首页| JavaScript| HTML/CSS| Matlab| PHP| Python| Java| C/C++/VC++| C#| ASP| 其他|
购买积分 购买会员 激活码充值

您现在的位置是:虫虫源码 > 其他 > 镂空工艺

镂空工艺

  • 资源大小:38.63 kB
  • 上传时间:2021-06-30
  • 下载次数:0次
  • 浏览次数:0次
  • 资源积分:1积分
  • 标      签: 工艺

资 源 简 介

Process hollowing is yet another tool in the kit of those who seek to hide the presence of a process. The idea is rather straight forward: a bootstrap application creates a seemingly innocent process in a suspended state. The legitimate image is then unmapped and replaced with the image that is to be hidden. If the preferred image base of the new image does not match that of the old image, the new image must be rebased. Once the new image is loaded in memory the EAX register of the suspended thread is set to the entry point. The process is then resumed and the entry point of the new image is executed.

文 件 列 表

ProcessHollowing.exe
src
HelloWorld
ProcessHollowing.sln
ProcessHollowing
HelloWorld
HelloWorld.cpp
HelloWorld.vcproj
ReadMe.txt
stdafx.cpp
stdafx.h
targetver.h
HelloWorld.exe
VIP VIP
0.196903s