样本使用FindResourceA( )查找资源,类型是"XIA",名称2058,在MSDN里面怎么也找不到类型是"XIA"的资源,后来使用Resource Hacker打开样本有如下信息:
还真有类型"XIA"(资源前两个字节是PK,ZIP压缩文件)
调用完FindResourceA( )还会有如下的一系列调用:
hMoule=FindResourceA( NULL, 2058, "XIA")
SizeofResource( NULL, hMoule ) //Returns the size, in bytes, of the specified resource.
handle=LoadResource( NULL, hMoule) //Returns a handle to be used to obtain a pointer
to the first byte of the resource in memory.
LockResource( handle ) // the return value is a pointer to the first byte of the resource.