DLL hijacking vulnerability caused by static links of Dynamic Link Libraries
Description using QQ program xgraphic32.dll
I don't want to say so much about it. Open the question directly.
I. Database
First, let's clarify the concept of the
Recently, someone asked in the Group how to use C language to compile DLL files (dynamic link library ).I didn't care too much about this problem or try any solution. After all, I used VB (now I use it.. Net). Creating a DLL is just a click to
Basic Ideas:
1. First, write a basic dynamic link library (DLL). I am talking about a DLL that is not a static interface. If you don't understand what I mean, it doesn't matter if I post a connection, learn more
Dynamic Link Library learning example:
1. New DLL
Open vb6--> file--> new project--> Select ActiveX dll--> OK
2, the default project, class renaming
Project renaming: Engineering--> Engineering 1 properties (this name corresponds to the project name in the body of the window)--> rename
To use Visual Studio. NET to create a small class library project, generate a strong name, and install the. dll file of the project in GAC, perform the following steps:
In Visual Studio. NET, create a new Visual C #. Net class library project
Symantec's official solution (it is recommended that you manually print the document and follow it)
Http://securityresponse.symantec.com/avcenter/venc/data/trojan.redfall.html
Technical details:
When Trojan. redfall runs, it performs the following
Copy files between VB and Windows Resource ManagerThe principle of copying or moving files through vbprogramming may be very clear to everyone. You can use Windows APIShfileoperation. You can also use the built-in functions of VB to perform
Situation
All the right keys are running, each disk will appear random 8-bit XXXXXXXX.exe and Autorun.inf files
Internet search virus, Trojan, etc will be virus turned off, can not open nod32 and other anti-virus
Software
Unable to view hidden files,
Strictly speaking, it is hard to say that it is an Internet Explorer error. However, based on experience, you may often make a hard job on Internet Explorer. For example, you may upgrade Internet Explorer 6 to Internet Explorer 7/Internet Explorer 8,
The following content is "original" + "reprint"
First, the solution and project folders contain relationships (C + + projects):
The VS solution and the individual project folders, as well as the configuration files that correspond to the individual
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.