{"id":556,"date":"2018-08-23T00:21:42","date_gmt":"2018-08-22T16:21:42","guid":{"rendered":"https:\/\/mnihyc.tk\/blog\/?p=556"},"modified":"2020-10-08T00:47:26","modified_gmt":"2020-10-07T16:47:26","slug":"memz-%e6%ba%90%e7%a0%81%e7%ba%a7%e5%88%86%e6%9e%90","status":"publish","type":"post","link":"https:\/\/0.mnihyc.com\/blog\/archives\/556","title":{"rendered":"MEMZ \u6e90\u7801\u7ea7\u5206\u6790"},"content":{"rendered":"<p>MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3\u7801\u5230\u5e95\u662f\u600e\u4e48\u6837\u7684\u3002<\/p>\n<p>\u9996\u5148 \uff0c\u6837\u672c\uff1a <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ\/MEMZ_virus.zip\">MEMZ_virus.zip<\/a> \uff08\u5bc6\u7801\uff1a<code>MEMZ!virus<\/code><\/p>\n<p>\u5de5\u5177\uff1a<code>IDA Pro v7.0<\/code> <a href=\"https:\/\/dl.mnihyc.com\/Tool\/IDA7.0.zip\">IDA7.0.zip<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\uff08Index\u4e0d\u60f3\u5199w<\/p>\n<p><!--more--><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u89e3\u538b\uff0c\u53d1\u73b0\u76ee\u5f55\u91cc\u6709\u4e24\u4e2a\u6587\u4ef6\uff0c\u4e00\u4e2a<code>.bat<\/code>\uff0c\u53e6\u4e00\u4e2a<code>.exe<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-557\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png\" alt=\"\" width=\"598\" height=\"400\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png 598w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1-300x201.png 300w\" sizes=\"auto, (max-width: 598px) 100vw, 598px\" \/><\/p>\n<p>\u5f88\u660e\u663e<code>.exe<\/code>\u5c31\u662f\u75c5\u6bd2\u6837\u672c\uff0c\u90a3\u4e48<code>.bat<\/code>\u4ec0\u4e48\u7528\u7684\uff1f<\/p>\n<p>\u6253\u5f00<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-559\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/2-1.png\" alt=\"\" width=\"765\" height=\"639\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/2-1.png 765w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/2-1-300x251.png 300w\" sizes=\"auto, (max-width: 765px) 100vw, 765px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>\u53ef\u4ee5\u770b\u5230\uff0c\u4e3a\u4e86\u9003\u907f\u68c0\u6d4b\uff0c\u5b83\u8fd8\u7279\u5730\u628a\u6267\u884c\u5185\u5bb9\u5199\u5230<code>js<\/code>\u91cc<\/p>\n<pre class=\"lang:default decode:true \">\/\/\u83b7\u53d6\u7ec4\u4ef6\r\nf=new ActiveXObject(\"Scripting.FileSystemObject\");\r\n\/\/\u6253\u5f00\u6587\u4ef6x\r\ni=f.getFile(\"x\").openAsTextStream();\r\n\/\/\u521b\u5efabase64\u89e3\u5bc6\u5bf9\u8c61\r\nx=new ActiveXObject(\"MSXml2.DOMDocument\").createElement(\"Base64Data\");\r\nx.dataType=\"bin.base64\";\r\n\/\/\u8bfb\u53d6x\u4e2d\u6240\u6709\u6570\u636e\uff0c\u5e76\u89e3\u5bc6\r\nx.text=i.readAll();\r\no=new ActiveXObject(\"ADODB.Stream\");\r\no.type=1;\r\no.open();\r\no.write(x.nodeTypedValue);\r\n\/\/\u5c06\u89e3\u5bc6\u5185\u5bb9\u5199\u5165z.zip\r\nz=f.getAbsolutePathName(\"z.zip\");\r\no.saveToFile(z);\r\ns=new ActiveXObject(\"Shell.Application\");\r\n\/\/\u89e3\u538bz.zip\u5f97\u5230MEMZ.zip\r\ns.namespace(26).copyHere(s.namespace(z).items());\r\no.close();\r\ni.close();\r\n<\/pre>\n<p>\u5f88\u660e\u663e\u8fd9\u4e2abat\u662f\u7528\u6765\u751f\u6210exe\u75c5\u6bd2\u6587\u4ef6\u7684\u3002<\/p>\n<p>\u5c31\u4e00\u4e2a<code>base64<\/code>\u52a0\u5bc6\u7adf\u7136\u76f4\u63a5\u7ed5\u8fc7\u4e86360\uff1f\uff1f\uff1f\uff1f<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u76f4\u63a5\u7528<code>IDA<\/code>\u6253\u5f00<code>MEMZ.exe<\/code>\uff0c\u5206\u6790\u6e90\u4ee3\u7801<\/p>\n<p>\u7a0b\u5e8f\u51fa\u53e3\u70b9\u4e3a<code>start<\/code>\u51fd\u6570\uff0c\u8ddf\u8fdb<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-564 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/3-1.png\" alt=\"\" width=\"457\" height=\"65\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/3-1.png 457w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/3-1-300x43.png 300w\" sizes=\"auto, (max-width: 457px) 100vw, 457px\" \/><\/p>\n<p>\u7136\u540e\u76f4\u63a5\u4e00\u4e2a F5 \u4e0b\u53bb<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-565\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/4-1.png\" alt=\"\" width=\"659\" height=\"519\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/4-1.png 659w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/4-1-300x236.png 300w\" sizes=\"auto, (max-width: 659px) 100vw, 659px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-567\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/5-1.png\" alt=\"\" width=\"641\" height=\"491\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/5-1.png 641w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/5-1-300x230.png 300w\" sizes=\"auto, (max-width: 641px) 100vw, 641px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-568\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/6-2.png\" alt=\"\" width=\"649\" height=\"492\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/6-2.png 649w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/6-2-300x227.png 300w\" sizes=\"auto, (max-width: 649px) 100vw, 649px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-569\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/7-1.png\" alt=\"\" width=\"909\" height=\"488\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/7-1.png 909w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/7-1-300x161.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/7-1-768x412.png 768w\" sizes=\"auto, (max-width: 909px) 100vw, 909px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-570\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/8-1.png\" alt=\"\" width=\"603\" height=\"402\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/8-1.png 603w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/8-1-300x200.png 300w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>\u89c2\u5bdf\u4e00\u4e0b\u51fd\u6570\u7684\u6d41\u7a0b\u3002<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-572\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/9-1.png\" alt=\"\" width=\"549\" height=\"199\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/9-1.png 549w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/9-1-300x109.png 300w\" sizes=\"auto, (max-width: 549px) 100vw, 549px\" \/><\/p>\n<p>\u9996\u5148\u83b7\u53d6\u4e86\u7a0b\u5e8f\u7684\u542f\u52a8\u53c2\u6570\uff0c\u7c7b\u4f3c\u4e8e<code>int main(int argc,char**argv)<\/code>\uff0c\u53ea\u4e0d\u8fc7\u7528<code>Windows API GetCommandLine()<\/code>\u7684\u65b9\u5f0f\u83b7\u53d6\u3002<\/p>\n<p>\u7136\u540e\u518d\u5224\u65ad\u53c2\u6570\u662f\u5426\u5b58\u5728\uff0c\u5b58\u5728\u7684\u8bdd\u518d\u5224\u65ad\u662f\u4e0d\u662f\u4e3a<code>\/watchdog<\/code>\uff0c\u662f\u7684\u8bdd\u521b\u5efa\u4e00\u4e2a\u65b0\u7ebf\u7a0b\u6267\u884c<code>sub_40114A()<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-573\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/10-1.png\" alt=\"\" width=\"490\" height=\"346\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/10-1.png 490w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/10-1-300x212.png 300w\" sizes=\"auto, (max-width: 490px) 100vw, 490px\" \/><\/p>\n<p>\u521b\u5efa\u5b8c\u65b0\u7ebf\u7a0b\u540e\uff0c\u8c03\u7528\u4e86<code>RegisterClassEx<\/code>\u6ce8\u518c\u7a97\u53e3\u548c<code>CreateWindowEx<\/code>\u65b0\u5efa\u7a97\u53e3\u3002<\/p>\n<p>\u4f46\u662f\u8fd9\u91cc\u7684\u53c2\u6570\u6709\u70b9\u5947\u602a<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-574 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/11-1.png\" alt=\"\" width=\"390\" height=\"20\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/11-1.png 390w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/11-1-300x15.png 300w\" sizes=\"auto, (max-width: 390px) 100vw, 390px\" \/><\/p>\n<p><code>RegisterClassEx<\/code>\u7684\u5b9a\u4e49<code><br \/>\nATOM WINAPI RegisterClassEx(<br \/>\n_In_ const WNDCLASSEX *lpwcx<br \/>\n);<\/code><\/p>\n<p>\u53c2\u6570\u5e94\u8be5\u4e3a<code>WNDCLASSEX*<\/code>\u800c\u4e0d\u662f<code>SHELLEXECUTEINFO*<\/code><\/p>\n<p>\u6709\u53ef\u80fd\u662f<code>IDA<\/code>\u53cd\u7f16\u8bd1\u51fa\u9519\uff0c\u4e5f\u6709\u53ef\u80fd\u662f\u4f5c\u8005\u7684\u6df7\u6dc6\uff08\u53ef\u80fd\u6027\u66f4\u5927<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-575 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/12-1.png\" alt=\"\" width=\"398\" height=\"352\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/12-1.png 398w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/12-1-300x265.png 300w\" sizes=\"auto, (max-width: 398px) 100vw, 398px\" \/>\uff09<\/p>\n<p>\u603b\u4e4b\uff0c\u5230<code>MSDN<\/code>\u4e0a\u627e\u8fd9\u4e24\u7684\u5b9a\u4e49<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-576 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/13-1.png\" alt=\"\" width=\"346\" height=\"374\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/13-1.png 346w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/13-1-278x300.png 278w\" sizes=\"auto, (max-width: 346px) 100vw, 346px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-577 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/14-1.png\" alt=\"\" width=\"496\" height=\"494\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/14-1.png 496w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/14-1-150x150.png 150w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/14-1-300x300.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/14-1-100x100.png 100w\" sizes=\"auto, (max-width: 496px) 100vw, 496px\" \/><\/p>\n<p>\u6ce8\u610f\u7a0b\u5e8f\u4e2d\u7684\u8c03\u7528\u4e3a<code>RegisterClassExA((const WNDCLASSEXA *)&amp;pExecInfo.lpVerb);<\/code><\/p>\n<p>\u6240\u4ee5<code>SHELLEXECUTEINFO.lpVerb<\/code>\u53ca\u4ee5\u4e0b\u4e0e<code>WNDCLASSEX.cbSize<\/code>\u53ca\u4ee5\u4e0b\u7684\u53c2\u6570\u4e00\u4e00\u5bf9\u5e94\u3002\uff08\u9879\u6570\u4e5f\u521a\u597d\u76f8\u540c\uff0c\u5927\u5c0f\u4e5f\u76f8\u7b49<code>sizeof(*void)=sizeof(int)=sizeof(DWORD)=4<\/code>\uff09<\/p>\n<p>\u5206\u6790\u4e00\u4e0b\u53c2\u6570\u5c31\u53ef\u4ee5\u53d1\u73b0\uff0c\u5b83\u521b\u5efa\u4e86\u4e00\u4e2a\u7c7b\u540d\u4e3a<code>hax<\/code>\u7684\u7a97\u53e3\uff0c\u4e14\u6b64\u7a97\u53e3\u7684\u56de\u8c03\u51fd\u6570\u4e3a<code>sub_4010000<\/code>\uff0c\u5176\u4f59\u4ec0\u4e48\u4e5f\u6ca1\u6709\u3002<\/p>\n<p>\u8ddf\u8fdb\u6b64\u51fd\u6570<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-579\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/15-1.png\" alt=\"\" width=\"612\" height=\"176\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/15-1.png 612w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/15-1-300x86.png 300w\" sizes=\"auto, (max-width: 612px) 100vw, 612px\" \/><\/p>\n<p>\u5728<code>winuser.h<\/code>\u91cc\u9762\u53ef\u4ee5\u770b\u5230\u5173\u4e8e<code>Message<\/code>\u7cfb\u5217\u5e38\u6570\u5b9a\u4e49\u7684\u503c<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-580\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/16.png\" alt=\"\" width=\"519\" height=\"398\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/16.png 519w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/16-300x230.png 300w\" sizes=\"auto, (max-width: 519px) 100vw, 519px\" \/><\/p>\n<p><code>WM_CLOSE<\/code>\u5bf9\u5e94\u7a97\u53e3\u5173\u95ed\u8bf7\u6c42\uff0c<code>WM_ENDSESSION<\/code>\u5bf9\u5e94\u5173\u673a\u65f6\u5173\u95ed\u7a97\u53e3\u8bf7\u6c42<\/p>\n<p>\u4e14\u5982\u679c\u4f20\u7ed9\u5f53\u524d\u7a97\u53e3\u7684\u6d88\u606f\u4e0d\u4e3a\u5176\u4e2d\u4efb\u4e00\u65f6\uff0c\u7a97\u53e3\u4fe1\u606f\u8f6c\u4e3a<code>DefWindowProc<\/code>\u5904\u7406\u3002<\/p>\n<p>\u5426\u5219\u8c03\u7528\u51fd\u6570<code>sub_401021<\/code><\/p>\n<p>\u8ddf\u8fdb\u6b64\u51fd\u6570<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-581\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/17.png\" alt=\"\" width=\"587\" height=\"514\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/17.png 587w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/17-300x263.png 300w\" sizes=\"auto, (max-width: 587px) 100vw, 587px\" \/><\/p>\n<p><del>\u51fd\u6570\u4e00\u5f00\u59cb\u5c31\u521b\u5efa\u4e86 20 \u4e2a\u7ebf\u7a0b\u6267\u884c\u540c\u6837\u8fd9\u4e2a\u51fd\u6570\uff0c\u8fd9\u6837\u4f1a\u53d8\u6210\u65e0\u9650\u521b\u5efa\u7ebf\u7a0b\uff0c\u5982\u679c\u6ca1\u6709\u540e\u7eed\u5904\u7406\u7cfb\u7edf\u4f1a\u5361\u6b7b\u3002<\/del><\/p>\n<p>\u4e0a\u9762\u8fd9\u4e2a\u662f\u6211\u4e00\u5f00\u59cb\u7684\u60f3\u6cd5\u3002\u5176\u5b9e\u5b83\u662f\u9519\u7684\u3002<\/p>\n<p>\u8fd920\u4e2a\u7ebf\u7a0b\u6267\u884c\u7684\u4e0d\u662f\u8fd9\u4e2a\u51fd\u6570\u7684\u5f00\u5934\uff0c\u800c\u662f\u4e00\u6bb5IDA\u6ca1\u80fdF5\u51fa\u6765\u7684\u4ee3\u7801\uff0c\u5728\u8fd9\u91cc<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-604\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/28-1.png\" alt=\"\" width=\"722\" height=\"516\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/28-1.png 722w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/28-1-300x214.png 300w\" sizes=\"auto, (max-width: 722px) 100vw, 722px\" \/><\/p>\n<p>\uff08\u610f\u4e49\u4e0d\u660e\uff0c\u4e0b\u56fe\u770b\u5f97\u51fa\u5806\u6808\u4e5f\u662f\u5e73\u8861\u7684\uff0c\u4e0d\u77e5\u9053\u4e3a\u4ec0\u4e48IDA\u9519\u8bef<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-607\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/29-1.png\" alt=\"\" width=\"416\" height=\"419\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/29-1.png 416w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/29-1-150x150.png 150w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/29-1-298x300.png 298w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/29-1-100x100.png 100w\" sizes=\"auto, (max-width: 416px) 100vw, 416px\" \/><\/p>\n<p>\u6ca1\u6709\u529e\u6cd5\uff0c\u6211\u4eec\u76f4\u63a5\u5bf9\u7740\u6c47\u7f16\u5206\u6790\u3002<\/p>\n<p>\u9996\u5148<code>push esi<\/code>\uff0c\u610f\u4e49\u4e0d\u660e\u3002<\/p>\n<p>\u7136\u540e\u8c03\u7528<code>GetCurrentThreadId<\/code>\u83b7\u53d6\u5f53\u524d\u7ebf\u7a0bID\uff0c\u4fdd\u5b58\u5728<code>eax<\/code>\u4e2d\u3002<\/p>\n<p>\u63a5\u7740<code>SetWindowHookEx(idHook=5,lpfn=offset_fn,hmod=0,dwId);<\/code><\/p>\n<p>\u67e5\u9605<code>MSDN<\/code>\uff0c<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-608 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/30-1.png\" alt=\"\" width=\"830\" height=\"64\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/30-1.png 830w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/30-1-300x23.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/30-1-768x59.png 768w\" sizes=\"auto, (max-width: 830px) 100vw, 830px\" \/><\/p>\n<p>\u5373\u6240\u6709\u7684\u7a97\u53e3\u4e8b\u4ef6\u5c06\u4f1a\u88ab\u4f20\u9001\u5230<code>fn<\/code>\u6240\u6307\u5411\u7684\u51fd\u6570\u5904\u7406\uff0c\u8ddf\u8fdb<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-609\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/31.png\" alt=\"\" width=\"554\" height=\"406\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/31.png 554w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/31-300x220.png 300w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/p>\n<p>\u518d\u6b21\u67e5\u8be2<code>MSDN<\/code>\uff0c<code>code=3<\/code>\u5373\u521b\u5efa\u7a97\u53e3\u4e8b\u4ef6<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-610 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/32.png\" alt=\"\" width=\"828\" height=\"219\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/32.png 828w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/32-300x79.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/32-768x203.png 768w\" sizes=\"auto, (max-width: 828px) 100vw, 828px\" \/><\/p>\n<p>\u8ddf\u8fdb\u51fd\u6570<code>sub_401A55<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-611\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/33.png\" alt=\"\" width=\"660\" height=\"274\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/33.png 660w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/33-300x125.png 300w\" sizes=\"auto, (max-width: 660px) 100vw, 660px\" \/><\/p>\n<p>\u53d1\u73b0\u8fd9\u662f\u4e2a\u751f\u6210\u968f\u673a\u6570\u7684\u51fd\u6570\u3002<\/p>\n<p>\u89c2\u5bdf\u539f\u51fd\u6570\uff0c\u751f\u6210\u7684\u968f\u673a\u6570\u90fd\u8fd4\u56de\u7ed9\u4e86<code>v4 (LPARAM)<\/code>\uff0c\u6240\u4ee5\u8fd9\u6bb5\u4ee3\u7801\u5b9e\u73b0\u4e86\u968f\u673a\u8bbe\u7f6e\u6b64\u53e5\u67c4\u4e0a\u7684\u7a97\u53e3\u4f4d\u7f6e\u3002<\/p>\n<p>\u4e4b\u540e\u8c03\u7528\u4e86<code>MessageBox(hWnd=0,lpText,Caption=\"MEMZ\",0x1010=MB_OK|MB_ICONERROR|MB_SYSTEMMODAL)<\/code>\u6765\u663e\u793a\u5bf9\u8bdd\u6846\u3002<\/p>\n<p>\u6700\u540e\u4f7f\u7528<code>UnhookWindowHookEx<\/code>\u5378\u8f7d\u4e4b\u524d\u7684\u94a9\u5b50\u3002<\/p>\n<p><code>MessageBox<\/code>\u4e2d\u7684\u5185\u5bb9<code>lpText<\/code>\u5219\u662f\u968f\u673a\u4ee5\u4e0b\u5185\u5bb9<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-613\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/34.png\" alt=\"\" width=\"805\" height=\"496\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/34.png 805w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/34-300x185.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/34-768x473.png 768w\" sizes=\"auto, (max-width: 805px) 100vw, 805px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-614\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/35.png\" alt=\"\" width=\"639\" height=\"472\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/35.png 639w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/35-300x222.png 300w\" sizes=\"auto, (max-width: 639px) 100vw, 639px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-615\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/36.png\" alt=\"\" width=\"741\" height=\"362\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/36.png 741w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/36-300x147.png 300w\" sizes=\"auto, (max-width: 741px) 100vw, 741px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>\u56de\u5230\u539f\u51fd\u6570\uff0c\u521b\u5efa\u5bf9\u8bdd\u6846\u540e<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-583\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/18.png\" alt=\"\" width=\"859\" height=\"283\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/18.png 859w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/18-300x99.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/18-768x253.png 768w\" sizes=\"auto, (max-width: 859px) 100vw, 859px\" \/><\/p>\n<p>\u9996\u5148\u83b7\u53d6(<code>LoadLibrary<\/code>)<code>ntdll.dll<\/code>\u4e2d\u7684<code>RtlAdjustPrivilege<\/code>\u548c<code>NtRaiseHardError<\/code>\u51fd\u6570\uff0c\u5982\u679c\u8fd9\u4e24\u4e2a\u51fd\u6570\u90fd\u80fd\u6210\u529f\u83b7\u53d6\u7684\u8bdd\uff0c\u5c31\u5148\u8c03\u7528<code>v4(RtlAdjustPrivilege)<\/code>\uff0c\u518d\u8c03\u7528<code>v6(NtRaiseHardError)<\/code><\/p>\n<p>\u4f46\u662f\u5982\u679c\u6709\u4e00\u83b7\u53d6\u4e0d\u6210\u529f\uff0c\u5c31\u662f\u7528\u539f\u59cb\u7684\u65b9\u6cd5\u63d0\u5347\u81f3<code>SeShutdownPrivilege<\/code>\u6743\u9650\uff0c\u6700\u540e\u8c03\u7528<code>ExitWindowsEx<\/code>\u5f3a\u5236\u5173\u673a\u3002<\/p>\n<p><code>RtlAdjustPrivilege<\/code>\u662f\u4e00\u4e2a<code>MSDN<\/code>\u672a\u516c\u5f00\u7684\u51fd\u6570\uff0c\u56e0\u4e3a\u5b83\u53ef\u4ee5\u505a\u5230\u4e00\u884c\u63d0\u6743\uff0c\u5b8c\u7f8e\u66ff\u4ee3\u4ee5\u524d\u4f7f\u7528\u4f20\u7edf\u7684<code>OpenProcessToken -&gt;    LookupPrivilegeValue -&gt;    AdjustTokenPrivileges<\/code>\u9ebb\u70e6\u65b9\u6cd5\u3002<\/p>\n<p>\u6b64\u51fd\u6570\u5b9a\u4e49<code>NTSTATUS RtlAdjustPrivilege<br \/>\n(<br \/>\nULONG    Privilege, \/\/Privilege [In] Privilege index to change.<br \/>\nBOOLEAN Enable, \/\/Enable [In] If TRUE, then enable the privilege otherwise disable.<br \/>\nBOOLEAN CurrentThread, \/\/CurrentThread [In] If TRUE, then enable in calling thread, otherwise process.<br \/>\nPBOOLEAN Enabled \/\/<br \/>\nEnabled [Out] Whether privilege was previously enabled or disabled.<br \/>\n)<\/code><\/p>\n<p><code>19 = 0x13 = SE_SHUTDOWN_PRIVILEGE<\/code>\u5373\u5173\u673a\u6743\u9650<\/p>\n<p>\u540c\u6837\uff0c<code>NtRaiseHardError<\/code>\u4e5f\u4e3a<code>ntdll.dll<\/code>\u4e2d<code>MSDN<\/code>\u672a\u516c\u5f00\u7684\u51fd\u6570\uff0c\u5b83\u7684\u529f\u80fd\u662f\u5f15\u53d1\u4e00\u6b21\u84dd\u5c4f\uff08\u4e0e\u666e\u901a\u84dd\u5c4f\u4e0d\u540c\uff0c\u8fd9\u4e2a\u84dd\u5c4f\u4e00\u822c\u7531\u786c\u4ef6\u9519\u8bef\u5f15\u8d77\uff0c\u533a\u522b\u5982\u56fe<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-584\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/u21665444573124045168fm26gp0.jpg\" alt=\"\" width=\"500\" height=\"375\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/u21665444573124045168fm26gp0.jpg 500w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/u21665444573124045168fm26gp0-300x225.jpg 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-585\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/e08aa918972bd407a4ae870d7e899e510eb30907.jpg\" alt=\"\" width=\"580\" height=\"407\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/e08aa918972bd407a4ae870d7e899e510eb30907.jpg 580w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/e08aa918972bd407a4ae870d7e899e510eb30907-300x211.jpg 300w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/>\uff09\u3002<\/p>\n<p>\u51fd\u6570\u5b9a\u4e49<code>NTSYSAPI NTSTATUS NTAPI NtRaiseHardError<br \/>\n(<br \/>\nIN NTSTATUS             ErrorStatus,<br \/>\nIN ULONG                NumberOfParameters,<br \/>\nIN PUNICODE_STRING      UnicodeStringParameterMask OPTIONAL,<br \/>\nIN PVOID                *Parameters,<br \/>\nIN HARDERROR_RESPONSE_OPTION ResponseOption,<br \/>\nOUT PHARDERROR_RESPONSE Response<br \/>\n);<\/code><\/p>\n<p>\u4f7f\u7528\u4f8b\u5b50\uff1a<\/p>\n<pre class=\"lang:default decode:true \">typedef \/*__success(return &amp;gt;= 0)*\/ LONG NTSTATUS;   \r\ntypedef NTSTATUS *PNTSTATUS;   \r\n  \r\n#define STATUS_SUCCESS  ((NTSTATUS)0x00000000L)  \r\n  \r\ntypedef struct _LSA_UNICODE_STRING {  \r\n  USHORT Length;  \r\n  USHORT MaximumLength;  \r\n  PWSTR  Buffer;  \r\n} LSA_UNICODE_STRING, *PLSA_UNICODE_STRING, UNICODE_STRING, *PUNICODE_STRING;  \r\n  \r\ntypedef enum _HARDERROR_RESPONSE_OPTION {  \r\n    OptionAbortRetryIgnore,  \r\n    OptionOk,  \r\n    OptionOkCancel,  \r\n    OptionRetryCancel,  \r\n    OptionYesNo,  \r\n    OptionYesNoCancel,  \r\n    OptionShutdownSystem  \r\n} HARDERROR_RESPONSE_OPTION, *PHARDERROR_RESPONSE_OPTION;  \r\n  \r\ntypedef enum _HARDERROR_RESPONSE {  \r\n    ResponseReturnToCaller,  \r\n    ResponseNotHandled,  \r\n    ResponseAbort,  \r\n    ResponseCancel,  \r\n    ResponseIgnore,  \r\n    ResponseNo,  \r\n    ResponseOk,  \r\n    ResponseRetry,  \r\n    ResponseYes  \r\n} HARDERROR_RESPONSE, *PHARDERROR_RESPONSE;\r\n\r\n\/\/\u83b7\u53d6\u51fd\u6570\u5730\u5740.......\r\n\r\nint nEn = 0;\r\nRtlAdjustPrivilege(0x13, TRUE, FALSE, &amp;amp;nEn);\r\nHARDERROR_RESPONSE reResponse;\r\nNtRaiseHardError(0xC000021A,0,0,0,OptionShutdownSystem,&amp;amp;reResponse);\r\n\r\n<\/pre>\n<p>\uff08\u4e5f\u53ef\u4ee5\u53c2\u8003\uff1a<a href=\"https:\/\/blog.csdn.net\/AcceZn\/article\/details\/54670776\">https:\/\/blog.csdn.net\/AcceZn\/article\/details\/54670776<\/a><\/p>\n<p>\u5373\u53ef\u5f15\u8d77\u4e00\u6b210xC000021A\u84dd\u5c4f\u3002\uff08\u6ce8\uff1a\u4ee3\u7801\u4e2d<code>NtRaiseHardError<\/code>\u7684\u7b2c\u4e00\u4e2a\u53c2\u6570\u4e3a\u8d1f\u6570\u662f\u56e0\u4e3a<code>signed int<\/code>\u7684\u6ea2\u51fa\uff09<\/p>\n<p>&nbsp;<\/p>\n<p>\u522b\u5fd8\u4e86\uff0c\u5728\u521b\u5efa\u7a97\u53e3\u524d\u8fd8\u521b\u5efa\u4e86\u4e00\u4e2a\u7ebf\u7a0b\u6267\u884c\u51fd\u6570<code>sub_40114A()<\/code><\/p>\n<p>\u7ee7\u7eed\u8ddf\u8fdb<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-586\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/19.png\" alt=\"\" width=\"597\" height=\"514\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/19.png 597w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/19-300x258.png 300w\" sizes=\"auto, (max-width: 597px) 100vw, 597px\" \/><\/p>\n<p>\u8fd9\u4e2a\u51fd\u6570\u6d41\u7a0b\u662f\u4e00\u76ee\u4e86\u7136\u3002<\/p>\n<p>\u9996\u5148\u7528<code>GetProcessImageFileName<\/code>\u83b7\u53d6\u5f53\u524d\u8fd0\u884c\u6587\u4ef6\u540d\uff0c\u7136\u540e\u5229\u7528<code>tlhelp32.h<\/code>\u91cc\u7684<code>CreateToolhelp32Snapshot<\/code>\u7ed3\u5408<code>Process32First<\/code>\u548c<code>Process32Next<\/code>\u904d\u5386\u6240\u6709\u8fdb\u7a0b\uff0c\u4e5f\u83b7\u53d6\u8fd9\u4e9b\u8fdb\u7a0b\u7684\u6587\u4ef6\u540d\uff0c\u5e76\u5bfb\u627e\u4e0e\u5f53\u524d\u8fdb\u7a0b\u540d\u76f8\u7b49\u7684\u6570\u91cf\u3002\u5982\u679c\u6570\u91cf<code>v4<\/code>\u6bd4\u4e4b\u524d\u7684\u6570\u91cf<code>v7<\/code>\u8fd8\u5c11\uff08\u8bf4\u660e\u6709\u8fdb\u7a0b\u88ab\u6740\u6b7b\uff09\uff0c\u76f4\u63a5\u8c03\u7528\u51fd\u6570<code>sub_401021<\/code>\uff0c\u5373\u4e4b\u524d\u7684\u84dd\u5c4f\/\u5173\u673a\u51fd\u6570\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u603b\u7ed3\u4e00\u4e0b\u76ee\u524d\u4e3a\u6b62\u7684\u6d41\u7a0b\uff1a\u4ece\u7a0b\u5e8f\u542f\u52a8\u5f00\u59cb\uff0c\u5982\u679c\u53c2\u6570\u5e26\u6709<code>\/watchdog<\/code>\uff0c\u5219\u521b\u5efa\u4e00\u4e2a\u7ebf\u7a0b\u5224\u65ad\u662f\u5426\u6709\u5f53\u524d\u75c5\u6bd2\u7a0b\u5e8f\u88ab\u6740\u6b7b\uff0c\u6709\u7684\u8bdd\u76f4\u63a5\u84dd\u5c4f\/\u5173\u673a\u3002\u4e4b\u540e\u521b\u5efa\u4e00\u4e2a\u7a97\u53e3\uff0c\u5982\u679c\u68c0\u6d4b\u5230\u7a97\u53e3\u88ab\u5173\u95ed\u6216\u7cfb\u7edf\u5c06\u8981\u5173\u95ed\uff0c\u624b\u52a8\u521b\u5efa\u591a\u4e2a\u7ebf\u7a0b\u84dd\u5c4f\/\u5173\u673a\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u56de\u5230\u4e3b\u7a0b\u5e8f\uff0c\u7ee7\u7eed\u5f80\u4e0b\u770b\u6d41\u7a0b\u3002\uff08\u6ce8\uff1a\u6b64\u65f6\u8fd8\u5728\u6709\u53c2\u6570\u5b58\u5728\u7684\u6761\u4ef6\u5185\uff0c\u5373\u6709\u53c2\u6570\u4f46\u4e0d\u4e3a<code>\/watchdog<\/code>\uff0c\u56e0\u4e3a\u5728\u4e4b\u524d\u521b\u5efa\u7a97\u53e3\u540e\u4f7f\u7528<code>while<\/code>\u6b7b\u5faa\u73af\u83b7\u53d6\u5e76\u5904\u7406\u7a97\u53e3\u6d88\u606f\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-591\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/20-1.png\" alt=\"\" width=\"582\" height=\"383\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/20-1.png 582w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/20-1-300x197.png 300w\" sizes=\"auto, (max-width: 582px) 100vw, 582px\" \/><\/p>\n<p>\u8fde\u7eed\u8c03\u7528<code>CreateFile<\/code>\u548c<code>WriteFile<\/code>\u5c1d\u8bd5\u5411<code>\\\\.\\PhysicalDrive0<\/code>\u53730\u53f7\u78c1\u76d8\u8bbe\u5907\u5199\u5165\u6247\u533a\u5185\u5bb9\u3002\u4e2d\u95f4\u90a3\u4e00\u5927\u6bb5\u5c31\u662f\u83b7\u53d6\u5199\u5165\u5185\u5bb9\uff0c\u8fd9\u4e00\u6bb5\u5c31\u662f\u8986\u76d6\u7cfb\u7edf<code>MBR<\/code>\u7684\u8fc7\u7a0b\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-593\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/22-1.png\" alt=\"\" width=\"539\" height=\"60\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/22-1.png 539w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/22-1-300x33.png 300w\" sizes=\"auto, (max-width: 539px) 100vw, 539px\" \/><\/p>\n<p>\u9996\u5148\u6253\u5f00\u5f53\u524d\u78c1\u76d8\u76ee\u5f55\u4e0b\u7684<code>note.txt<\/code>\uff0c\u5199\u5165\u4ee5\u4e0b\u5185\u5bb9\uff0c\u5b8c\u6210\u540e\u8c03\u7528<code>notepad<\/code>\u5c06\u5176\u6253\u5f00\uff0c\u5373\u663e\u793a\u4e86\u8fd9\u6bb5\u4fe1\u606f\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-592\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/21-1.png\" alt=\"\" width=\"568\" height=\"515\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/21-1.png 568w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/21-1-300x272.png 300w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>\u4e4b\u540e\u5faa\u73af\u521b\u5efa\u7ebf\u7a0b\u6267\u884c\u51fd\u6570<code>sub_401A2B<\/code><\/p>\n<p>\u7136\u540e\u8fdb\u5165<code>while() Sleep<\/code>\u6c38\u4e45\u963b\u585e\u72b6\u6001<\/p>\n<p>&nbsp;<\/p>\n<p>\u4e2d\u95f4\u8fd9\u4e00\u6bb5\u6709\u70b9\u96be\u5206\u6790\uff0c\u6211\u4eec\u5148\u770b\u63a5\u4e0b\u6765\u7684\u7a0b\u5e8f\u3002\uff08\u6ce8\uff1a\u6b64\u65f6\u4e3a\u65e0\u53c2\u6570\u5185<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-594\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/23-1.png\" alt=\"\" width=\"913\" height=\"348\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/23-1.png 913w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/23-1-300x114.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/23-1-768x293.png 768w\" sizes=\"auto, (max-width: 913px) 100vw, 913px\" \/><\/p>\n<p>\u4e00\u5806\u8b66\u544a\u4fe1\u606f\u3002<\/p>\n<p>\u90fd\u786e\u8ba4\u4e4b\u540e<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-595\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/24-1.png\" alt=\"\" width=\"469\" height=\"372\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/24-1.png 469w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/24-1-300x238.png 300w\" sizes=\"auto, (max-width: 469px) 100vw, 469px\" \/><\/p>\n<p>\u9996\u5148\u901a\u8fc7<code>ShellExecuteEx<\/code>\u521b\u5efa5\u4e2a\u5e26<code>\/watchdog<\/code>\u53c2\u6570\u7684\u7a0b\u5e8f\uff08\u4f5c\u7528\u5982\u4e0a\u5206\u6790\uff09\uff0c\u518d\u6267\u884c\u4e00\u4e2a\u5e26<code>\/main<\/code>\u53c2\u6570\u7684\u7a0b\u5e8f\uff0c\u8fd8<code>SetPriorityClass (0x80u=HIGH_PRIORITY_CLASS)<\/code>\u8bbe\u7f6e\u6700\u9ad8\u4f18\u5148\u7ea7\u540e\u672c\u8fdb\u7a0b\u9000\u51fa\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u73b0\u5728\u6574\u4e2a\u7a0b\u5e8f\u7684\u6d41\u7a0b\u90fd\u5927\u6982\u6e05\u695a\u4e86\uff1a\u5148\u662f\u7528\u6237\u70b9\u51fb\uff0c\u6b64\u65f6\u65e0\u53c2\u6570\uff0c\u663e\u793a\u4e24\u4e2a\u8b66\u544a\uff0c\u90fd\u786e\u8ba4\u540e\u521b\u5efa5\u4e2a<code>\/watch<\/code>\u8fdb\u7a0b\u548c\u4e00\u4e2a<code>\/main<\/code>\u8fdb\u7a0b\u5e76\u9000\u51fa\u3002<code>\/watchdog<\/code>\u8fdb\u7a0b\u53ea\u662f\u68c0\u6d4b\u662f\u5426\u6709\u81ea\u5df1\u7684\u8fdb\u7a0b\u88ab\u6740\u6b7b\u6216\u8005\u8981\u5173\u673a\u4e86\uff0c\u90a3\u4e2a\u65f6\u5019\u76f4\u63a5\u84dd\u5c4f\/\u5173\u673a\u3002<code>\/main<\/code>\u8fdb\u7a0b\u624d\u662f\u6267\u884c\u4e3b\u8981\u529f\u80fd\u7684\u8fdb\u7a0b\uff0c\u5148\u662f\u8986\u76d6\u78c1\u76d8<code>MBR<\/code>\uff0c\u7136\u540e\u5f00\u59cb<del>\u641e\u4e8b<\/del>\u641e\u4e8b\uff08\u597d\u50cf\u786e\u5b9e\u662f\u771f\u7684\u641e\u4e8b<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/>\uff09\u3002<\/p>\n<p>\u56de\u5230\u521a\u521a\u53c2\u6570<code>\/main<\/code>\uff08\u73b0\u5728\u5df2\u7ecf\u77e5\u9053\u662f\u5b83\u4e86\uff09\u6267\u884c\u7684\u5730\u65b9\uff0c\u73b0\u5728\u6765\u8be6\u7ec6\u5206\u6790\u8fd9\u6bb5\u8c03\u7528\uff08\u5faa\u73af\u521b\u5efa\u7ebf\u7a0b\u6267\u884c\u51fd\u6570<code>sub_401A2B<\/code>\uff09\u7684\u529f\u80fd\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-597\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/25-1.png\" alt=\"\" width=\"564\" height=\"186\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/25-1.png 564w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/25-1-300x99.png 300w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/p>\n<p>\u8ddf\u8fdb<code>sub_401A2B()<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-598\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/26-1.png\" alt=\"\" width=\"563\" height=\"318\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/26-1.png 563w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/26-1-300x169.png 300w\" sizes=\"auto, (max-width: 563px) 100vw, 563px\" \/><\/p>\n<p>\u53d1\u73b0\u8fd9\u4e2a\u51fd\u6570\u53ea\u662f\u7b80\u5355\u5730\u8c03\u7528\u4e86\u4ee5\u53c2\u6570<code>lpThreadParameter<\/code>\u4f20\u8fdb\u6765\u7684\u51fd\u6570\uff0c\u5e76\u4e14\u53ea\u8981\u51fd\u6570\u8c03\u7528\u6210\u529f\u7684\u8bdd\u8fd9\u4e2a\u51fd\u6570\u7684\u4e24\u4e2a\u53c2\u6570\u90fd\u81ea\u52a0\uff0c10sec\u540e\u53c8\u91cd\u65b0\u6267\u884c\u4e00\u904d\u3002<\/p>\n<p>\u6240\u4ee5\u95ee\u9898\u7684\u6240\u5728\u4e0d\u662f\u8fd9\u4e2a\u51fd\u6570\uff0c\u800c\u662f\u53c2\u6570<code>v9<\/code><\/p>\n<p>\u56de\u5230\u539f\u51fd\u6570\uff0c\u5206\u6790\u4e00\u4e0b\u6d41\u7a0b\uff1a\u9996\u5148<code>v8=0; v9=(DWORD *)&amp;off_405130<\/code><\/p>\n<p>\u7136\u540e<code>Sleep() v9<\/code>\u6307\u5411\u7684\u7a7a\u95f4\u7684\u7b2c\u4e8c\u4e2a<code>DWORD<\/code>\u5b57\u8282\u7684\u6570\u636e\u5927\u5c0f\u3002<\/p>\n<p>\u63a5\u7740<code>CreateThread() v9<\/code>\u6307\u5411\u7684\u7a7a\u95f4\u7b2c\u4e00\u4e2a<code>DWORD<\/code>\u6307\u5411\u7684\u51fd\u6570\u3002<\/p>\n<p>\u6700\u540e<code>v9<\/code>\u8d8a\u8fc7\u4e24\u4e2a<code>DWORD<\/code>\u5b57\u8282\uff0c\u5e76\u4e14\u963b\u585e10msec\u540e\u7ee7\u7eed\u3002<\/p>\n<p>\u770b\u5f97\u51fa\u6765\uff0c\u6700\u91cd\u8981\u7684\u5c31\u662f\u5728<code>off_405130<\/code>\u5904\u7684\u6570\u636e\u4e86\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-601\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/27-1.png\" alt=\"\" width=\"571\" height=\"409\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/27-1.png 571w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/27-1-300x215.png 300w\" sizes=\"auto, (max-width: 571px) 100vw, 571px\" \/><\/p>\n<p>\u51fd\u6570\u90fd\u76f4\u63a5\u786c\u7f16\u7801\u4e86\u5728\u91cc\u9762\uff0c\u6211\u4eec\u4e00\u4e2a\u4e00\u4e2a\u5206\u6790\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_4014FC<\/code>\uff08\u51fd\u6570\u53ea\u6709\u4e00\u4e2a\u53c2\u6570\uff0c\u6211\u4e5f\u4e0d\u77e5\u9053\u4e3a\u4ec0\u4e48<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-617\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/37.png\" alt=\"\" width=\"648\" height=\"224\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/37.png 648w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/37-300x104.png 300w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/p>\n<p>\u5148\u662f<code>sub_401A55()<\/code>\u968f\u673a\u6570\u5230<code>v2<\/code>\uff0c\u7136\u540e<code>ShellExecute (&amp;lpFile)[v2 % 0x2E]<\/code>\uff0c\u5373\u968f\u673a\u6253\u5f00\u4ee5\u4e0b\u6587\u4ef6<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-618\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/38.png\" alt=\"\" width=\"836\" height=\"500\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/38.png 836w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/38-300x179.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/38-768x459.png 768w\" sizes=\"auto, (max-width: 836px) 100vw, 836px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-619\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/39.png\" alt=\"\" width=\"774\" height=\"305\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/39.png 774w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/39-300x118.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/39-768x303.png 768w\" sizes=\"auto, (max-width: 774px) 100vw, 774px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_40156D<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-620\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/40.png\" alt=\"\" width=\"408\" height=\"384\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/40.png 408w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/40-300x282.png 300w\" sizes=\"auto, (max-width: 408px) 100vw, 408px\" \/><\/p>\n<p>\u5148\u662f<code>GetCursorPos<\/code>\u83b7\u53d6\u6307\u9488\u4f4d\u7f6e\uff0c\u7136\u540e\u75af\u72c2\u5728\u4e00\u5b9a\u8303\u56f4\u5185\u968f\u673a\uff0c\u6700\u540e<code>SetCursorPos<\/code>\uff0c\u5b9e\u73b0\u4e86\u9f20\u6807\u4e0d\u65ad\u6296\u52a8<del>\u8ddf\u559d\u4e86\u8109\u52a8\u4e00\u6837<\/del>\u7684\u6548\u679c\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_4017A5<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-622\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/41.png\" alt=\"\" width=\"417\" height=\"185\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/41.png 417w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/41-300x133.png 300w\" sizes=\"auto, (max-width: 417px) 100vw, 417px\" \/><\/p>\n<p>\u4e5f\u5f88\u660e\u663e\uff0c\u5148\u662f\u968f\u673a\u4e86\u4e00\u5b9a\u8303\u56f4\u5185\u7684\u6570\u4f5c\u4e3a<code>SendInput<\/code>\u7684\u53c2\u6570\uff08<code>1=INPUT_KEYBOARD<\/code>\uff09\uff0c\u4e14\u8fd9\u4e2a\u968f\u673a\u6570\u4f5c\u4e3a\u53ef\u89c6<code>ASCII<\/code>\u88ab\u6a21\u62df\u53d1\u9001\u81f3\u952e\u76d8\u3002\uff08<code>'0'=48 '0'+42=90='Z'<\/code>\uff09<\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_4016A0<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-623\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/42.png\" alt=\"\" width=\"379\" height=\"170\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/42.png 379w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/42-300x135.png 300w\" sizes=\"auto, (max-width: 379px) 100vw, 379px\" \/><\/p>\n<p>\u968f\u673a\u4e86\u4e00\u4e2a\u6570\u4f5c\u4e3a<code>PlaySound<\/code>\u7684\u53c2\u6570<code>(&amp;pszSound)[v1 % 3]<\/code>\uff0c\u5373\u968f\u673a\u64ad\u653e\u4e0b\u5217\u58f0\u97f3<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-624\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/43.png\" alt=\"\" width=\"611\" height=\"93\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/43.png 611w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/43-300x46.png 300w\" sizes=\"auto, (max-width: 611px) 100vw, 611px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_4015D4<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-625\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/44.png\" alt=\"\" width=\"662\" height=\"234\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/44.png 662w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/44-300x106.png 300w\" sizes=\"auto, (max-width: 662px) 100vw, 662px\" \/><\/p>\n<p>\u5148\u7528<code>GetDesktopWindow()<\/code>\u83b7\u53d6\u4e86\u9876\u5c42\u684c\u9762\u7684\u53e5\u67c4\uff0c\u518d\u7528<code>GetWindowDC()<\/code>\u83b7\u53d6\u4e86\u684c\u9762\u7684\u7a97\u53e3\u8bbe\u5907\u4e0a\u4e0b\u6587\uff08DC\uff09\uff0c\u63a5\u7740\u7528<code>GetWindowRect<\/code>\u83b7\u53d6\u684c\u9762\u7684\u5927\u5c0f\uff0c\u6700\u540e\u4f7f\u7528<code>BitBlt()<\/code>\u7ed8\u5236\u56fe\u5f62\u5e76<code>ReleaseDC()<\/code>\u5173\u95ed\u5199\u5165\u3002<\/p>\n<p><code>BitBlt()<\/code>\u53c2\u6570\u4e2d\u7684<code>0x330008=NOTSRCCOPY<\/code>\u5373<code>\u201c <\/code><br \/>\n<code>Copies the inverted source rectangle to the destination.\u201d(MSDN)<\/code>\uff0c\u5c31\u662f\u5b9e\u73b0\u4e86\u5c06\u6574\u4e2a\u684c\u9762\u8fdb\u884c\u53cd\u8272\u663e\u793a\u7684\u529f\u80fd\u3002\uff08\u4e00\u4e2aF5\u5237\u65b0\u5373\u53ef\u590d\u539f\uff09<\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_40162A<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-626\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/45.png\" alt=\"\" width=\"625\" height=\"171\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/45.png 625w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/45-300x82.png 300w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/p>\n<p>\u53d1\u73b0\u521b\u5efa\u4e86\u4e00\u4e2a\u65b0\u7ebf\u7a0b\u6267\u884c<code>sub_401994<\/code>\uff0c\u8ddf\u8fdb<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-627\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/46.png\" alt=\"\" width=\"503\" height=\"196\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/46.png 503w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/46-300x117.png 300w\" sizes=\"auto, (max-width: 503px) 100vw, 503px\" \/><\/p>\n<p>\u529f\u80fd\u4e0e\u4e4b\u524d\u5206\u6790\u7684\u7c7b\u4f3c\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_401866<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-628\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/47.png\" alt=\"\" width=\"528\" height=\"544\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/47.png 528w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/47-291x300.png 291w\" sizes=\"auto, (max-width: 528px) 100vw, 528px\" \/><\/p>\n<p>\u9996\u5148\u4f7f\u7528<code>GetSystemMetrics()<\/code>\u83b7\u53d6<code>ICO<\/code>\u652f\u6301\u5927\u5c0f\uff0c\u5982\u4e0b<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-629\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/48.png\" alt=\"\" width=\"832\" height=\"67\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/48.png 832w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/48-300x24.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/48-768x62.png 768w\" sizes=\"auto, (max-width: 832px) 100vw, 832px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-630\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/49.png\" alt=\"\" width=\"827\" height=\"61\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/49.png 827w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/49-300x22.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/49-768x57.png 768w\" sizes=\"auto, (max-width: 827px) 100vw, 827px\" \/><\/p>\n<p>\u7136\u540e\u540c\u6837\u7684\u83b7\u53d6\u684c\u9762<code>DC<\/code>\uff0c\u9f20\u6807\u4f4d\u7f6e\u3002\u4e4b\u540e\u7528<code>LoadIcon()<\/code>\u8bfb\u53d6<code>ICO<\/code>\u56fe\u7247\uff0c\u5728\u9f20\u6807\u4f4d\u7f6e\u4e0a\u8c03\u7528<code>DrawIcon<\/code>\u7ed8\u5236<code>ICO<\/code>\u56fe\u7247\u540e\uff0c\u518d\u968f\u673a\u751f\u6210\u4f4d\u7f6e\u7ed8\u5236<code>ICO<\/code>\u56fe\u7247\u3002\uff08\u540c\u6837F5\u5237\u65b0\u53ef\u53bb\u9664\uff09<\/p>\n<p>\u6ce8\uff1a<code>0x7F01=32513=IDI_ERROR   0x7F03=32515=IDI_EXCLAMATION<\/code><\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_401688<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-631\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/50.png\" alt=\"\" width=\"293\" height=\"146\" \/><\/p>\n<p>\u4f7f\u7528\u4e86<code>EnumChildWindows()<\/code>\u83b7\u53d6\u684c\u9762\u4e0a\u6240\u6709\u5b50\u7a97\u53e3\uff0c\u5e76\u4e14\u7528<code>EnumFunc()<\/code>\u51fd\u6570\u56de\u8c03\uff0c\u8ddf\u8fdb\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-632\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/51.png\" alt=\"\" width=\"569\" height=\"223\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/51.png 569w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/51-300x118.png 300w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><\/p>\n<p>\u4f7f\u7528<code>GlobalAlloc()<\/code>\u5206\u914d\u5806\u7a7a\u95f4\uff0c\u4f5c\u4e3a<code>SendMessageTimeout()<\/code>\u7684\u4e00\u53c2\u6570\uff0c\u540c\u65f6\u8bbe\u7f6e<code>Msg<\/code>\uff0c\u8d85\u65f6\u65f6\u95f4\u4e3a<code>0x64=100msec<br \/>\n<\/code><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-634\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/52.png\" alt=\"\" width=\"370\" height=\"320\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/52.png 370w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/52-300x259.png 300w\" sizes=\"auto, (max-width: 370px) 100vw, 370px\" \/><\/p>\n<p><code>Msg=0xD<\/code>\uff0c\u5f00\u59cb\u5148\u83b7\u53d6\u7a97\u53e3\u4e2d\u6240\u6709\u6587\u672c\uff0c\u5b58\u5230<code>v2<\/code>\uff0c\u7136\u540e\u5c06<code>v2<\/code>\u4ee3\u5165<code>sub_401AA0<\/code>\uff0c\u6700\u540e<code>Msg=0xC<\/code>\u91cd\u65b0\u8bbe\u7f6e\u7a97\u53e3\u7684\u6587\u672c\u4e3a\u5904\u7406\u540e\u7684<code>v2<\/code>\u3002\u8ddf\u8fdb\u6b64\u51fd\u6570\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-635\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/53.png\" alt=\"\" width=\"476\" height=\"580\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/53.png 476w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/53-246x300.png 246w\" sizes=\"auto, (max-width: 476px) 100vw, 476px\" \/><\/p>\n<p>\u5bf9\u4e0d\u8d77\u6839\u672c\u4e0d\u60f3\u770b<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720180624220829.jpg\" alt=\"\" width=\"58\" height=\"63\" \/><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/>\uff0c\u81ea\u5df1\u53bb\u8bd5\u8fc7\u4e4b\u540e\u77e5\u9053\u8fd9\u4e2a\u51fd\u6570\u4f5c\u7528\u662f\u98a0\u5012\u5b57\u7b26\u4e32\uff0c\u540c<code>STL<\/code>\u4e2d<code>reverse()<\/code>\u4e00\u6837\u3002<\/p>\n<p>\u8fd9\u4e2a\u51fd\u6570\u529f\u80fd\u5c31\u662f\u98a0\u5012\u684c\u9762\u5b50\u7a97\u53e3\u4e2d\u6240\u6709\u6587\u672c\u6846\u91cc\u7684\u5b57\u7b26\u4e32\u3002<\/p>\n<p>\uff08\u6ce8\uff1a\u8fd9\u91cc\u7684\u684c\u9762\u4e0d\u4ec5\u4ec5\u662f<code>explorer.exe<\/code>\uff0c\u8fd8\u6709\u5176\u5b50\u8fdb\u7a0b\uff0c\u5c31\u662f\u6240\u6709\u901a\u8fc7\u53cc\u51fb\u6253\u5f00\u7684\u7a0b\u5e8f\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_4017E9<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-636\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/54.png\" alt=\"\" width=\"799\" height=\"226\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/54.png 799w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/54-300x85.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/54-768x217.png 768w\" sizes=\"auto, (max-width: 799px) 100vw, 799px\" \/><\/p>\n<p><code>StretchBlt()<\/code>\u548c<code>BitBlt()<\/code>\u7684\u533a\u522b\u5c31\u662f\u524d\u8005\u4f1a\u6839\u636e<code>Dst<\/code>\u653e\u7f29\u56fe\u50cf\uff0c\u540e\u8005\u53ea\u662f\u5355\u7eaf\u62f7\u8d1d\u3002<\/p>\n<p><code>StretchBlt()<\/code>\u4e2d\u53c2\u6570<code>0xCC0020=SRCCOPY<\/code>\uff0c\u5373\u5c06\u6574\u4e2a\u684c\u9762\u7f29\u5c0f<code>50,50,100,100<\/code><\/p>\n<p>\u5b9e\u73b0\u4e86\u65e0\u9650\u5faa\u73af\u7f29\u5c0f\u5c4f\u5e55\u7684\u6548\u679c\u3002\uff08\u540c\u6837\uff0cF5\u5237\u65b0\u53ef\u590d\u539f\uff09<\/p>\n<p>&nbsp;<\/p>\n<p>\u6765\u5230<code>sub_4016CD<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-637\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/55.png\" alt=\"\" width=\"477\" height=\"585\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/55.png 477w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/55-245x300.png 245w\" sizes=\"auto, (max-width: 477px) 100vw, 477px\" \/><\/p>\n<p>\u751f\u6210\u4e00\u5806\u968f\u673a\u6570\uff0c\u7136\u540e\u518d\u4e00\u5b9a\u8303\u56f4\u5185\u968f\u673a\u590d\u5236\u56fe\u50cf\uff0c\u9020\u6210\u6df7\u4e71\u7684\u6548\u679c\uff08\u540c\u6837F5\u53ef\u53bb\u9664\uff09<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u81f3\u6b64\u6240\u6709\u7684\u529f\u80fd\u90fd\u5206\u6790\u5b8c\u4e86\u3002<\/p>\n<p>\u603b\u7ed3\uff1a \u53cc\u51fb\u6253\u5f00\u75c5\u6bd2\u6587\u4ef6\u65f6\uff0c\u9996\u5148\u5f39\u51fa\u4fe9\u8b66\u544a\u6846\uff0c\u70b9\u53d6\u6d88\u76f4\u63a5\u9000\u51fa\uff0c\u70b9\u786e\u5b9a\u5219\u521b\u5efa\u4e94\u4e2a\u53c2\u6570<code>\/watchdog<\/code>\u548c\u4e00\u4e2a\u53c2\u6570<code>\/main<\/code>\u7684\u8fdb\u7a0b\u3002<code>\/watchdog<\/code>\u8fdb\u7a0b\u68c0\u6d4b\u662f\u5426\u6709\u75c5\u6bd2\u8fdb\u7a0b\u88ab\u5173\u95ed\u6216\u8005\u5c06\u8981\u5173\u673a\uff0c\u6709\u7684\u8bdd\u5f39\u51fa20\u4e2a\u63d0\u793a\u6846\uff0c\u7136\u540e\u84dd\u5c4f\/\u5173\u673a\u3002<code>\/main<\/code>\u8fdb\u7a0b\u9996\u5148\u4fee\u6539\u78c1\u76d8<code>MBR<\/code>\uff0c\u7136\u540e\u7528\u8bb0\u4e8b\u672c\u5f39\u51fa\u4fe1\u606f\uff0c\u6700\u540e\u5faa\u73af\u6267\u884c\u6253\u5f00\u7a0b\u5e8f\/\u64ad\u653e\u58f0\u97f3\/\u53cd\u8272\u5c4f\u5e55\/\u653e\u56fe\u7247\/\u4e0d\u65ad\u7f29\u653e\u5c4f\u5e55\/\u968f\u610f\u590d\u5236\u5c4f\u5e55\u5185\u5bb9\u7b49\u64cd\u4f5c\u5e76\u5835\u585e\u3002<\/p>\n<p>\u611f\u89c9\u9664\u4e86\u6539<code>MBR<\/code>\u5176\u5b83\u597d\u50cf\u90fd\u4e0d\u4f1a\u600e\u4e48\u6837<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>\u6240\u4ee5\u5e2e\u5b83\u628a\u6539<code>MBR<\/code>\u53bb\u6389\u5c31\u5b89\u5168\u4e86<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-644\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/56.png\" alt=\"\" width=\"635\" height=\"280\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/56.png 635w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/56-300x132.png 300w\" sizes=\"auto, (max-width: 635px) 100vw, 635px\" \/><\/p>\n<p>\u6e90\u4ee3\u7801\uff0c\u8981\u53bb\u6389<code>CreateFile<\/code>\u5e76\u4e14\u4e0d\u89e6\u53d1<code>ExitProcess<\/code><\/p>\n<p>\u9996\u5148\u628a\u5e95\u4e0b\u7684<code>jnz<\/code>\u6539\u6210<code>jmp<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-645 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/57.png\" alt=\"\" width=\"445\" height=\"65\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/57.png 445w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/57-300x44.png 300w\" sizes=\"auto, (max-width: 445px) 100vw, 445px\" \/><\/p>\n<p>\u7136\u540e\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-646\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/58.png\" alt=\"\" width=\"596\" height=\"503\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/58.png 596w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/58-300x253.png 300w\" sizes=\"auto, (max-width: 596px) 100vw, 596px\" \/><\/p>\n<p>\u518d\u6765\u5230\u8fd9\u91cc<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-647\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/59.png\" alt=\"\" width=\"610\" height=\"289\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/59.png 610w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/59-300x142.png 300w\" sizes=\"auto, (max-width: 610px) 100vw, 610px\" \/><\/p>\n<p>\u540c\u6837\u628a<code>jnz<\/code>\u6362\u6210<code>jmp<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-648\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/60.png\" alt=\"\" width=\"480\" height=\"67\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/60.png 480w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/60-300x42.png 300w\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" \/><\/p>\n<p>\u518d\u7136\u540e\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-649\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/61.png\" alt=\"\" width=\"627\" height=\"560\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/61.png 627w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/61-300x268.png 300w\" sizes=\"auto, (max-width: 627px) 100vw, 627px\" \/><\/p>\n<p>\u7136\u540e\u5f88\u5b8c\u7f8e<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-650\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/62.png\" alt=\"\" width=\"535\" height=\"585\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/62.png 535w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/62-274x300.png 274w\" sizes=\"auto, (max-width: 535px) 100vw, 535px\" \/><\/p>\n<p>\u524d\u9762\u5220\u7684\u592a\u723d\u4e00\u4e0d\u5c0f\u5fc3\u628a\u8fd9\u4e2a\u7ed9\u5220\u4e86<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-652\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/64.png\" alt=\"\" width=\"469\" height=\"73\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/64.png 469w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/64-300x47.png 300w\" sizes=\"auto, (max-width: 469px) 100vw, 469px\" \/><\/p>\n<p>\u5f04\u56de\u53bb\u5c31\u597d\u4e86<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-654\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/65-1.png\" alt=\"\" width=\"305\" height=\"116\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/65-1.png 305w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/65-1-300x114.png 300w\" sizes=\"auto, (max-width: 305px) 100vw, 305px\" \/><\/p>\n<p>\u8fd8\u6709\u8fd9\u4e2a\u4e5f\u8981\u5f04\u56de\u53bb\uff08\u624b\u6253\u5c31\u6210\u8fd9\u6837\u4e86\uff0c\u4e0d\u8fc7\u4e0d\u5f71\u54cd<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-656\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/67.png\" alt=\"\" width=\"652\" height=\"106\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/67.png 652w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/67-300x49.png 300w\" sizes=\"auto, (max-width: 652px) 100vw, 652px\" \/><\/p>\n<p>\u7136\u540e\u5199\u5165<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-655\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/66.png\" alt=\"\" width=\"483\" height=\"265\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/66.png 483w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/66-300x165.png 300w\" sizes=\"auto, (max-width: 483px) 100vw, 483px\" \/><\/p>\n<p>\u4e00\u4efd\u65e0\u6bd2\u65e0\u5bb3\u5b89\u5168\u7684<code>MEMZ.exe<\/code>\u5c31\u5f04\u597d\u4e86<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>\u3002\u3002\u3002\u3002\u3002\u3002\u867d\u7136\u8fd0\u884c\u4e0d\u6b63\u5e38<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>\u522b\u4e86\u522b\u4e86\u522b\u8fd9\u6837\u6362\uff0c\u91cd\u65b0\u66ff\u6362\u4e00\u6b21\uff0c\u8fd9\u6b21\u53ea\u4fee\u6539<code>jmp<\/code>\u4ee5\u53ca<code>call<\/code>\u4ee5\u53ca<code>push<\/code>\u8c03\u7528<\/p>\n<p>\u7136\u540e\u5c31\u6210\u529f\u7684\u53bb\u6389\u4e86\u5199<code>MBR<\/code>\u7684\u529f\u80fd\u3002<\/p>\n<p>\u56e0\u4e3a\u5b83\u5b9e\u5728\u662f\u592a\u5b89\u5168\u4e86\uff0c\u4ee5\u81f3\u4e8e360\u90fd\u62a5\u6bd2\u4e86<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>\u4fee\u6539\u7248\uff08\u53bb\u9664\u5199<code>MBR<\/code>\uff0c\u5b89\u5168\u65e0\u5bb3\uff0c\u53ef\u4ee5\u5728\u771f\u673a\u4e0a\u8fd0\u884c\uff09\uff1a<a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ\/memz_edit.zip\">memz_edit.zip<\/a>\uff08\u5bc6\u7801\uff1a<code>memz!funny<\/code><\/p>\n<p>\uff08PS\uff1a\u4ece\u4e0a\u9762\u7684\u6e90\u4ee3\u7801\u5206\u6790\u770b\u5f97\u51fa\u6765\uff0c\u5176\u5b9e\u53ea\u8981<code>taskkill \/f \/im MEMZ.exe<\/code>\u5c31\u597d\u4e86\uff0c\u4ec0\u4e48\u90fd\u4e0d\u4f1a\u53d1\u751f<\/p>\n<p>\uff08\u53ef\u4ee5\u76f4\u63a5\u5199\u4e00\u4e2a\u68c0\u6d4b\u6309\u952e\u7684\u7a0b\u5e8f\uff0cxx\u952e\u6309\u4e0b<code>while(1)if(GetAsyncKeyState(...))<\/code>\u76f4\u63a5\u5168\u90e8\u5173\u95ed<code>MEMZ.exe<\/code>\uff0c\u662f\u5b8c\u7f8e\u5b89\u5168\u7684\u505a\u6cd5\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u603b\u611f\u89c9\u628a\u5199<code>MBR<\/code>\u53bb\u4e86\u8fd9\u7a0b\u5e8f\u4e50\u8da3\u5c31\u5c11\u4e86\u4e00\u534a<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>\u6240\u4ee5\u6211\u7279\u5730\u628a<code>MBR<\/code>\u53ca<code>NC<\/code>\u4ee3\u7801\u63d0\u51fa\u6765\uff1a<a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ\/new.bin\">dump.bin<\/a>\uff08\u5982\u679c\u53ea\u6709<a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ\/mbr.bin\">mbr.bin<\/a>\u662f\u4e0d\u591f\u7684<\/p>\n<p>\u76f4\u63a5\u7528<code>WinHex<\/code>\u7b49\u5de5\u5177\u8986\u76d6\u5199\u5230\u865a\u62df\u673a\u7684\u78c1\u76d8\u504f\u79fb\u91cf<code>0<\/code>\u5c31\u53ef\u4ee5\u4e86\u3002<\/p>\n<p>\u4e3a\u4e86\u65b9\u4fbf\u5199\u5165\uff0c\u6211\u8fd8\u7279\u5730\u5199\u4e86\u4e2a\u5c0f\u5de5\u5177 <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ\/WriteMBR.exe\">WriteMBR.exe<\/a>\uff08\u6e90\u4ee3\u7801\uff1a<a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ\/WriteMBR.zip\">WriteMBR.zip<\/a><\/p>\n<p>\u76f4\u63a5\u628a<code>.bin<\/code>\u6587\u4ef6\u62d6\u8fdb\u53bb\u5c31\u53ef\u4ee5\u4e86\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u672c\u6765\u5f04\u5230\u8fd9\u91cc\u5f88\u5f00\u5fc3<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720180624220829.jpg\" alt=\"\" width=\"58\" height=\"63\" \/>\u5f88\u5feb\u4e50<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720180624220829.jpg\" alt=\"\" width=\"58\" height=\"63\" \/><\/p>\n<p>\u76f4\u5230\u6211\u770b\u5230\u4e86\u8fd9\u4e2a<a href=\"https:\/\/github.com\/Leurak\/MEMZ\"> https:\/\/github.com\/Leurak\/MEMZ<\/a><\/p>\n<p>MMP*******************************************************************************************************************************<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-667 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u56fe\u724720180823214535.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>MD\u6709\u6e90\u4ee3\u7801\u6211\u8fd8\u5206\u6790\u4e2a**<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-667 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u56fe\u724720180823214535.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u7b49\u7b49\uff0c\u5176\u5b9e\u8fd9\u6ce2\u4e0d\u4e8f\u554a\u3002<\/p>\n<p>\u56e0\u4e3a\u5728Windows\u4e0a\u914d\u7f6e\u7f16\u8bd1\u73af\u5883\u6bd4TM\u76f4\u63a5\u6539\u6c47\u7f16\u8fd8\u96be<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-667 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u56fe\u724720180823214535.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u597d\u4e86\uff0c\u6e90\u4ee3\u7801\u6709\u662f\u6709\uff0c\u4f46\u662f\u6211\u4e5f\u4e0d\u4f1a\u6539<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p>\u53ea\u597d\u81ea\u5df1\u7422\u78e8\u8fd9\u4e5f\u5f04\u4e2a\u9a9a\u4e1c\u897f\u51fa\u6765\u3002<\/p>\n<p>\u63a8\u8350\u4e0b\u8f7d\u5730\u5740\uff1a <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ_av\/av_full.rar\">av_full.rar<\/a> \uff08\u65e0\u6253\u5305\uff0c\u591a\u6587\u4ef6<\/p>\n<p>\uff08\u6ce8\uff1aWin7\u4ee5\u4e0a\u53ef\u80fd\u65e0\u6cd5\u8fd0\u884c\uff01 <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ_av\/av_packed_full.rar\">av_packed_full.rar<\/a> \uff08\u6253\u5305\u7248\u672c\uff0c\u5355\u6587\u4ef6<\/p>\n<p>\uff08\u6ce8\uff1a\u65e0\u538b\u7f29 <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ_av\/av_packed_full.exe\">av_packed_full.exe<\/a><\/p>\n<p>\uff08\u6ce8\uff1a\u7cbe\u7b80\u8b66\u544a\uff1a\u53ef\u80fd\u8fd0\u884c\u4e0d\u6b63\u5e38\uff01\uff01\uff01 <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ_av\/av_packed.exe\">av_packed.exe<\/a> <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ_av\/av_packed.rar\">av_packed.rar<\/a><\/p>\n<p>\u6ce8\uff1a\u5b89\u5168\u65e0\u6bd2\u8b66\u544a\uff01 <a href=\"http:\/\/r.virscan.org\/language\/zh-cn\/report\/58c20ab6372e192bf370238cb13bbbdb\">http:\/\/r.virscan.org\/language\/zh-cn\/report\/58c20ab6372e192bf370238cb13bbbdb<\/a><\/p>\n<p>\u81f3\u4e8e360sd&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.\u5927\u5bb6\u90fd\u77e5\u9053\u7684\u3002\uff08QVM\u548cKVM\u5b58\u5728\u610f\u4e49\u4e0d\u660e\uff1f\uff1f\uff1f\uff1f\uff09<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-670\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825153143.png\" alt=\"\" width=\"832\" height=\"59\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825153143.png 832w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825153143-300x21.png 300w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825153143-768x54.png 768w\" sizes=\"auto, (max-width: 832px) 100vw, 832px\" \/><\/p>\n<p><span style=\"font-size: 20px;\"><strong>\u58f0\u660e\uff1a\u672c\u7a0b\u5e8f\u5e76\u4e0d\u4f1a\u7be1\u6539\u4efb\u4f55\u7cfb\u7edf\u6587\u4ef6\uff08\u91cd\u542f\u540e\u5c31\u8ddf\u6ca1\u8fd0\u884c\u8fc7\u4e00\u6837\uff09\uff0c\u53ef\u4ee5\u653e\u5fc3\u7684\u5728\u771f\u673a\u4e0a\u98df\u7528\u3002<\/strong><\/span><\/p>\n<p>\u6e90\u4ee3\u7801\uff1a <a href=\"https:\/\/dl.mnihyc.com\/Other\/MEMZ_av\/av_source.zip\">av_source.zip<\/a> \uff08<code>build with VC6 on win7x64<\/code><\/p>\n<p>\u7279\u522b\u9e23\u8c22\uff1a6332812\uff08\u867d\u7136\u662f\u81ea\u5df1\u62ff\u6765\u7528\u7684w<\/p>\n<p>\u987a\u5e26BUG\uff1a<strong>XP\u4e0a\u81ea\u884c\u5173\u6389\u9759\u97f3\uff0c\u8c22\u8c22\u5408\u4f5c<\/strong><\/p>\n<p style=\"padding-left: 30px;\">\u8fd8\u6709\u6211\u5728Win7\u4e0a\u5199\u7684\uff0c\u754c\u9762\u662f\u8fd9\u6837\u7684\uff1a<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-672\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825154856.png\" alt=\"\" width=\"483\" height=\"123\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825154856.png 483w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825154856-300x76.png 300w\" sizes=\"auto, (max-width: 483px) 100vw, 483px\" \/><\/p>\n<p style=\"padding-left: 30px;\">\u5982\u679c\u62ff\u5230XP\u4e0a\u8fd0\u884c\u754c\u9762\u53d8\u6210\u8fd9\u6837\u77e5\u9053\u4e00\u4e0b\u610f\u601d\u4e00\u4e0b\u5c31\u884c\u54c8<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-77 alignnone\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/06\/QQ\u56fe\u724720170624045141.jpg\" alt=\"\" width=\"56\" height=\"52\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-673\" src=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825154914.png\" alt=\"\" width=\"472\" height=\"97\" srcset=\"https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825154914.png 472w, https:\/\/0.mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/QQ\u622a\u56fe20180825154914-300x62.png 300w\" sizes=\"auto, (max-width: 472px) 100vw, 472px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3 &hellip; <a href=\"https:\/\/0.mnihyc.com\/blog\/archives\/556\" class=\"more-link\">\u7ee7\u7eed\u9605\u8bfb<span class=\"screen-reader-text\">MEMZ \u6e90\u7801\u7ea7\u5206\u6790<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-556","post","type-post","status-publish","format-standard","hentry","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>MEMZ \u6e90\u7801\u7ea7\u5206\u6790 - mnihyc&#039;s Blog<\/title>\n<meta name=\"description\" content=\"MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3\u7801\u5230\u5e95\u662f\u600e\u4e48\u6837\u7684\u3002 \u9996\u5148 \uff0c\u6837\u672c\uff1a MEMZ_virus.zip \uff08\u5bc6\u7801\uff1aMEMZ!virus \u5de5\u5177\uff1aIDA Pro v7.0 IDA7.0.zip &nbsp; &nbsp;\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cf.mnihyc.com\/blog\/archives\/556\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MEMZ \u6e90\u7801\u7ea7\u5206\u6790 - mnihyc&#039;s Blog\" \/>\n<meta property=\"og:description\" content=\"MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3\u7801\u5230\u5e95\u662f\u600e\u4e48\u6837\u7684\u3002 \u9996\u5148 \uff0c\u6837\u672c\uff1a MEMZ_virus.zip \uff08\u5bc6\u7801\uff1aMEMZ!virus \u5de5\u5177\uff1aIDA Pro v7.0 IDA7.0.zip &nbsp; &nbsp;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cf.mnihyc.com\/blog\/archives\/556\" \/>\n<meta property=\"og:site_name\" content=\"mnihyc&#039;s Blog\" \/>\n<meta property=\"article:published_time\" content=\"2018-08-22T16:21:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-10-07T16:47:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png\" \/>\n<meta name=\"author\" content=\"mnihyc\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@mnihyc\" \/>\n<meta name=\"twitter:site\" content=\"@mnihyc\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"mnihyc\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#article\",\"isPartOf\":{\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556\"},\"author\":{\"name\":\"mnihyc\",\"@id\":\"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751\"},\"headline\":\"MEMZ \u6e90\u7801\u7ea7\u5206\u6790\",\"datePublished\":\"2018-08-22T16:21:42+00:00\",\"dateModified\":\"2020-10-07T16:47:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556\"},\"wordCount\":156,\"commentCount\":11,\"publisher\":{\"@id\":\"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751\"},\"image\":{\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage\"},\"thumbnailUrl\":\"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png\",\"articleSection\":[\"\u5b89\u5168\"],\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556\",\"url\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556\",\"name\":\"MEMZ \u6e90\u7801\u7ea7\u5206\u6790 - mnihyc&#039;s Blog\",\"isPartOf\":{\"@id\":\"https:\/\/mnihyc.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage\"},\"image\":{\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage\"},\"thumbnailUrl\":\"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png\",\"datePublished\":\"2018-08-22T16:21:42+00:00\",\"dateModified\":\"2020-10-07T16:47:26+00:00\",\"description\":\"MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3\u7801\u5230\u5e95\u662f\u600e\u4e48\u6837\u7684\u3002 \u9996\u5148 \uff0c\u6837\u672c\uff1a MEMZ_virus.zip \uff08\u5bc6\u7801\uff1aMEMZ!virus \u5de5\u5177\uff1aIDA Pro v7.0 IDA7.0.zip &nbsp; &nbsp;\",\"breadcrumb\":{\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cf.mnihyc.com\/blog\/archives\/556\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage\",\"url\":\"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png\",\"contentUrl\":\"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cf.mnihyc.com\/blog\/archives\/556#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/mnihyc.com\/blog\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"MEMZ \u6e90\u7801\u7ea7\u5206\u6790\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/mnihyc.com\/blog\/#website\",\"url\":\"https:\/\/mnihyc.com\/blog\/\",\"name\":\"mnihyc&#039;s Blog\",\"description\":\"Welcome!\",\"publisher\":{\"@id\":\"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/mnihyc.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"zh-Hans\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751\",\"name\":\"mnihyc\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8d111f863afc3f98816bc96220f97077d470a96f41088de9f19530fc480f8e72?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8d111f863afc3f98816bc96220f97077d470a96f41088de9f19530fc480f8e72?s=96&d=mm&r=g\",\"caption\":\"mnihyc\"},\"logo\":{\"@id\":\"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"MEMZ \u6e90\u7801\u7ea7\u5206\u6790 - mnihyc&#039;s Blog","description":"MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3\u7801\u5230\u5e95\u662f\u600e\u4e48\u6837\u7684\u3002 \u9996\u5148 \uff0c\u6837\u672c\uff1a MEMZ_virus.zip \uff08\u5bc6\u7801\uff1aMEMZ!virus \u5de5\u5177\uff1aIDA Pro v7.0 IDA7.0.zip &nbsp; &nbsp;","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cf.mnihyc.com\/blog\/archives\/556","og_locale":"zh_CN","og_type":"article","og_title":"MEMZ \u6e90\u7801\u7ea7\u5206\u6790 - mnihyc&#039;s Blog","og_description":"MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3\u7801\u5230\u5e95\u662f\u600e\u4e48\u6837\u7684\u3002 \u9996\u5148 \uff0c\u6837\u672c\uff1a MEMZ_virus.zip \uff08\u5bc6\u7801\uff1aMEMZ!virus \u5de5\u5177\uff1aIDA Pro v7.0 IDA7.0.zip &nbsp; &nbsp;","og_url":"https:\/\/cf.mnihyc.com\/blog\/archives\/556","og_site_name":"mnihyc&#039;s Blog","article_published_time":"2018-08-22T16:21:42+00:00","article_modified_time":"2020-10-07T16:47:26+00:00","og_image":[{"url":"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png","type":"","width":"","height":""}],"author":"mnihyc","twitter_card":"summary_large_image","twitter_creator":"@mnihyc","twitter_site":"@mnihyc","twitter_misc":{"\u4f5c\u8005":"mnihyc","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"4 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556#article","isPartOf":{"@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556"},"author":{"name":"mnihyc","@id":"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751"},"headline":"MEMZ \u6e90\u7801\u7ea7\u5206\u6790","datePublished":"2018-08-22T16:21:42+00:00","dateModified":"2020-10-07T16:47:26+00:00","mainEntityOfPage":{"@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556"},"wordCount":156,"commentCount":11,"publisher":{"@id":"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751"},"image":{"@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage"},"thumbnailUrl":"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png","articleSection":["\u5b89\u5168"],"inLanguage":"zh-Hans","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cf.mnihyc.com\/blog\/archives\/556#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556","url":"https:\/\/cf.mnihyc.com\/blog\/archives\/556","name":"MEMZ \u6e90\u7801\u7ea7\u5206\u6790 - mnihyc&#039;s Blog","isPartOf":{"@id":"https:\/\/mnihyc.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage"},"image":{"@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage"},"thumbnailUrl":"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png","datePublished":"2018-08-22T16:21:42+00:00","dateModified":"2020-10-07T16:47:26+00:00","description":"MEMZ \u8fd9\u4e2a\u4e0a\u53e4\u6bd2\u7269\u6211\u4e24\u4e09\u5e74\u524d\u5c31\u4e0b\u8f7d\u4e86\u5b83\u7684\u6837\u672c\uff0c\u7136\u540e\u628a\u5b83\u6254\u5230\u786c\u76d8\u7684\u67d0\u4e2a\u89d2\u843d\u3002\u4eca\u5929\u91cd\u65b0\u7ed9\u5b83\u7ffb\u51fa\u6765\uff0c\u770b\u770b\u5b83\u7684\u6e90\u4ee3\u7801\u5230\u5e95\u662f\u600e\u4e48\u6837\u7684\u3002 \u9996\u5148 \uff0c\u6837\u672c\uff1a MEMZ_virus.zip \uff08\u5bc6\u7801\uff1aMEMZ!virus \u5de5\u5177\uff1aIDA Pro v7.0 IDA7.0.zip &nbsp; &nbsp;","breadcrumb":{"@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cf.mnihyc.com\/blog\/archives\/556"]}]},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556#primaryimage","url":"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png","contentUrl":"https:\/\/mnihyc.com\/blog\/wp-content\/uploads\/2018\/08\/1-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/cf.mnihyc.com\/blog\/archives\/556#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/mnihyc.com\/blog"},{"@type":"ListItem","position":2,"name":"MEMZ \u6e90\u7801\u7ea7\u5206\u6790"}]},{"@type":"WebSite","@id":"https:\/\/mnihyc.com\/blog\/#website","url":"https:\/\/mnihyc.com\/blog\/","name":"mnihyc&#039;s Blog","description":"Welcome!","publisher":{"@id":"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/mnihyc.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"zh-Hans"},{"@type":["Person","Organization"],"@id":"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/61e167d6d591fdd20dcfee2cf848a751","name":"mnihyc","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8d111f863afc3f98816bc96220f97077d470a96f41088de9f19530fc480f8e72?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8d111f863afc3f98816bc96220f97077d470a96f41088de9f19530fc480f8e72?s=96&d=mm&r=g","caption":"mnihyc"},"logo":{"@id":"https:\/\/mnihyc.com\/blog\/#\/schema\/person\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/posts\/556","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/comments?post=556"}],"version-history":[{"count":0,"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/posts\/556\/revisions"}],"wp:attachment":[{"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/media?parent=556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/categories?post=556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/0.mnihyc.com\/blog\/wp-json\/wp\/v2\/tags?post=556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}