本帖最后由 lifan88 于 2013-9-14 14:59 编辑
lifan88 发表于 2013-9-14 14:43
给楼主个RUNDLL32.EXE+IEXPLORER.EXE锁屏的
直接REGSVR32.EXE加载...
重测证明,直接复制他的命令行,只要原文件还在,直接锁屏,但MD突破锁屏...
2013-9-14 14:45:45 创建新进程 允许
进程: d:\windows\system32\cmd.exe
目标: d:\windows\system32\rundll32.exe
命令行: D:\WINDOWS\system32\rundll32.exe D:\DOCUME~1\ALLUSE~1\APPLIC~1\4jeelo.dat,FG07
规则: [应用程序]d:\windows\system32\cmd.exe
2013-9-14 14:45:49 读文件 (3) 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\4jeelo.dat
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:45:52 加载动态链接库 允许
进程: d:\windows\system32\rundll32.exe
目标: d:\documents and settings\all users\application data\4jeelo.dat
规则: [应用程序]d:\windows\system32\rundll32.exe
2013-9-14 14:45:59 读文件 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:03 读文件 (5) 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\rundll32.exe
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:07 创建新进程 允许
进程: d:\windows\system32\rundll32.exe
目标: d:\documents and settings\all users\application data\rundll32.exe
命令行: D:\DOCUME~1\ALLUSE~1\APPLIC~1\rundll32.exe D:\DOCUME~1\ALLUSE~1\APPLIC~1\4jeelo.dat,FG00
规则: [应用程序]d:\windows\system32\rundll32.exe
2013-9-14 14:46:07 读文件 允许
进程: d:\documents and settings\all users\application data\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\4jeelo.dat
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:08 读文件 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:09 读文件 允许
进程: d:\documents and settings\all users\application data\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\4jeelo.dat
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:09 读文件 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:10 读文件 允许
进程: d:\documents and settings\all users\application data\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\4jeelo.dat
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:10 读文件 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:10 加载动态链接库 允许
进程: d:\documents and settings\all users\application data\rundll32.exe
目标: d:\documents and settings\all users\application data\4jeelo.dat
规则: [应用程序]d:\documents and settings\all users\application data\rundll32.exe
2013-9-14 14:46:11 读文件 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:12 修改文件 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:15 读文件 (3) 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
在这步被锁,背景变成UK的XX局
2013-9-14 14:46:16 修改文件 允许
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:27 读文件 阻止并结束进程
进程: d:\documents and settings\all users\application data\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
2013-9-14 14:46:51 读文件 阻止并结束进程
进程: d:\windows\system32\rundll32.exe
目标: D:\Documents and Settings\All Users\Application Data\oleej4.pad
规则: [文件]d:\documents and settings\all users\application data
被结束后解锁,由此可见,他生成的*.pad是背景图包,是白文件...
还好锁屏被破....
原因不明................................我第一次测试,他是先把PAD读好了再锁,结果MD窗口被屏蔽,PAD背景包也因为触发询问规则,线程被暂停,所以背景没有出现...
第二次,他是没能锁住MD...MD破了锁屏,奇迹 |