計算機病毒原理與防范-復習總結


結構

Screen Shot 2018-06-26 at 16.30.25

病毒基本

病毒基本能力
Screen Shot 2018-06-27 at 10.25.28
Screen Shot 2018-06-27 at 10.25.44
Screen Shot 2018-06-27 at 10.35.33
Screen Shot 2018-06-27 at 10.36.59

Screen Shot 2018-06-27 at 10.44.25

文件系統

磁盤原理

Screen Shot 2018-06-27 at 11.07.37

Screen Shot 2018-06-27 at 11.07.51
Screen Shot 2018-06-27 at 11.08.07

FAT12

DOS時代,主要用於軟盤
Screen Shot 2018-06-27 at 11.09.13
Screen Shot 2018-06-27 at 14.04.14
Screen Shot 2018-06-27 at 14.04.22

55aa結束標志
Screen Shot 2018-06-27 at 14.06.36
Screen Shot 2018-06-27 at 14.06.57

文件定位

Screen Shot 2018-06-27 at 14.09.57
Screen Shot 2018-06-27 at 14.10.09
Screen Shot 2018-06-27 at 14.11.18
Screen Shot 2018-06-27 at 14.18.28

Screen Shot 2018-06-27 at 14.19.47
Screen Shot 2018-06-27 at 14.20.36
Screen Shot 2018-06-27 at 14.21.06
Screen Shot 2018-06-27 at 14.21.54
Screen Shot 2018-06-27 at 14.22.55Screen Shot 2018-06-27 at 14.41.30

Screen Shot 2018-06-27 at 14.40.47
Screen Shot 2018-06-27 at 14.41.59
Screen Shot 2018-06-27 at 14.42.40
Screen Shot 2018-06-27 at 14.42.58

文件刪除與恢復


Screen Shot 2018-06-27 at 14.44.39
Screen Shot 2018-06-27 at 14.46.13
Screen Shot 2018-06-27 at 14.46.45

文件創建與分配

Screen Shot 2018-06-27 at 14.47.08

FAT16

Screen Shot 2018-06-27 at 14.47.54

FAT32

Screen Shot 2018-06-27 at 14.48.19
Screen Shot 2018-06-27 at 14.49.07

FAT32引導記錄



Screen Shot 2018-06-27 at 14.50.08
Screen Shot 2018-06-27 at 14.51.13

Screen Shot 2018-06-27 at 14.52.59

Screen Shot 2018-06-27 at 14.54.39
Screen Shot 2018-06-27 at 14.55.32

硬盤數據結構

分區

Screen Shot 2018-06-27 at 14.56.21
Screen Shot 2018-06-27 at 14.56.38
Screen Shot 2018-06-27 at 14.58.03
Screen Shot 2018-06-27 at 14.58.47
Screen Shot 2018-06-27 at 15.02.28

硬盤啟動

Screen Shot 2018-06-27 at 15.03.17
Screen Shot 2018-06-27 at 15.03.43

Screen Shot 2018-06-27 at 15.04.18
同時要驗證55AA結束標志

DOS病毒

Screen Shot 2018-06-28 at 10.14.31

Screen Shot 2018-06-28 at 10.14.36

病毒程序在正常程序中頭插入或尾插入

Screen Shot 2018-06-28 at 15.36.13
Screen Shot 2018-06-28 at 18.36.41
Screen Shot 2018-07-03 at 21.07.42

簡答題:

病毒定義

Screen Shot 2018-07-01 at 16.29.19
Screen Shot 2018-07-01 at 16.29.25
Screen Shot 2018-07-04 at 08.48.22

PE格式
Screen Shot 2018-07-03 at 21.37.11

Screen Shot 2018-07-03 at 21.37.23

FAT32/12

Screen Shot 2018-06-27 at 14.49.07

Screen Shot 2018-06-27 at 14.51.13

Screen Shot 2018-06-27 at 14.55.32

文件名長度 根目錄區 32的引導區有保留區

病毒防范

Screen Shot 2018-07-03 at 21.53.36
Screen Shot 2018-07-03 at 21.53.43

Screen Shot 2018-07-03 at 21.53.54
Screen Shot 2018-07-03 at 21.54.36

虛擬機

Screen Shot 2018-07-03 at 21.54.51

蠕蟲

Screen Shot 2018-07-03 at 21.57.43
Screen Shot 2018-07-03 at 21.57.32

木馬

Screen Shot 2018-07-03 at 21.57.36

RVA地址轉換

入口點RVA - 節表 - 查找文件起始位置

可造頭 - 入口點RVA - 從節表中找到代碼節的文件偏移

計算節頭到入口點的差值+文件偏移 -》 入口點偏移量

病毒掃描 - 特征碼技術
病毒監控 - 程序行為定義 int13h
病毒防范 - 查殺

保護模式-實模式

Screen Shot 2018-07-03 at 22.04.38


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM