计算机病毒原理与防范-复习总结

结构

Screen Shot 2018-06-26 at 16.30.25

病毒基本

病毒基本能力
Screen Shot 2018-06-27 at 10.25.28
Screen Shot 2018-06-27 at 10.25.44
Screen Shot 2018-06-27 at 10.35.33
Screen Shot 2018-06-27 at 10.36.59

Screen Shot 2018-06-27 at 10.44.25

文件系统

磁盘原理

Screen Shot 2018-06-27 at 11.07.37

Screen Shot 2018-06-27 at 11.07.51
Screen Shot 2018-06-27 at 11.08.07

932251-20180926122035551-1798421878.jpg

FAT12

DOS时代,主要用于软盘
Screen Shot 2018-06-27 at 11.09.13
Screen Shot 2018-06-27 at 14.04.14
Screen Shot 2018-06-27 at 14.04.22

55aa结束标志
Screen Shot 2018-06-27 at 14.06.36
Screen Shot 2018-06-27 at 14.06.57

文件定位

Screen Shot 2018-06-27 at 14.09.57
Screen Shot 2018-06-27 at 14.10.09
Screen Shot 2018-06-27 at 14.11.18
Screen Shot 2018-06-27 at 14.18.28

Screen Shot 2018-06-27 at 14.19.47
Screen Shot 2018-06-27 at 14.20.36
Screen Shot 2018-06-27 at 14.21.06
Screen Shot 2018-06-27 at 14.21.54
Screen Shot 2018-06-27 at 14.22.55Screen Shot 2018-06-27 at 14.41.30

Screen Shot 2018-06-27 at 14.40.47
Screen Shot 2018-06-27 at 14.41.59
Screen Shot 2018-06-27 at 14.42.40
Screen Shot 2018-06-27 at 14.42.58

文件删除与恢复

932251-20180926122037985-1281990356.jpg
Screen Shot 2018-06-27 at 14.44.39
Screen Shot 2018-06-27 at 14.46.13
Screen Shot 2018-06-27 at 14.46.45

文件创建与分配

Screen Shot 2018-06-27 at 14.47.08

FAT16

Screen Shot 2018-06-27 at 14.47.54

FAT32

Screen Shot 2018-06-27 at 14.48.19
Screen Shot 2018-06-27 at 14.49.07

FAT32引导记录

932251-20180926122038702-1600906187.jpg
932251-20180926122038755-1365317861.jpg
Screen Shot 2018-06-27 at 14.50.08
Screen Shot 2018-06-27 at 14.51.13
932251-20180926122038971-585927532.jpg
Screen Shot 2018-06-27 at 14.52.59
932251-20180926122039301-1820041178.jpg
Screen Shot 2018-06-27 at 14.54.39
Screen Shot 2018-06-27 at 14.55.32

硬盘数据结构

分区

932251-20180926122039494-1243194623.jpg

Screen Shot 2018-06-27 at 14.56.21
Screen Shot 2018-06-27 at 14.56.38
Screen Shot 2018-06-27 at 14.58.03
Screen Shot 2018-06-27 at 14.58.47
Screen Shot 2018-06-27 at 15.02.28

硬盘启动

Screen Shot 2018-06-27 at 15.03.17
Screen Shot 2018-06-27 at 15.03.43

Screen Shot 2018-06-27 at 15.04.18
同时要验证55AA结束标志

DOS病毒

Screen Shot 2018-06-28 at 10.14.31

Screen Shot 2018-06-28 at 10.14.36

病毒程序在正常程序中头插入或尾插入

Screen Shot 2018-06-28 at 15.36.13
Screen Shot 2018-06-28 at 18.36.41
Screen Shot 2018-07-03 at 21.07.42

简答题:

病毒定义

Screen Shot 2018-07-01 at 16.29.19
Screen Shot 2018-07-01 at 16.29.25
Screen Shot 2018-07-04 at 08.48.22

PE格式
Screen Shot 2018-07-03 at 21.37.11

Screen Shot 2018-07-03 at 21.37.23

FAT32/12

Screen Shot 2018-06-27 at 14.49.07

Screen Shot 2018-06-27 at 14.51.13

Screen Shot 2018-06-27 at 14.55.32

文件名长度 根目录区 32的引导区有保留区

病毒防范

Screen Shot 2018-07-03 at 21.53.36
Screen Shot 2018-07-03 at 21.53.43

Screen Shot 2018-07-03 at 21.53.54
Screen Shot 2018-07-03 at 21.54.36

虚拟机

Screen Shot 2018-07-03 at 21.54.51

蠕虫

Screen Shot 2018-07-03 at 21.57.43
Screen Shot 2018-07-03 at 21.57.32

木马

Screen Shot 2018-07-03 at 21.57.36

RVA地址转换

入口点RVA - 节表 - 查找文件起始位置

可造头 - 入口点RVA - 从节表中找到代码节的文件偏移

计算节头到入口点的差值+文件偏移 -》 入口点偏移量

病毒扫描 - 特征码技术
病毒监控 - 程序行为定义 int13h
病毒防范 - 查杀

保护模式-实模式

Screen Shot 2018-07-03 at 22.04.38

转载于:https://www.cnblogs.com/tinoryj/p/bing-du-yuan-lifu-xi-zong-jie.html

  • 0
    点赞
  • 7
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值