Introduction - If you have any usage issues, please Google them yourself
PE document windows (9598NT) of the executable file format. Popular CIH virus is through changes in PE content of the document, and to maintain the size of the same document, thus achieving its own functions. The procedures by analyzing PE file format, the executable files repositioning positioning table, prepared by the user at DLL, and then returned to normal indicators directive calling location. The DLL system by linking the background to achieve various levels of password function intercepted.
Packet : 605996pefile.zip filelist
Debug/
decode/
decode/decode.aps
decode/decode.clw
decode/decode.cpp
decode/decode.dsp
decode/decode.dsw
decode/decode.h
decode/decode.ncb
decode/decode.opt
decode/decode.plg
decode/decode.rc
decode/decodeDlg.cpp
decode/decodeDlg.h
decode/Loadlib.cpp
decode/loadlib.h
decode/ReadMe.txt
decode/res/
decode/resource.h
decode/res/decode.ico
decode/res/decode.rc2
decode/StdAfx.cpp
decode/StdAfx.h
fordebug/
fordebug/fordebug.aps
fordebug/fordebug.clw
fordebug/fordebug.cpp
fordebug/fordebug.dsp
fordebug/fordebug.h
fordebug/fordebug.plg
fordebug/fordebug.rc
fordebug/fordebugDlg.cpp
fordebug/fordebugDlg.h
fordebug/HookDll.dll
fordebug/ReadMe.txt
fordebug/res/
fordebug/resource.h
fordebug/res/fordebug.ico
fordebug/res/fordebug.rc2
fordebug/StdAfx.cpp
fordebug/StdAfx.h
HLP/
HLP/CRACKUP.RTF
HookDll.aps
HookDll.clw
HookDll.cpp
HookDll.def
HookDll.dll
HookDll.dsp
HookDll.dsw
HookDll.h
HookDll.ncb
HookDll.opt
HookDll.plg
HookDll.rc
ReadMe.txt
Release/
Release/HookDll.dll
res/
Resource.h
res/HookDll.rc2
StdAfx.cpp
StdAfx.h