Dev tools: Visual C++
File size: 10 KB
Update: 2007-04-28
Downloads: 374
Describe:
PE File infection : an example, used to demonstrate the windows PE format injected other code. This example is a document open cmd.exe. Of course, the other can read the code, or even Trojan.
File list(time 2003052315~2009021203)(Click to check if it's the file you need, and recomment it at the bottom):
check_data.cpp head.h mAx.cpp pefile.cpp pefile.dsp
pefile.dsw
pefile.ncb
pefile.opt
pefile.plg
[
load.rar] - Modify the import table loaded dll' s complete source code, by this code, you can load any dll
files you need to insert
[
shellcode-PE.rar] - PE shellcode
[
Inject.rar] - DLL to achieve with a three jump into the explorer method.
[
pelib.zip] - operation of a document PE class for understanding the format of PE help
[
PEfileformat.Zip] - PE document windows (9598NT) of the executable
file format. Popular CIH virus is through changes in PE content of the document, and to maintain the si
[
pe_dll_backdoor.rar] - Exe
file to run through the infected DLL code, VC++ Development, writing Trojan friends can refer to the following
[
documentsbundledwiththesourcecode-authorXu] - documents bundled with the source code-author Xu Jing Zhou documents bundled with the source code-author Xu Jing Zhou
[
MyOzone.zip] - Take the initiative to drive the ozone layer defense system source code! Layer active defense system-driven source code!
[
Hook_Windows_API.rar] - This article is concerned with the OS Windows API function linked to the method. All the examples are based on the NT version of Windows NT 4.0 and ab
[
bambam004_source.rar] - former EEC core members of the Organization of writing new procedures PE shell of C source code. Right Dos Stud also of encryption, very classic.
Functions/Classes:
WinExec CreateFile CreateFileMapping MapViewOfFile LoadLibrary GetProcAddress GetFileSize FlushViewOfFile UnmapViewOfFile CloseHandle SetFilePointer SetEndOfFile