Z°T¹q¸£
¡u¸Ó°O¾ÐÅ餣¯à¬°read©Îwritten¡v°ÝÃD±´°Q
¨Ï¥ÎWindows¾Þ§@¨t²Îªº¤H¦³®É·|¹J¨ì³o¼Ëªº¿ù»~«H®§¡G¡u0X????????«ü¥O¤Þ¥Îªº0x00000000°O¾ÐÅé¡A¸Ó°O¾ÐÅ餣¯àwritten¡v¡AµM«áÀ³¥Îµ{¦¡³QÃö³¬¡C
¦pªG¥h½Ð±Ð¤@¨Ç¡u°ª¤â¡v¡A±o¨ìªº¦^µª©¹©¹¬O¡uWindows´N¬O³o¼Ë¤£Ã©w¡v¤§Ãþªº¸q¼«©M¤£®h¡C¨ä¹ê¡A³oÓ¿ù»~¨Ã¤£¤@©w¬OWindows¤£Ã©w³y¦¨ªº¡C¥»¤å´N¨Ó²³æ¤ÀªR³oºØ¿ù»~ªº¤@¯ëì¦]¡C
¦pªG¨t²Î¸g±`¦³©Ò´£¨ìªº¿ù»~´£¥Ü¡A¤U±ªº«Øij¥i¯à·|¦³»¡©ú ¡G
1.À˵ø¨t²Î¤¤¬O§_¦³¤ì°¨©Î¯f¬r¡C³oÃþµ{§Ç¬°¤F±±¨î¨t²Î©¹©¹¤£t³d¥ô¦aקï¨t²Î¡A±q¦Ó¾ÉP¾Þ§@¨t²Î²§±`¡C¥±`À³¥[±j«H®§¦w¥þ·NÃÑ¡A¹ï¨Ó·½¤£©úªº¥i°õ¦æµ{§Çµ´¤£¦n©_¡C
2.§ó·s¾Þ§@¨t²Î¡AÅý¾Þ§@¨t²Îªº¦w¸Ëµ{§Ç«·s«þ¨©¥¿½Tª©¥»ªº¨t²ÎÀɮסB×¥¿¨t²Î°Ñ¼Æ¡C¦³®ÉÔ¾Þ§@¨t²Î¥»¨¤]·|¦³BUG¡Anª`·N¦w¸Ë©x¤èµo¦æªºª@¯Åµ{§Ç¡C
3.¸Õ¥Î·sª©¥»ªºÀ³¥Îµ{¦¡¡C
Mode:±NµêÀÀ°O¾ÐÅéºM´«
µª®×:¥Ø«e¬°¤î¬OªÖ©wªº¡A¤]´N¬O¦p¦b¤U¦¸§N¤Ñ¨ì¨Ó®É¥ç¨S¦Aµo¥Í¡A´N¥Nªí³o¬O¥D¦]°l¥[:¦pªG§A¥Î Ghost «ì´_ OS «á«Øij§R°£WINDOWS¢@PREFETCH¥Ø¿ý¤U©Ò¦³*.PF¤å¥ó,¦]¬°»ÝÅýwindows«·s¦¬¶°µ{¦¡ªºª«²z¦ì§}¦³¨ÇÀ³¥Îµ{¦¡¿ù»~: "0x7cd64998" «ü¥O°Ñ¦Òªº "0x14c96730" °O¾ÐÅé¡C¸Ó°O¾ÐÅ餣¯à¬° "read"±À½×¬O¦¹ì¦]
·½¥Ñ:
Win XPªº¡u¹wŪ¨ú¡v§Þ³N
³oºØ³Ì¨Î¤Æ§Þ³N¤]³Q¥Î¨ì¤FÀ³¥Î³nÅé¤W¡A¨t²Î¹ï¨C¤@ÓÀ³¥Î³nÅ骺«e´X¦¸±Ò°Ê±¡ªp¶i¦æ¤ÀªR¡AµM«á·s¼W¤@Ó´yz®M¥Î»Ý¨DªºµêÀÀ¡u°O¾ÐÅé¬M¹³¡v¡A¨Ã§â³o¨Ç«H®§Àx¦s¨ìWINDOWS\PREFETCH¸ê®Æ§¨¡C¤@¥¹«Ø¥ß¤F¬M¹³¡AÀ³¥Î³nÅ骺¸Ë¤J³t«×¤j¤j´£°ª¡CXPªº¹wŪ¨ú¸ê®ÆÀx¦s¤F³Ìªñ8¦¸¨t²Î±Ò°Ê©ÎÀ³¥Î³nÅé±Ò°Êªº«H®§¡C
«á±Ô:¥Ø«e¦¹¤èªk¥ç¬O¿W¨Bºô¸ôªº(¨ä½X¦Û¤v°w¹ï¦¹°ÝÃD¬d¤F³\¤[)¡A¤]¬O±`¨£°ÝÃD¡A쥻´X¥G¨C¤ÑºÎ«eÃö³¬³nÅé®É¤@¨Çµ{¦¡³£·|µo¥Í...read...²{¦b´N¨Sµo¥Í¤F
¥t¥~¡A¤]¦³¤@»¡¬O³oºØ¸Ñ¨M¤èªk¡G
«·s¦VWindowsµù¥U©Ò¦³ªºdll
¶}©l >> °õ¦æ >> ¿é¤Jcmd >> «ö¡u½T©w¡v¡A¦bDOSµøµ¡¤U¿é¤J
for %1 in (%windir%/system32/*.dll) do regsvr32.exe /s %1
±µ¤U¨Ó·|¬Ý¨ìµøµ¡µe±¤£Â_¦a±²°Ê¡C¤j¬ùµ¥«Ý´X¤ÀÄÁªº®É¶¡§Y¥iµù¥U§¹¦¨¡C
¸g¹L¹ê»Ú´ú¸Õ¡A²Ä¤GºØ¤è¦¡¦ü¥G¦³®Ä¡C
¥»¸ê®Æ¨Ó·½ - http://geteway.game.tw/phpbb/trackback.php?e=35 ¥H¤Î ¸ê¦w½×¾Â ( http://forum.icst.org.tw/ )
ª©Åv«Å§i:¥»ºô¶©Ò´£¨Ñ¤§¸ê°T,ª©Åv¬ÒÄݸê®Æ¨Ó·½ºô¯¸©ÎÓ¤H,¦p¦³¬ÛÃöºÃ°Ý,½Ð»P§Ú̳sµ¸