<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
 <channel>
  <title>VX Z0ne</title>
  <link>http://romio64.blogbus.com</link>
  <description><![CDATA[病毒地带
VIRII,ROOTKIT,KERNEL]]></description>
  <generator> by blogbus.com </generator>
  <lastBuildDate>Thu, 01 Jan 1970 07:00:00 +0700</lastBuildDate>
  <image>
									<url>http://public.blogbus.com/profile/4/7/4/8474/avatar_8474_96.jpg</url>
									<title>VX Z0ne</title>
									<link>http://romio64.blogbus.com</link>
								</image>  <item>
   <title>修改活动进程链隐藏进程</title>
   <description><![CDATA[coded by robinh00d<br />typedef struct _proc_info<br />{<br />DWORD dwPIDOffset;//PID偏移（相对于EPROCESS，下同）<br />DWORD dwAPLOffset;//ActiveProcessLink偏移<br />DWORD dwProcNameOffset ;//进程名偏移<br />char szProcName[16] ;//要隐藏的进程名<br />}proc_info ;<br />//取当前进程的EPROCESS<br />&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;//遍历ACTIVEPROCESSLINK，遇到要隐藏的进程则用RemoveEn...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/7049623.html">进程保护</a> 2007-07-25</div><div><a href="/logs/6182650.html">ATool的问题</a> 2007-06-28</div><div><a href="/logs/6132148.html">检查Windows所使用的内核及HAL的原始版本</a> 2007-06-25</div><div><a href="/logs/6131954.html">一个内核级的Shell工具源代码</a> 2007-06-25</div><div><a href="/logs/6131875.html">Virus.Win32.Downloader.c分析</a> 2007-06-25</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F10303526.html&title=%E4%BF%AE%E6%94%B9%E6%B4%BB%E5%8A%A8%E8%BF%9B%E7%A8%8B%E9%93%BE%E9%9A%90%E8%97%8F%E8%BF%9B%E7%A8%8B">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://pindao.blogbus.com/fengshang?utm_source=blogbus&utm_medium=rss&utm_campaign=fengshang" target="_blank">风尚频道——国内顶尖的时尚族群汇聚于此，未必是流行，但一定要有品位。</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/10303526.html</link>
   <author>robinh00d</author>
   <pubDate>Mon, 15 Oct 2007 16:52:34 +0800</pubDate>
  </item>
  <item>
   <title>进程保护</title>
   <description><![CDATA[<font size="2"><font face="Courier New">没啥说的。。。挂钩NtOpenProcess<br /></font>#include &quot;ntddk.h&quot;<br /><br />#define FILE_DEVICE_PROTECTPROC&nbsp;0x8000<br />#define PROTECTPROC_IOCTL_BASE&nbsp;0x800<br />#define CTL_CODE_PROTECTPROC(i) CTL_CODE(FILE_DEVICE_PROTECTPROC, PROTECTPROC_IOCTL_BASE+i, METHOD_BUFFERED, FILE_ANY_ACCESS)<br /><br />#define IOCTL_PROTECTPROC_...</font><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/10303526.html">修改活动进程链隐藏进程</a> 2007-10-15</div><div><a href="/logs/6182650.html">ATool的问题</a> 2007-06-28</div><div><a href="/logs/6132148.html">检查Windows所使用的内核及HAL的原始版本</a> 2007-06-25</div><div><a href="/logs/6131954.html">一个内核级的Shell工具源代码</a> 2007-06-25</div><div><a href="/logs/6051894.html">OllyDbg's fault</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F7049623.html&title=%E8%BF%9B%E7%A8%8B%E4%BF%9D%E6%8A%A4">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://icity.cn" target="_blank">《城客》：第一本中文互动杂志！</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/7049623.html</link>
   <author>robinh00d</author>
   <pubDate>Wed, 25 Jul 2007 16:58:32 +0800</pubDate>
  </item>
  <item>
   <title>Virus.Win32.Mock</title>
   <description><![CDATA[以前写的，比较适合科普<br />.386<br />.model flat,stdcall<br />option casemap:none<br /><br />include windows.inc<br />include user32.inc<br />includelib user32.lib<br />include kernel32.inc<br />includelib kernel32.lib<br /><br />VirusSize&nbsp;equ&nbsp;(offset virus_end - offset virus_start)<br /><br /><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/6131989.html">修改PE的e_lfnew感染法</a> 2007-06-25</div><div><a href="/logs/6131875.html">Virus.Win32.Downloader.c分析</a> 2007-06-25</div><div><a href="/logs/6052044.html">Mein Herz Brennt巴黎现场</a> 2007-06-21</div><div><a href="/logs/6051228.html">HOOK SSDT实现进程隐藏</a> 2007-06-21</div><div><a href="/logs/6051205.html">人品测试（驱动版）</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6486203.html&title=Virus.Win32.Mock">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://tuijian.blogbus.com/" target="_blank">推荐：让我们寻找最优秀的Blogger！</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6486203.html</link>
   <author>robinh00d</author>
   <pubDate>Sat, 07 Jul 2007 17:16:53 +0800</pubDate>
  </item>
  <item>
   <title>ATool的问题</title>
   <description><![CDATA[在用ATool检测文件系统挂钩的时候，有时候会出现显示被挂钩（红色高亮），但是却检测不出模块名称来。开始觉得很奇怪，用WinDbg看了一下HOOK后的地址：<br /><br />lkd&gt; u 85b0a1e8<br />85b0a1e8 8b542408&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; mov&nbsp;&nbsp;&nbsp;&nbsp; edx,dword ptr [esp+8]<br />85b0a1ec 8d4c2404&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; lea&nbsp;&nbsp;&nbsp;&nbsp; ecx,[esp+4]<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/10303526.html">修改活动进程链隐藏进程</a> 2007-10-15</div><div><a href="/logs/7049623.html">进程保护</a> 2007-07-25</div><div><a href="/logs/6132148.html">检查Windows所使用的内核及HAL的原始版本</a> 2007-06-25</div><div><a href="/logs/6131954.html">一个内核级的Shell工具源代码</a> 2007-06-25</div><div><a href="/logs/6051012.html">第一帖</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6182650.html&title=ATool%E7%9A%84%E9%97%AE%E9%A2%98">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://pindao.blogbus.com/xingzhe?utm_source=blogbus&utm_medium=rss&utm_campaign=xingzhe" target="_blank">行者频道——从普通游客到资深背包族，跟随Ta们的镜头游遍全世界。</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6182650.html</link>
   <author>robinh00d</author>
   <pubDate>Thu, 28 Jun 2007 09:50:47 +0800</pubDate>
  </item>
  <item>
   <title>检查Windows所使用的内核及HAL的原始版本</title>
   <description><![CDATA[/*===================================================================<br />* Filename CheckKernel.c<br />*<br />* Author: kcrazy<br />* Email: thekcrazy@gmail.com<br />*<br />* Description: 检查Windows所使用的内核及HAL的原始版本<br />*<br />* Date: 2007-4-27 Original from kcrazy<br />* <br />* Version: 1.0<br />=================================...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/10303526.html">修改活动进程链隐藏进程</a> 2007-10-15</div><div><a href="/logs/7049623.html">进程保护</a> 2007-07-25</div><div><a href="/logs/6182650.html">ATool的问题</a> 2007-06-28</div><div><a href="/logs/6131954.html">一个内核级的Shell工具源代码</a> 2007-06-25</div><div><a href="/logs/6051821.html">关于狙剑</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6132148.html&title=%E6%A3%80%E6%9F%A5Windows%E6%89%80%E4%BD%BF%E7%94%A8%E7%9A%84%E5%86%85%E6%A0%B8%E5%8F%8AHAL%E7%9A%84%E5%8E%9F%E5%A7%8B%E7%89%88%E6%9C%AC">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://pindao.blogbus.com/fengshang?utm_source=blogbus&utm_medium=rss&utm_campaign=fengshang" target="_blank">风尚频道——国内顶尖的时尚族群汇聚于此，未必是流行，但一定要有品位。</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6132148.html</link>
   <author>robinh00d</author>
   <pubDate>Mon, 25 Jun 2007 16:14:41 +0800</pubDate>
  </item>
  <item>
   <title>修改PE的e_lfnew感染法</title>
   <description><![CDATA[实验性质的东西<br />仍然属于bind infection的一种，只不过他是把宿主文件的e_lfanew指向了后面病毒PE的PE HEADER，我测试了一下，如果PE HEADER的SizeOfHeaders大于4k的话程序就不能被load，也就是说宿主程序大小+病毒的所有头大小+病毒的节表大小不能大于4K，这样的话这种感染方式就没有实用价值了。<br />以上说法如有错误，请批评指正嘿嘿～<br />BOOL CInfection::InfectFile(LPCTSTR lpVirus, LPCTSTR lpHost)<br />{<br />CFileMap fm(lpHost) ;<br /><br />DWORD dwHostSize = fm.GetSize() ;<br /><br />if (0 == dwHos...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/6486203.html">Virus.Win32.Mock</a> 2007-07-07</div><div><a href="/logs/6131875.html">Virus.Win32.Downloader.c分析</a> 2007-06-25</div><div><a href="/logs/6051894.html">OllyDbg's fault</a> 2007-06-21</div><div><a href="/logs/6051228.html">HOOK SSDT实现进程隐藏</a> 2007-06-21</div><div><a href="/logs/6051205.html">人品测试（驱动版）</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6131989.html&title=%E4%BF%AE%E6%94%B9PE%E7%9A%84e_lfnew%E6%84%9F%E6%9F%93%E6%B3%95">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://icity.cn" target="_blank">《城客》：第一本中文互动杂志！</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6131989.html</link>
   <author>robinh00d</author>
   <pubDate>Mon, 25 Jun 2007 15:54:35 +0800</pubDate>
  </item>
  <item>
   <title>一个内核级的Shell工具源代码</title>
   <description><![CDATA[驱动部分<br />;@echo off<br />;goto make<br /><br />;********************************************************************<br />;author :dge<br />;homepage:http://llfdge.googlepages.com/<br />;date :2007.3.16<br />;********************************************************************<br /><br />.386<br />.model flat, stdcall<br />option casemap:none<br /><br />include d:\masm32\include\w2k\ntstat...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://wandou2.blogbus.com/logs/31442998.html">「顶」拉票~</a> 2009-11-16</div><div><a href="/logs/10303526.html">修改活动进程链隐藏进程</a> 2007-10-15</div><div><a href="/logs/7049623.html">进程保护</a> 2007-07-25</div><div><a href="/logs/6182650.html">ATool的问题</a> 2007-06-28</div><div><a href="/logs/6132148.html">检查Windows所使用的内核及HAL的原始版本</a> 2007-06-25</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6131954.html&title=%E4%B8%80%E4%B8%AA%E5%86%85%E6%A0%B8%E7%BA%A7%E7%9A%84Shell%E5%B7%A5%E5%85%B7%E6%BA%90%E4%BB%A3%E7%A0%81">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://pindao.blogbus.com/xingzhe?utm_source=blogbus&utm_medium=rss&utm_campaign=xingzhe" target="_blank">行者频道——从普通游客到资深背包族，跟随Ta们的镜头游遍全世界。</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6131954.html</link>
   <author>robinh00d</author>
   <pubDate>Mon, 25 Jun 2007 15:51:41 +0800</pubDate>
  </item>
  <item>
   <title>Virus.Win32.Downloader.c分析</title>
   <description><![CDATA[【分析环境】VMWARE+WINDOWS XP SP2+OLLYDBG+PEID+PEInfo<br />首先用PEID扫描一下没有扫描出壳或者编译器特征，入口点RVA是0x70000,进一步使用PE分析工具查看关键的数据信息，我这里使用的是PEInfo：可以看到，代码入口不是在常规的.text节里而是在.rdata节里<br />再看输入表信息：输入表的RVA是0x70660,程序只导入了kernel32.dll里的GetProcAddress和LoadLibraryA这两个函数。<br /><br />下面是详细的代码分析：<br /><br />; 重定位到当前导入表<br />00470005 68 90184000 PUSH QQLiveUp.00401890<br />0047000A E8 71020000 CALL QQLiveUp.00470280<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/6486203.html">Virus.Win32.Mock</a> 2007-07-07</div><div><a href="/logs/6131989.html">修改PE的e_lfnew感染法</a> 2007-06-25</div><div><a href="/logs/6051228.html">HOOK SSDT实现进程隐藏</a> 2007-06-21</div><div><a href="/logs/6051205.html">人品测试（驱动版）</a> 2007-06-21</div><div><a href="/logs/6051146.html">Win32.Poly.DarkRain[NOT COMPLATE]</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6131875.html&title=Virus.Win32.Downloader.c%E5%88%86%E6%9E%90">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://pindao.blogbus.com/xingzhe?utm_source=blogbus&utm_medium=rss&utm_campaign=xingzhe" target="_blank">行者频道——从普通游客到资深背包族，跟随Ta们的镜头游遍全世界。</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6131875.html</link>
   <author>robinh00d</author>
   <pubDate>Mon, 25 Jun 2007 15:45:46 +0800</pubDate>
  </item>
  <item>
   <title>Mein Herz Brennt巴黎现场</title>
   <description><![CDATA[<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" width="370" height="240"><param name="width" value="370" /><param name="height" value="240" /><param name="src" value="http://www.56.com/n_v18_/c9_/19_/2_/yooyee_/1173601302_835_/387657_/0_/12655914.swf" /><embed type="application/x-shockwave-flash" width="370" height="240" src="http://www.56.com/n_v18_/c9_/19_/2_/yooyee_/1173601302_835_/387657_/0_/12655914.swf"></embed></object><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/7049623.html">进程保护</a> 2007-07-25</div><div><a href="/logs/6182650.html">ATool的问题</a> 2007-06-28</div><div><a href="/logs/6131989.html">修改PE的e_lfnew感染法</a> 2007-06-25</div><div><a href="/logs/6051205.html">人品测试（驱动版）</a> 2007-06-21</div><div><a href="/logs/6051146.html">Win32.Poly.DarkRain[NOT COMPLATE]</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6052044.html&title=Mein+Herz+Brennt%E5%B7%B4%E9%BB%8E%E7%8E%B0%E5%9C%BA">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://pindao.blogbus.com/xingzhe?utm_source=blogbus&utm_medium=rss&utm_campaign=xingzhe" target="_blank">行者频道——从普通游客到资深背包族，跟随Ta们的镜头游遍全世界。</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6052044.html</link>
   <author>robinh00d</author>
   <pubDate>Thu, 21 Jun 2007 17:41:44 +0800</pubDate>
  </item>
  <item>
   <title>OllyDbg's fault</title>
   <description><![CDATA[以前分析一些病毒和壳的时候经常会遇到这个程序可以正常执行，却用OD加载不了。一直怀疑是手工修改了PE的某个字段，但不确定是修改了哪一个。昨天在DEBUGMAN上问了一下，果然牛人很多<br />原来是修改了NumOfRvaAndSizes字段，一般情况下都是0x10<br /><br />...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/6486203.html">Virus.Win32.Mock</a> 2007-07-07</div><div><a href="/logs/6131989.html">修改PE的e_lfnew感染法</a> 2007-06-25</div><div><a href="/logs/6131875.html">Virus.Win32.Downloader.c分析</a> 2007-06-25</div><div><a href="/logs/6051228.html">HOOK SSDT实现进程隐藏</a> 2007-06-21</div><div><a href="/logs/6051205.html">人品测试（驱动版）</a> 2007-06-21</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fromio64.blogbus.com%2Flogs%2F6051894.html&title=OllyDbg%27s+fault">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://pindao.blogbus.com/sejie?utm_source=blogbus&utm_medium=rss&utm_campaign=sejie" target="_blank">色界频道——这里有顶尖的摄影大师，也有摄影爱好者，他们用相机收纳大千世界。</a></b></div><br /><br />]]></description>
   <link>http://romio64.blogbus.com/logs/6051894.html</link>
   <author>robinh00d</author>
   <pubDate>Thu, 21 Jun 2007 17:22:50 +0800</pubDate>
  </item>
 </channel>
</rss>
