能力值:
( LV9,RANK:280 )
|
-
-
2 楼
首先内核里得有一个可以供他利用的loader驱动,才能实现你所谓的内存加载
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
这种?????详见链接:667K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6Q4x3X3g2U0M7$3c8F1i4K6u0W2L8X3g2@1i4K6u0r3L8r3g2A6j5X3&6A6P5W2)9#2k6Y4A6K6N6g2)9J5c8X3q4J5N6r3W2U0L8r3g2Q4x3V1k6V1k6i4c8S2K9h3I4K6i4K6u0r3y4U0x3I4x3U0M7%4x3b7`.`. TARGETNAME=cocpyinf TARGETTYPE=DYNLINK USE_MSVCRT=1
_NT_TARGET_VERSION=$(_NT_TARGET_VERSION_WIN2K)
SOURCES=cocpyinf.c / cocpyinf.rc
TARGETLIBS= $(SDK_LIB_PATH)/setupapi.lib / $(SDK_LIB_PATH)/kernel32.lib / $(SDK_LIB_PATH)/advapi32.lib / $(SDK_LIB_PATH)/user32.lib
DLLBASE=0x2000000
|
能力值:
( LV8,RANK:130 )
|
-
-
4 楼
样本发上来。。
|
能力值:
( LV8,RANK:130 )
|
-
-
5 楼
扩展名无关紧要,系统内核ntoskrnl扩展名还是exe呢?
|
|
|