created, the BP shell32! ShellexecuteaThat means that the contents of the HLP file have been executed at this time, and then locate winhlp32! Execute down View parametersAccording to Ida's analysis; The int __stdcall Execute (LPCSTR lpString2) found parameters lpString2 the contents of the HLP file "EF (" C:\\windows\\calc.exe "," ', 1) ".Reposition the upper function Configmacroshde use IDA for disassemblyIt can be seen that the function of Configmacroshde is to iterate through the contents of
Settings\temp\wls0.dll
C:\Documents and Settings\ your username \local Settings\temp\wms0.dll
C:\Documents and Settings\ your username \local Settings\temp\wos0.dll
C:\Documents and Settings\ your username \local Settings\temp\ztso.exe
C:\Documents and Settings\ your username \local Settings\temp\ztso0.dll
C:\Program files\internet Explorer\rundll32.exe
C:\Program files\internet Explorer\smss. Exe
C:\WINDO
Settings \ your USERNAME \ Local Settings \ temp \ wls0.dll
C: \ Documents and Settings \ your USERNAME \ Local Settings \ temp \ wms0.dll
C: \ Documents and Settings \ your USERNAME \ Local Settings \ temp \ wos0.dll
C: \ Documents and Settings \ your USERNAME \ Local Settings \ temp \ ztso.exe
C: \ Documents and Settings \ your USERNAME \ Local Settings \ temp \ ztso0.dll
C: \ Program Files \ Internet Explorer \ rundll32.exe
C: \ Program Files \ In
C # Use ilmerge to compress all referenced DLL and exe files into an EXE file
Address: http://www.cnblogs.com/hongfei/archive/2013/03/14/2958627.html#2634561
Ilmerge:Http://www.microsoft.com/downloads/details.aspx? Familyid = 22914587-b4ad-4eae-87cf-b14ae6a939b0 displaylang = en
Install the SDK directly by default after the download. After installation, there will be three files.
run the Prog
What is the Rundll32.exe process?
Rundll32.exe is used to run DLL files in memory and they are used in applications. This program is very important for the normal operation of your system. Note: Rundl132.exe and rundll32.exe. But Rundl132.exe is a W32.Miroot.Worm virus. The
The eye of this article: note that these several filename ravfy.exe,ravwl. Exe,msdebug.dll is quite confusing.
First, questions: http://zhidao.baidu.com/question/23973092.html
Second, analysis:
1. Turn off System Restore before antivirus (Win2000 system can be ignored): Right button My Computer, properties, System Restore, turn off System Restore tick on all drives.
Clear IE Temporary files: Open IE point tool-->internet option: Internet temporary f
/// /// Start the CAD of the Local Machine and browse the DWG diagram in the CAD. /// /// Cad.exe location /// Full path of dwgfile Public Void Startcad2004 ( String Path, String Dwgfile) {PROCESS p = New Process (); p. startinfo. filename = Path; // Start CAD of the Local Machine P. startinfo. Arguments = Dwgfile ;//Set the DWG file to be opened by CADP. Start ();////Start CAD of the Local Machine} /// /// Obtain the CAD pa
: 2006.5.30Updated on: 2006.6.1Associated Virus:Spread by QQ tail and malicious websitesTechnical analysis:1. Create a file after running:% Windows % \ rundl132.exe\ VDll. dll (current directory)2. Create a self-starting item:[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Windows]"Load" = "% Windows % \ rundl132.exe"32.16vdll.dllwill be
EndurerOriginal
2Version
2006-09-131Version
A netizen's computer experienced a strange phenomenon. Double-click *. EXE to generate *~. Exe. if you double-click a.exe, A ~ is generated ~. EXE.
Four files are concurrently added: setup.exe and setup ~. EXE, frozen throne.exe, and frozen throne ~.
from the service list on the right, right-click the item, select "properties", and open the "login" page in the property box, select "allow desktop interaction" under "Local SYSTEM account" and click "OK. Restart the service.
2. Open the directory "C: \ WINDOWS \ Microsoft. net \ framework \ v1.1.4322 \ config "machine. in the config file, find the "processmodel" item. One of the original attributes of this item is username = "machine", change the
What file is Drwtsn32.exe?
Process file: DrWtsn32 or Drwtsn32.exe
Process name: Microsoft Dr Watson
Process Category: Application process
English Description: Drwtsn32.exe is a process belonging to Microsofts Dr. Watson program error Debug Utility. This utility can is important for technical support purposes and sh
specific derivation function of the DLL file to be executed before, [Arguments] is the specific parameter of the derivation function.
A brief talk on the function of Rundll32.exe
Windows9x friends must be familiar with the two files of Rundll32.exe and Rundll.exe, but since the functions of these two programs were originally limited to being used within Microsoft
The system time is modified to use the xibgptd.exe, netdde32.exe, and so on.
EndurerOriginal1Version
(Continued log)
O9-IE Toolbar extension button HKLM: Chinese Internet-{B012491E-8FA4-4851-AA9B-22E33784FBAD}-C:/program files/ocins/config.exeO9-ie tool menu extension item HKLM: Chinese Internet-{B012491E-8FA4-4851-AA9B-22E33784FBAD}-C:/program files/ocins/config.exe
O20-appinit_dlls: jzupli. dll
O23-service: aea6eaec (aea6eaec)-C:/Windows/system32/2d
file to be executed on the front, and [arguments] is the specific parameter of the extraction function.Role of rundll32.exe
Windows 9xis usually used to define rundll32.exeand rundll.exe files. However, since the functions of these two programs were originally used only within Microsoft, there may be few friends who really know how to use them. Well, if you still don't know, let me tell you.First, please m
Jar-to-exe and exe installation packages, including the java environment, jarjava
It is really difficult to start a name that can summarize all the content of this blog.
What a magic language Java is, it can be called a Learning application.
Java can be used to develop mobile PC Desktop Server Web Front-end programs
Java has developed well in the other three fields, but almost no one is using PC Desktop. W
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.