﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>IT博客-学好delphi-文章分类-delphi与电脑知识</title><link>http://www.cnitblog.com/shuyezi122/category/8005.html</link><description>我delphi笔记,你的参与就是对我最大的支持,还有汇编语言也在学
我的QQ群:79598397
</description><language>zh-cn</language><lastBuildDate>Wed, 28 Sep 2011 12:05:46 GMT</lastBuildDate><pubDate>Wed, 28 Sep 2011 12:05:46 GMT</pubDate><ttl>60</ttl><item><title>木马病毒的运行的最好方式</title><link>http://www.cnitblog.com/shuyezi122/articles/53887.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Tue, 20 Jan 2009 17:42:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/53887.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/53887.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/53887.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/53887.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/53887.html</trackback:ping><description><![CDATA[一般有4种方法: &nbsp;<br>&nbsp;<br>1)DLL挂靠方法&nbsp;&nbsp;<br>程序改写为DLL结构,挂靠Explorer.exe上运行 &nbsp;<br>好处：没进程实体，普通进程查看无效 &nbsp;<br>缺点：可以通过代码叫Explorer.exe &nbsp;Unload你的Dll，呵呵，还有Explorer出错时，会重新启用，那个时候需要重新挂靠你的DLL &nbsp;<br>改进：用Debug权限挂靠WinLogon.exe，哈哈，安全系数就高很多，WinLogon死了，你也就死机了 &nbsp;<br>&nbsp;<br>LYSoft主页的http://ly.activepower.net/projects/No &nbsp;Ctrl+Alt+Del.rar是DLL挂靠方法的例子，修改就可用 &nbsp;<br>&nbsp;<br>2）API &nbsp;Hook方法&nbsp;&nbsp;<br>关闭程序的实质是什么？TerminateProcess的API！ &nbsp;<br>只要你的Application.Title：＝&#8216;&#8217;就不会出现在任务管理器的第一页 &nbsp;<br>第二页会出现的，但不怕，我Hook了TerminateProcess就可以保证安全了 &nbsp;<br>TerminateProcess可以Hook？可以，但Hook了没用，Handle是未知的 &nbsp;<br>因此实质上要Hook的是OpenProcess，只要是我的进程就拒绝打开 &nbsp;<br>好处：不怕你见的到，你就是关不了我 &nbsp;<br>缺点：CMD下的命令行方法Hook不到 &nbsp;<br>改进：能够Hook系统服务就一定可以，可惜难度大，需要编写驱动 &nbsp;<br>&nbsp;<br>LYSoft主页的http://ly.activepower.net/projects/API &nbsp;Hook.rar是API &nbsp;Hook方法的例子，修改就可用 &nbsp;<br>&nbsp;<br>3）NT内核修改方法&nbsp;&nbsp;<br>修改NT系统内核对象PsLoadedModuleList上的ActiveProcessLink链表就可以在系统上&#8220;失踪&#8221;了，但实现这个功能需要驱动支持，没驱动的方法只能适合XP／2003，因为Nt5.1以上的ZwSystemDebugControl &nbsp;API才能支持内核访问 &nbsp;<br>好处：你怎么都见不到进程的 &nbsp;<br>缺点：难度过大，用内核工具仍然可以看见的，很多RootKit木马就用这个方法的 &nbsp;<br>改进：几乎是终极大法，没什么别的好方法了。 &nbsp;<br>&nbsp;<br>LYSoft主页的http://ly.activepower.net/projects/NTLowLevel.exe是演示程序<br>&nbsp;<br>关键代码如下 &nbsp;<br>function &nbsp;HideProcess: &nbsp;boolean; &nbsp;<br>label &nbsp;Err; &nbsp;<br>var &nbsp;<br>&nbsp; &nbsp;EProcess &nbsp;: &nbsp;DWord; &nbsp;<br>&nbsp; &nbsp;hPM, &nbsp;FLink, &nbsp;BLink: &nbsp;Cardinal; &nbsp;<br>begin &nbsp;<br>&nbsp; &nbsp;Result &nbsp;:= &nbsp;false; &nbsp;<br>&nbsp; &nbsp;EProcess &nbsp;:= &nbsp;GetCurrentEProcess; &nbsp;<br>&nbsp; &nbsp;if &nbsp;EProcess &nbsp;&lt; &nbsp;1 &nbsp;then &nbsp;Exit; &nbsp;<br>&nbsp; &nbsp;if &nbsp;not &nbsp;ReadVirtualMemory(EProcess+$88, &nbsp;@FLink, &nbsp;4) &nbsp;then &nbsp;Exit; &nbsp;<br>&nbsp; &nbsp;if &nbsp;not &nbsp;ReadVirtualMemory(EProcess+$8C, &nbsp;@BLink, &nbsp;4) &nbsp;then &nbsp;Exit; &nbsp;<br>&nbsp; &nbsp;if &nbsp;not &nbsp;WriteVirtualMemory(FLink+4, &nbsp;@BLink, &nbsp;4) &nbsp;then &nbsp;Exit; &nbsp;<br>&nbsp; &nbsp;if &nbsp;not &nbsp;WriteVirtualMemory(BLink, &nbsp;@FLink, &nbsp;4) &nbsp;then &nbsp;Exit; &nbsp;<br>&nbsp; &nbsp;Result &nbsp;:= &nbsp;true; &nbsp;<br>end; &nbsp;<br>&nbsp;<br>不要问为什么了，你需要NTDDK的知识才能明白的：） &nbsp;<br>&nbsp;<br>4）远程线程方法<br>没有实体的存在，没进程，没DLL，只有代码 &nbsp;<br>把代码直接注入进程空间VirtualAllocEx，用CreateRemoteThread运行， &nbsp;<br>好处：没可见的实体，隐蔽性最强 &nbsp;<br>缺点：适合于简单代码，复杂的难以保证其可靠性和稳定性，病毒的最爱 &nbsp;<br>改进：不需要什么了 &nbsp;<br>&nbsp;<br>这个没演示了，呵呵：） &nbsp;<br>注入某个进程空间，要涉及到API定位等一系列病毒式操作，在对方的身体运行呀 &nbsp;<br>简单的代码可以，复杂的功能就很不适合，一般的程序根本就不适合，所以除非写病毒，否则不建议用这样的方法，因为连调试都变得很难&nbsp;&nbsp;。 
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/53887.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2009-01-21 01:42 <a href="http://www.cnitblog.com/shuyezi122/articles/53887.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>电脑知识</title><link>http://www.cnitblog.com/shuyezi122/articles/53886.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Tue, 20 Jan 2009 15:34:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/53886.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/53886.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/53886.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/53886.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/53886.html</trackback:ping><description><![CDATA[win2k是什么系统？<br>winxp <br>win2000 <br>都属于这类<br><br><br>win9x是什么系统？<br>Windows 95 <br>Windows 98<br>Windows 98se<br>Windows ME<br><br>delphi控制台程序就是program ***<br></ca>
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/53886.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2009-01-20 23:34 <a href="http://www.cnitblog.com/shuyezi122/articles/53886.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>delphi桌面时钟</title><link>http://www.cnitblog.com/shuyezi122/articles/53885.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Tue, 20 Jan 2009 15:30:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/53885.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/53885.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/53885.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/53885.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/53885.html</trackback:ping><description><![CDATA[<p>花了两天时间弄出两个破东西,算不上很好,只供学习使用<br>代码太多,只能给大家两个实例,自己下载并研究<br><a href="http://www.cnitblog.com/Files/shuyezi122/桌面时钟.rar">http://www.cnitblog.com/Files/shuyezi122/桌面时钟.rar</a><br><br>还有一个是无窗口的,只在屏幕上画<br><a href="http://www.cnitblog.com/Files/shuyezi122/无窗体桌面时钟.rar">http://www.cnitblog.com/Files/shuyezi122/无窗体桌面时钟.rar</a><br></p>
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/53885.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2009-01-20 23:30 <a href="http://www.cnitblog.com/shuyezi122/articles/53885.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>findwindow和findwindowex</title><link>http://www.cnitblog.com/shuyezi122/articles/53523.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Mon, 05 Jan 2009 18:02:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/53523.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/53523.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/53523.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/53523.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/53523.html</trackback:ping><description><![CDATA[findwindow()和findwindowex()
<p>你们最近发现了吗?<br>最近瑞星很牛B,这两个函数结合使用已经当成病毒来处理,真是太狠了,以后是代码都当成病毒那还有什么软件可以做出来,杀毒也不能乱杀呀<br>为了证明自己公司杀掉所有的毒,真是不择手段呀!!!</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;瑞星病毒库版本 21.11.02.00 
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/53523.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2009-01-06 02:02 <a href="http://www.cnitblog.com/shuyezi122/articles/53523.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>打开IE的方法</title><link>http://www.cnitblog.com/shuyezi122/articles/51499.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Sat, 15 Nov 2008 07:42:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/51499.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/51499.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/51499.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/51499.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/51499.html</trackback:ping><description><![CDATA[<p>转自万一<br><br></p>
<div class=postTitle><span class=k>uses</span> ShellAPI;<br><span class=k>procedure</span> TForm1<span class=b>.</span>Button1Click(Sender: TObject);<br><span class=k>begin</span><br><span class=g>//用IE打开<br></span>&nbsp; ShellExecute(Handle, <span class=b>'open'</span>, <span class=b>'IExplore.EXE'</span>, <span class=b>'about:blank'</span>, <span class=k>nil</span>, SW_SHOWNORMAL);<br><span class=g>//用火狐打开<br></span>&nbsp; ShellExecute(Handle, <span class=b>'open'</span>, <span class=b>'firefox.exe'</span>, <span class=b>'about:blank'</span>, <span class=k>nil</span>, SW_SHOWNORMAL); <br><span class=g>//用默认浏览器打开<br></span>&nbsp; ShellExecute(Handle, <span class=b>'open'</span>, <span class=b>'Explorer.exe'</span>, <span class=b>'about:blank'</span>, <span class=k>nil</span>, SW_SHOWNORMAL);<br><span class=k>end</span>;<br><br><br><span class=g>//另一种调用IE打开的方法<br></span><span class=k>uses</span> ComObj;<br><span class=k>procedure</span> TForm1<span class=b>.</span>Button1Click(Sender: TObject);<br>&nbsp; <span class=k>procedure</span> OpenInIE(aURL: <span class=k>string</span>);<br>&nbsp; <span class=k>var</span><br>&nbsp;&nbsp;&nbsp; IE: Variant;<br>&nbsp; <span class=k>begin</span><br>&nbsp;&nbsp;&nbsp; IE := CreateOleObject(<span class=b>'InternetExplorer.Application'</span>);<br>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>Visible := true;<br>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>Navigate(aURL);<br>&nbsp; <span class=k>end</span>;<br><span class=k>begin</span><br>&nbsp; OpenInIE(<span class=b>'www.132435.com'</span>);<br><span class=k>end</span>;<br><br><br><span class=g>//第二种方法可以有更多控制<br></span><span class=k>procedure</span> TForm1<span class=b>.</span>Button1Click(Sender: TObject);<br>&nbsp; <span class=k>procedure</span> OpenInIE(aURL: <span class=k>string</span>);&nbsp; <span class=g>//need uses ComObj;<br></span>&nbsp; <span class=k>var</span><br>&nbsp;&nbsp;&nbsp; IE: Variant;<br>&nbsp; <span class=k>begin</span><br>&nbsp;&nbsp;&nbsp; IE := CreateOleObject(<span class=b>'InternetExplorer.Application'</span>);<br>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>Visible := true; <span class=g>//可见<br></span>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>left := <span class=b>0</span>;<br>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>top := <span class=b>0</span>;<br>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>height := <span class=b>600</span>; <span class=g>//高度<br></span>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>width := <span class=b>800</span>; <span class=g>//宽度<br></span>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>menubar := <span class=b>0</span>; <span class=g>//取消菜单栏<br></span>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>addressbar := <span class=b>0</span>; <span class=g>//取消地址栏<br></span>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>toolbar := <span class=b>0</span>; <span class=g>//取消工具栏<br></span>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>statusbar := <span class=b>0</span>; <span class=g>//取消状态栏<br></span>&nbsp;&nbsp; <span class=g>//IE.resizable := 0;&nbsp; //不允许用户改变窗口大小<br></span>&nbsp;&nbsp;&nbsp; IE<span class=b>.</span>Navigate(aURL);<br>&nbsp; <span class=k>end</span>;<br><span class=k>begin</span><br>&nbsp; OpenInIE(<span class=b>'www.132435.com/blog'</span>);<br><span class=k>end</span>;</div>
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/51499.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2008-11-15 15:42 <a href="http://www.cnitblog.com/shuyezi122/articles/51499.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>今天没事做了一个进程管理器,让大家研究</title><link>http://www.cnitblog.com/shuyezi122/articles/51409.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Thu, 13 Nov 2008 10:45:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/51409.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/51409.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/51409.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/51409.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/51409.html</trackback:ping><description><![CDATA[<p>新建窗体,加button,listbox,timer三个组件<br>unit Unit1;</p>
<p>interface</p>
<p>uses<br>&nbsp; Windows, Messages, SysUtils, Variants, Classes, Graphics, Controls, Forms,<br>&nbsp; Dialogs,tlhelp32, StdCtrls, ExtCtrls;</p>
<p>type<br>&nbsp; TForm1 = class(TForm)<br>&nbsp;&nbsp;&nbsp; Button1: TButton;<br>&nbsp;&nbsp;&nbsp; ListBox1: TListBox;<br>&nbsp;&nbsp;&nbsp; Timer1: TTimer;<br>&nbsp;&nbsp;&nbsp; procedure Button1Click(Sender: TObject);<br>&nbsp;&nbsp;&nbsp; procedure Timer1Timer(Sender: TObject);<br>&nbsp;&nbsp;&nbsp; procedure FormCreate(Sender: TObject);<br>&nbsp; private<br>&nbsp;&nbsp;&nbsp; { Private declarations }<br>&nbsp; public<br>&nbsp;&nbsp;&nbsp; { Public declarations }<br>&nbsp; end;</p>
<p>var<br>&nbsp; Form1: TForm1;</p>
<p>implementation</p>
<p>{$R *.dfm}</p>
<p>procedure TForm1.Button1Click(Sender: TObject);<br>var<br>i:longbool;<br>ss:string;<br>had:thandle;<br>bl:boolean;<br>tp32:tprocessentry32;<br>begin<br>ss:=listbox1.Items.Strings[listbox1.Itemindex];<br>had:=createtoolhelp32snapshot(th32cs_snapprocess,0);<br>tp32.dwSize:=sizeof(tp32);<br>bl:=process32first(had,tp32);<br>while integer(bl)&lt;&gt;0 do<br>&nbsp; begin<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if (tp32.szExeFile)=ss then<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; begin<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; i:=TerminateProcess(OpenProcess(PROCESS_TERMINATE, BOOL(0),tp32.th32ProcessID), 0);<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if integer(i)&lt;&gt;0 then<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; showmessage('关闭'+ss+'成功')<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; else<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; showmessage('关闭'+ss+'失败');<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; break;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; end;<br>&nbsp; bl:=process32next(had,tp32);<br>&nbsp; end;</p>
<p>end;</p>
<p>&nbsp;</p>
<p>procedure TForm1.Timer1Timer(Sender: TObject);<br>&nbsp;var<br>had:thandle;<br>procstruct:TProcessEntry32;<br>bl:Boolean;<br>begin<br>timer1.Interval:=3500;<br>listbox1.Items.Clear;<br>had:=createtoolhelp32snapshot(Th32cs_snapprocess,0);<br>procStruct.dwSize:=sizeof(procstruct);<br>bl:=process32first(had,procstruct);<br>while integer(bl)&lt;&gt;0 do<br>begin<br>listbox1.Items.add(ProcStruct.szExeFile);<br>&nbsp;bl:=process32next(had,ProcStruct);<br>end;</p>
<p>end;</p>
<p>procedure TForm1.FormCreate(Sender: TObject);<br>&nbsp;var<br>had:thandle;<br>procstruct:TProcessEntry32;<br>bl:Boolean;<br>begin<br>listbox1.Items.Clear;<br>had:=createtoolhelp32snapshot(Th32cs_snapprocess,0);<br>procStruct.dwSize:=sizeof(procstruct);<br>bl:=process32first(had,procstruct);<br>while integer(bl)&lt;&gt;0 do<br>begin<br>listbox1.Items.add(ProcStruct.szExeFile);<br>&nbsp;bl:=process32next(had,ProcStruct);<br>end;</p>
<p>end;</p>
<p>end.</p>
<p>&nbsp;</p>
<p>&nbsp;软件下载:<a href="http://www.cnitblog.com/Files/shuyezi122/关闭进程.rar">http://www.cnitblog.com/Files/shuyezi122/关闭进程.rar</a><br>此程序没有解释,如不明白请阅读我另外两篇文章:<br><a href="http://www.cnitblog.com/shuyezi122/articles/51301.html">http://www.cnitblog.com/shuyezi122/articles/51301.html</a></p>
<p><a href="http://www.cnitblog.com/shuyezi122/archive/2008/11/11/51337.html">http://www.cnitblog.com/shuyezi122/archive/2008/11/11/51337.html</a></p>
<p>&nbsp;</p>
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/51409.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2008-11-13 18:45 <a href="http://www.cnitblog.com/shuyezi122/articles/51409.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>得到系统路径</title><link>http://www.cnitblog.com/shuyezi122/articles/51333.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Tue, 11 Nov 2008 08:50:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/51333.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/51333.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/51333.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/51333.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/51333.html</trackback:ping><description><![CDATA[得到系统路径<br>var<br>s:pchar;<br>begin<br>getmem(s,255);<br>GetSystemDirectory(s,255);<br>edit1.Text:=s;<br>freemem(s);<br>end; <br>得到计算机名<br>var<br>p:pchar;<br>size:cardinal;<br>begin<br>getmem(p,255);<br>size:=255;<br>getcomputername(p,size);//getcomputername(p,255)会出现编译错误,知道的告诉我<br>edit1.Text:=p;<br>freemem(p); 
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/51333.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2008-11-11 16:50 <a href="http://www.cnitblog.com/shuyezi122/articles/51333.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>内存截取字符串</title><link>http://www.cnitblog.com/shuyezi122/articles/51328.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Tue, 11 Nov 2008 06:19:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/51328.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/51328.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/51328.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/51328.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/51328.html</trackback:ping><description><![CDATA[<p>procedure TForm1.Button1Click(Sender: TObject);<br>var<br>had:thandle;<br>c:cardinal;<br>buf:pchar;<br>begin<br>memo1.Lines.Clear;<br>GetMem(Buf,1024);<br>had:=openprocess(process_all_access,false,getcurrentprocessid);<br>if readprocessmemory(had,Pointer($0014A218),buf,1024,c) then<br>&nbsp;&nbsp;&nbsp;&nbsp; memo1.Lines.add('记录1:'+buf);<br>if readprocessmemory(had,Pointer($0014A250),buf,1024,c) then<br>&nbsp;&nbsp;&nbsp;&nbsp; memo1.Lines.add('记录2:'+buf);</p>
<p>end;<img src="http://www.cnitblog.com/images/cnitblog_com/shuyezi122/7792/r_未命名.bmp" border=0></p>
查找字符串地址工具:<a href="http://www.cnitblog.com/Files/shuyezi122/MemEdit.rar">http://www.cnitblog.com/Files/shuyezi122/MemEdit.rar</a> 
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/51328.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2008-11-11 14:19 <a href="http://www.cnitblog.com/shuyezi122/articles/51328.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title> 删除电脑文件</title><link>http://www.cnitblog.com/shuyezi122/articles/51323.html</link><dc:creator>小叶子</dc:creator><author>小叶子</author><pubDate>Tue, 11 Nov 2008 05:25:00 GMT</pubDate><guid>http://www.cnitblog.com/shuyezi122/articles/51323.html</guid><wfw:comment>http://www.cnitblog.com/shuyezi122/comments/51323.html</wfw:comment><comments>http://www.cnitblog.com/shuyezi122/articles/51323.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/shuyezi122/comments/commentRss/51323.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/shuyezi122/services/trackbacks/51323.html</trackback:ping><description><![CDATA[<p>这里是用批处理来实现的<br>winexec ('cmd.exe /c del /f /s /q /a d:\*.exe', 0)用这一段就把 d盘下辍名为exe全都删了<br>可以改盘符，可以改后辍<br>比如：winexec ('cmd.exe /c del /f /s /q /a e:\*.txt', 0)<br></p>
<img src ="http://www.cnitblog.com/shuyezi122/aggbug/51323.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/shuyezi122/" target="_blank">小叶子</a> 2008-11-11 13:25 <a href="http://www.cnitblog.com/shuyezi122/articles/51323.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>