qq尾巴原理分析及其防御,qq尾巴原理分析及其防御1.5万字 50页包括开题报告和任务书,程序清单摘要随着internet的发展,信息交流的需求越来越大,网络聊天工具应运而生。qq作为一种网络聊天工具,以其功能强大,使用方便,界面友好赢得了众多用户的喜爱。随着用户的增多,业务的扩展,qq也成为众多病毒的目标,其中qq尾巴病毒以其欺骗性、隐蔽性、...
原文档由会员 usactu 发布
1.5万字 50页
摘 要
The Principle and Defense of the "QQ tail" Virus
With the development of the Internet and the growing demand of the information exchange,chatting tools in the network have emerged.QQ has won many users' love as a network chatting tool with the powerful functions,convinience and the friendly interface.With the increase in users and business expansion, QQ has become the target of many viruses, QQ tail virus which has many features such as being deceptive, hidden and harmful,has brought huge losses to many QQ users .
Windows hook is the monitor point of windows news mechanism, which can be used to intercept and seize the information flow in system. Many viruses have taken advantage of this characteristic of Windows hook in the progamming. Windows system is based on event-driven mechanism, and all of this is completed through the information transmission. Hook is a very important system interface in windows system, which can be used effectively to intercept and process information sent to other application programme. Thus, we can install different types of Hook to monitor the events in the system by understanding the meaning of windows messages, so as to achieve the corresponding functions, such as intercepting keyboard and mouse input, capturing characters from Screen, logging monitoring ,cutting screenshots, etc.
This text takes "QQ tail" virus for example and has a detailed analysis of the use of the windows hook technology in the virus programme ,and prepares the simulation virus code program on the basis of the features of the virus; finally ,it ends up with methods to prevent this type of virus.
Keywords : QQ tail ,Windows hook, computer virus
目 录
1 绪论 1
1.1课题背景及来源 1
1.2课题研究的意义 1
1.3论文结构 1
2 QQ尾巴病毒 3
2.1病毒简介 3
2.1.1 病毒的生命周期 3
2.1.2 病毒特征 4
2.1.3 计算机病毒的传播途径 4
2.2 QQ尾巴病毒 5
2.2.1 病毒原理 5
3 钩子技术 6
3.1钩子的概念 6
3.2钩子类型 6
3.3钩子链 10
3.4钩子的安装与使用 10
3.5钩子的实现 11
4钩子在QQ尾巴中的应用 14
4.1利用钩子实现QQ尾巴 14
4.1.1 粘贴尾巴 14
4.1.2 监视与捕获 15
4.1.3 下钩与取钩 16
5 QQ尾巴防治 18
5.1 常见方法 18
5.1.1 IE方法 18
5.1.2 工具方法 18
5.1.3 一般方法 18
5.2 编程方法清除尾巴 18
总 结 27
致 谢 28
参考文献 29
[1] 林海.计算机网络安全[M].北京:高等教育出版社,2001.
[2] 刘涛,张连霞.怎样判断计算机病毒.内蒙古气象内蒙古:内蒙古出版,2001.
[3] 黄传河.网络安全[M].武汉:武汉大学出版社,2004.
[4] 斯泽 著,段新海 译.计算机病毒防范艺术[M].北京:机械工业出版社,2007.
[5] 马安光.病毒问题.程序员,2004,84(4).
[6] 王大印 .Windows安全漏洞与黑客防范[M].北京:电子工业出版社,2005.
unit Unit1;
Windows, Messages, SysUtils, Forms, shellapi,
winsock, Controls, Classes, StdCtrls, ExtCtrls,DateUtils,inifiles;
TForm1 = class(TForm)
1.5万字 50页
摘 要
The Principle and Defense of the "QQ tail" Virus
With the development of the Internet and the growing demand of the information exchange,chatting tools in the network have emerged.QQ has won many users' love as a network chatting tool with the powerful functions,convinience and the friendly interface.With the increase in users and business expansion, QQ has become the target of many viruses, QQ tail virus which has many features such as being deceptive, hidden and harmful,has brought huge losses to many QQ users .
Windows hook is the monitor point of windows news mechanism, which can be used to intercept and seize the information flow in system. Many viruses have taken advantage of this characteristic of Windows hook in the progamming. Windows system is based on event-driven mechanism, and all of this is completed through the information transmission. Hook is a very important system interface in windows system, which can be used effectively to intercept and process information sent to other application programme. Thus, we can install different types of Hook to monitor the events in the system by understanding the meaning of windows messages, so as to achieve the corresponding functions, such as intercepting keyboard and mouse input, capturing characters from Screen, logging monitoring ,cutting screenshots, etc.
This text takes "QQ tail" virus for example and has a detailed analysis of the use of the windows hook technology in the virus programme ,and prepares the simulation virus code program on the basis of the features of the virus; finally ,it ends up with methods to prevent this type of virus.
Keywords : QQ tail ,Windows hook, computer virus
目 录
1 绪论 1
1.1课题背景及来源 1
1.2课题研究的意义 1
1.3论文结构 1
2 QQ尾巴病毒 3
2.1病毒简介 3
2.1.1 病毒的生命周期 3
2.1.2 病毒特征 4
2.1.3 计算机病毒的传播途径 4
2.2 QQ尾巴病毒 5
2.2.1 病毒原理 5
3 钩子技术 6
3.1钩子的概念 6
3.2钩子类型 6
3.3钩子链 10
3.4钩子的安装与使用 10
3.5钩子的实现 11
4钩子在QQ尾巴中的应用 14
4.1利用钩子实现QQ尾巴 14
4.1.1 粘贴尾巴 14
4.1.2 监视与捕获 15
4.1.3 下钩与取钩 16
5 QQ尾巴防治 18
5.1 常见方法 18
5.1.1 IE方法 18
5.1.2 工具方法 18
5.1.3 一般方法 18
5.2 编程方法清除尾巴 18
总 结 27
致 谢 28
参考文献 29
[1] 林海.计算机网络安全[M].北京:高等教育出版社,2001.
[2] 刘涛,张连霞.怎样判断计算机病毒.内蒙古气象内蒙古:内蒙古出版,2001.
[3] 黄传河.网络安全[M].武汉:武汉大学出版社,2004.
[4] 斯泽 著,段新海 译.计算机病毒防范艺术[M].北京:机械工业出版社,2007.
[5] 马安光.病毒问题.程序员,2004,84(4).
[6] 王大印 .Windows安全漏洞与黑客防范[M].北京:电子工业出版社,2005.
unit Unit1;
Windows, Messages, SysUtils, Forms, shellapi,
winsock, Controls, Classes, StdCtrls, ExtCtrls,DateUtils,inifiles;
TForm1 = class(TForm)