_READ
0012F4FC 00000001 |ShareMode = FILE_SHARE_READ
0012F500 00000000 |pSecurity = NULL
0012F504 00000003 |Mode = OPEN_EXISTING
0012F508 00000020 |Attributes = ARCHIVE
0012F50C 00000000 \hTemplateFile = NULL
0012F4F0 100022FF /CALL 到 CreateFileA 来自 win32dll.100022FD
0012F4F4 0012F620 |FileName = "\\.\SICE"
0012F4F8 80000000 |Access = GENERIC_READ
0012F4F0 100022FF /CALL 到 CreateFileA 来自 win32dll.100022FD
0012F4F4 0012F620 |FileName = "\\.\TRW"
0012F4F8 80000000 |Access = GENERIC_READ
0012F4FC 00000001 |ShareMode = FILE_SHARE_READ
0012F4F0 100022FF /CALL 到 CreateFileA 来自 win32dll.100022FD
0012F4F4 0012F620 |FileName = "\\.\TRWDEBUG"
0012F4F8 80000000 |Access = GENERIC_READ
0012F4FC 00000001 |ShareMode = FILE_SHARE_READ
0012F4F0 100022FF /CALL 到 CreateFileA 来自 win32dll.100022FD
0012F4F4 0012F620 |FileName = "\\.\ICEDUMP"
0012F4F8 80000000 |Access = GENERIC_READ
0012F4FC 00000001 |ShareMode = FILE_SHARE_READ
以往的修改方式怕要改改了.呵呵.
1000E97D MOV ESI,DWORD PTR SS:[EBP+8]
1000E980 MOV AL,BYTE PTR DS:[ESI] ; 比较读狗程序中是否加了断点
1000E982 CMP AL,0CC
1000E984 JE SHORT win32dll.1000E98A
换汤不换药的东东.
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课