Introduction - If you have any usage issues, please Google them yourself
PE file is windows (95/98/NT) is currently used in the executable file format. CIH virus is prevalent PE by changing the contents of the file, and keep the file size unchanged, and thus realize their functions. This procedure by analyzing the PE file format, the executable file to re-positioning table positioning, pointing users to the preparation of the DLL, and then return to normal call instruction pointer location. Adopted in the DLL system linking all levels realize the background of the intercepted password function.
Packet : 55593380hookdll.rar filelist
HookDll\decode\decode.001
HookDll\decode\decode.clw
HookDll\decode\decode.cpp
HookDll\decode\decode.dsp
HookDll\decode\decode.dsw
HookDll\decode\decode.h
HookDll\decode\decode.rc
HookDll\decode\decodeDlg.cpp
HookDll\decode\decodeDlg.h
HookDll\decode\Loadlib.cpp
HookDll\decode\loadlib.h
HookDll\decode\res\decode.ico
HookDll\decode\res\decode.rc2
HookDll\decode\resource.h
HookDll\decode\StdAfx.cpp
HookDll\decode\StdAfx.h
HookDll\fordebug\fordebug.001
HookDll\fordebug\fordebug.clw
HookDll\fordebug\fordebug.cpp
HookDll\fordebug\fordebug.dsp
HookDll\fordebug\fordebug.h
HookDll\fordebug\fordebug.rc
HookDll\fordebug\fordebugDlg.cpp
HookDll\fordebug\fordebugDlg.h
HookDll\fordebug\HookDll.dll
HookDll\fordebug\res\fordebug.ico
HookDll\fordebug\res\fordebug.rc2
HookDll\fordebug\resource.h
HookDll\fordebug\StdAfx.cpp
HookDll\fordebug\StdAfx.h
HookDll\HLP\CRACKUP.RTF
HookDll\HookDll.001
HookDll\HookDll.clw
HookDll\HookDll.cpp
HookDll\HookDll.def
HookDll\HookDll.dll
HookDll\HookDll.dsp
HookDll\HookDll.dsw
HookDll\HookDll.h
HookDll\HookDll.ncb
HookDll\HookDll.opt
HookDll\HookDll.plg
HookDll\HookDll.rc
HookDll\res\HookDll.rc2
HookDll\Resource.h
HookDll\StdAfx.cpp
HookDll\StdAfx.h
HookDll\decode\res
HookDll\fordebug\res
HookDll\decode
HookDll\fordebug
HookDll\HLP
HookDll\Release
HookDll\res
HookDll