能力值:
( LV2,RANK:10 )
|
-
-
2 楼
拿个进程工具,查看B程序运行参数
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
楼上推荐个软件,刚才搜了个有毒
|
能力值:
( LV2,RANK:10 )
|
-
-
4 楼
如果程序B没加VM的话, 分析一下应该就能知道个大概了。
如果程序B被VM了,那就杯具了一半了,程序A启动程序B,关于参数的传递有很多方法的,一种是直接传递参数,这个还好弄。还有其他方法,比如,程序A创建映射,然后把一些需要传递的数据加密写入这个映射地址中,程序B打开这个映射地址,验证映射内容的合法性,这就难搞了。
|
能力值:
( LV2,RANK:10 )
|
-
-
5 楼
11:43:33 Explorer.EXE:1636 OPEN C:\Program Files\Filemon\Filemon.exe SUCCESS Options: Open Access: Read-Attributes
11:43:33 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Filemon\Filemon.exe SUCCESS Attributes: A
11:43:33 Explorer.EXE:1636 CLOSE C:\Program Files\Filemon\Filemon.exe SUCCESS
11:43:33 Explorer.EXE:1636 OPEN C:\Program Files\Filemon\Filemon.exe SUCCESS Options: Open Access: Read-Attributes
11:43:33 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Filemon\Filemon.exe SUCCESS Attributes: A
11:43:33 Explorer.EXE:1636 CLOSE C:\Program Files\Filemon\Filemon.exe SUCCESS
11:43:33 Explorer.EXE:1636 OPEN C:\Program Files\Filemon\Filemon.exe SUCCESS Options: Open Access: Read-Attributes
11:43:33 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Filemon\Filemon.exe SUCCESS Attributes: A
11:43:33 Explorer.EXE:1636 CLOSE C:\Program Files\Filemon\Filemon.exe SUCCESS
11:43:33 Explorer.EXE:1636 OPEN C:\Program Files\Filemon\Filemon.exe SUCCESS Options: Open Access: 00100020
11:43:33 Explorer.EXE:1636 OPEN C:\Program Files\Filemon\Filemon.exe SUCCESS Options: Open Access: 00100001
11:43:33 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Filemon\Filemon.exe SUCCESS FileInternalInformation
11:43:33 Explorer.EXE:1636 CLOSE C:\Program Files\Filemon\Filemon.exe SUCCESS
11:43:33 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Filemon\Filemon.exe SUCCESS Length: 741376
11:43:33 Explorer.EXE:1636 CLOSE C:\Program Files\Filemon\Filemon.exe SUCCESS
11:43:33 Explorer.EXE:1636 OPEN C:\Program Files\Filemon\Filemon.exe SUCCESS Options: Open Access: Read-Attributes
11:43:33 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Filemon\Filemon.exe SUCCESS Attributes: A
11:43:33 Explorer.EXE:1636 CLOSE C:\Program Files\Filemon\Filemon.exe SUCCESS
11:43:33 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 8192
11:43:33 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 8192
11:43:33 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 16384
11:43:37 svchost.exe:1200 OPEN C:\WINDOWS\EXPLORER.EXE SUCCESS Options: Open Access: Read-Attributes
11:43:37 svchost.exe:1200 QUERY INFORMATION C:\WINDOWS\EXPLORER.EXE SUCCESS Attributes: A
11:43:37 svchost.exe:1200 CLOSE C:\WINDOWS\EXPLORER.EXE SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100020
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100001
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileInternalInformation
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100001
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileInternalInformation
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100020
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100001
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileInternalInformation
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read
11:43:37 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100001
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileInternalInformation
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:37 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:37 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC SUCCESS Attributes: D
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 001000A1
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100001
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileInternalInformation
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileNameInformation
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\ SUCCESS Options: Open Directory Access: 00100001
11:43:38 Explorer.EXE:1636 DIRECTORY C:\Program Files\ SUCCESS FileBothDirectoryInformation: Utility
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\ SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\ SUCCESS Options: Open Directory Access: 00100001
11:43:38 Explorer.EXE:1636 DIRECTORY C:\Program Files\Utility\ SUCCESS FileBothDirectoryInformation: Heart_NC
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\ SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\ SUCCESS Options: Open Directory Access: 00100001
11:43:38 Explorer.EXE:1636 DIRECTORY C:\Program Files\Utility\Heart_NC\ SUCCESS FileBothDirectoryInformation: DiProWin.exe
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\ SUCCESS
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe.Manifest NOT FOUND Options: Open Access: 001200A9
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe.Manifest NOT FOUND Options: Open Access: 00100001
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC SUCCESS Attributes: D
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC SUCCESS
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 20480
11:43:38 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 24576
11:43:38 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 28672
11:43:38 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 32768
11:43:38 Explorer.EXE:1636 SET INFORMATION C:\Documents and Settings\Administrator\NTUSER.DAT.LOG SUCCESS Length: 36864
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\diprowin.exe SUCCESS FileNameInformation
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\diprowin.exe SUCCESS FileNameInformation
11:43:38 diprowin.exe:2484 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe.Local NOT FOUND Options: Open Access: Read-Attributes
11:43:38 diprowin.exe:2484 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe.Local\ NOT FOUND Options: Open Access: Read-Attributes
11:43:38 diprowin.exe:2484 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 diprowin.exe:2484 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\diprowin.exe BUFFER OVERFLOW FileNameInformation
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\diprowin.exe SUCCESS FileNameInformation
11:43:38 diprowin.exe:2484 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 diprowin.exe:2484 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100020
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100001
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileInternalInformation
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 diprowin.exe:2484 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 diprowin.exe:2484 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:38 diprowin.exe:2484 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:38 diprowin.exe:2484 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:38 diprowin.exe:2484 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:41 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: Read-Attributes
11:43:41 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Attributes: A
11:43:41 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:41 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100020
11:43:41 Explorer.EXE:1636 OPEN C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Options: Open Access: 00100001
11:43:41 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS FileInternalInformation
11:43:41 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
11:43:41 Explorer.EXE:1636 QUERY INFORMATION C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS Length: 7401472
11:43:41 Explorer.EXE:1636 CLOSE C:\Program Files\Utility\Heart_NC\DiProWin.exe SUCCESS
|
能力值:
( LV2,RANK:10 )
|
-
-
6 楼
谁帮我看看上面DiProWin.exe 这个,
用filemon扫的,没见他调用另一个软件呀!但为何另一个软件不开,就执行不了他?
|
能力值:
( LV2,RANK:10 )
|
-
-
7 楼
不运行另一个软件,open file map error!然后中断
|
能力值:
( LV2,RANK:10 )
|
-
-
8 楼
这可能性万千种么, 你不如把程序上传了看看, 譬如判断父进程什么的
|
能力值:
( LV2,RANK:10 )
|
-
-
9 楼
看这个样子,是有CreateFileMapping()函数创建共享内存区,在父进程和子进程之间传递了一些数据,不好搞
|
|
|