能力值:
( LV2,RANK:10 )
|
-
-
26 楼
ri 删除了干吗啊。。。
|
能力值:
( LV2,RANK:10 )
|
-
-
27 楼
来完了一看。全删了。。看来有好帖要及时复制下来
|
能力值:
( LV2,RANK:10 )
|
-
-
28 楼
看了UMC/UMI复制工具。。。
去分析deviceiocontrol吧。。。
0041198C: FF15AC704100 call KERNEL32.CreateFileA
00411992: 8BD8 mov ebx, eax
00411994: 83FBFF cmp ebx, FFFFFFFF
00411997: 746E je 00411A07
00411999: 8D45F4 lea eax, [ebp-0C]
0041199C: 56 push esi
0041199D: 50 push eax
0041199E: 8D45EC lea eax, [ebp-14]
004119A1: 6A08 push 00000008
004119A3: 50 push eax
004119A4: 56 push esi
004119A5: 56 push esi
004119A6: 68902A2200 push 00222A90-------------------------------------------GETID
004119AB: 53 push ebx
004119AC: FF1574704100 call KERNEL32.DeviceIoControl
004119B2: 85C0 test eax, eax
004119B4: 7508 jne 004119BE
004119B6: FF1568704100 call KERNEL32.GetLastError
004119BC: EB3F jmp 004119FD
* String: "\\.\RCUSBNT0"
00411D35: 6844C24100 push 0041C244
00411D3A: FF15AC704100 call KERNEL32.CreateFileA
00411D40: 8BF0 mov esi, eax
00411D42: 83FEFF cmp esi, FFFFFFFF
00411D45: 7507 jne 00411D4E
00411D47: B82F4E0000 mov eax, 00004E2F
00411D4C: EB3B jmp 00411D89
* Jump:
00411D45(C)
00411D4E: 8D4508 lea eax, [ebp+08]
00411D51: 57 push edi
00411D52: 8B7D0C mov edi, [ebp+0C]
00411D55: 50 push eax
00411D56: 6807010000 push 00000107
00411D5B: 57 push edi
00411D5C: 6815010000 push 00000115
00411D61: 53 push ebx
00411D62: 68942A2200 push 00222A94-------------------------------------------秘密
00411D67: 56 push esi
00411D68: FF1574704100 call KERNEL32.DeviceIoControl
00411D6E: 85C0 test eax, eax
00411D70: 56 push esi
00411D71: 750D jne 00411D80
00411D73: FF156C704100 call KERNEL32.CloseHandle
00411D79: B8304E0000 mov eax, 00004E30
00411D7E: EB09 jmp 00411D89
好好去分析吧。。。
|
能力值:
( LV2,RANK:10 )
|
-
-
29 楼
学习了。谢谢
|
能力值:
( LV2,RANK:10 )
|
-
-
30 楼
楼上好几位杀狗专家啊
|
能力值:
( LV2,RANK:10 )
|
-
-
31 楼
看得我一头雾水啊
|
|
|