主题:[转帖]探讨:VB利用StickyApp32.DLL使进程防杀
原文:
form:http://www.internals.com/utilities_main.htm
StickyApp32
StickyApp32 is a tiny visual basic application which is resistant to termination attempts from the Windows NT task manager. It does this by establishing a hook on the OpenProcess API and modifying the return value of this function. Complete source code is included !
问题:
如果运行它本身生成的EXE文件是可以做到进程防杀的(icesword除外),但如果我们再生成一个EXE文件就不行了?
发现:
原来的StickyApp32.exe文件比我们后来生成的exe文件要小的多。
希望各位帮忙分析原因!
说明:如果用瑞星等杀软的客户请先将文件监控关闭下,否则会报病毒!(StickyApp32.dll安全的)
form:http://www.internals.com/utilities_main.htm
StickyApp32
StickyApp32 is a tiny visual basic application which is resistant to termination attempts from the Windows NT task manager. It does this by establishing a hook on the OpenProcess API and modifying the return value of this function. Complete source code is included !
问题:
如果运行它本身生成的EXE文件是可以做到进程防杀的(icesword除外),但如果我们再生成一个EXE文件就不行了?
发现:
原来的StickyApp32.exe文件比我们后来生成的exe文件要小的多。
希望各位帮忙分析原因!
说明:如果用瑞星等杀软的客户请先将文件监控关闭下,否则会报病毒!(StickyApp32.dll安全的)