发现了一点有意思的地方,大家讨论讨论~(似看懂,却又未看懂~)
打开楼主发给我的飘雪样本~~~
没有运行,只是先用记事本打开了这个文件.
显示的内容有点乱~(这里就不全帖上来了,)
最前面显示了一句话~
This program cannot be run in DOS mode.
(我用快译翻了下(版本有点低):这个计划不能够在操作系统模态中被进行)
下面一段看不懂的东西~(略)
接着,下面看到些稍稍好理解些的地方(当然,如果没有看过楼主提供的链接,这些还是不明白的~)
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ SOFTWARE\VMware, Inc.\VMware Tools ShowTray %s\msvcrt.dll SearchPlugInX SearchPlug SOFTWARE\Microsoft\Internet Explorer SearchPlugIn Type Start ErrorControl Group DisplayName ImagePath System Bus Extender SYSTEM\CurrentControlSet\Services\%s system32\drivers\%s.sys %s\%s.sys %s\drivers %c%c%c%c%c%c%c%c versioncheck http://baidu2.fenleidangdang.com/tj/%d/%s/%s System %d|%s|%s %02X %d 000000000000 %02X%02X%02X%02X%02X%02X *
再略一段~
?memset strlen ?free strcpy ?malloc sprintf ?rand srand !time strcat ?_snprintf ??3@YAXPAX@Z ?fwrite ?fclose ?memcpy ?fopen msvcrt.dll _c_exit _exit N _XcptFilter _cexit ?exit _acmdln p __getmainargs @_initterm __setusermatherr _adjust_fdiv __p__commode __p__fmode __set_app_type _except_handler3 _controlfp SHGetValueA SHSetValueA SHLWAPI.dll InternetOpenUrlA InternetOpenA WININET.dll Netbios NETAPI32.dll . CloseHandle SetFileTime M CreateFileA WGetFileAttributesExA ?GetSystemDirectoryA ?GetVersionExA ?GetTickCount ;GetCurrentProcessId iGetLastError ?GetStartupInfoA KERNEL32.dll USER32.dll > CloseServiceHandle d CreateServiceA >StartServiceA ?OpenServiceA DeleteService ?OpenSCManagerA ADVAPI32.dll ?
虽说,这些,并不是能看得很明白~但却又好像看到些什么~~
唉,还需要学习~~~