RUNDLL32.EXE
Rundll32.exeæ¯ä»ä¹ï¼é¡¾åææï¼âæ§è¡32ä½çDLLæ件âãå®çä½ç¨æ¯æ§è¡DLLæ件ä¸çå
é¨å½æ°ï¼è¿æ ·å¨è¿ç¨å½ä¸ï¼åªä¼æRundll32.exeï¼èä¸ä¼æDLLåé¨çè¿ç¨ï¼è¿æ ·ï¼å°±å®ç°äºè¿ç¨ä¸çéèãå¦æçå°ç³»ç»ä¸æå¤ä¸ªRundll32.exeï¼ä¸å¿
ææ
ï¼è¿è¯æç¨Rundll32.exeå¯å¨äºå¤å°ä¸ªçDLLæ件ãå½ç¶ï¼è¿äºRundll32.exeæ§è¡çDLLæ件æ¯ä»ä¹ï¼æ们é½å¯ä»¥ä»ç³»ç»èªå¨å è½½çå°æ¹æ¾å°ã
ç°å¨ï¼ææ¥ä»ç»ä¸ä¸Rundll32.exeè¿ä¸ªæ件ï¼ææä¸è¾¹å·²ç»è¯´è¿ï¼åè½å°±æ¯ä»¥å½ä»¤è¡çæ¹å¼è°ç¨å¨æé¾æ¥ç¨åºåºãç³»ç»ä¸è¿æä¸ä¸ªRundll.exeæ件ï¼ä»çæææ¯âæ§è¡16ä½çDLLæ件âï¼è¿éè¦æ³¨æä¸ä¸ãå¨æ¥ççRundll32.exe使ç¨çå½æ°ååï¼
Void CALLBACK FunctionName (
HWND hwnd,
HINSTANCE hinst,
LPTSTR lpCmdLine,
Int nCmdShow
);
å
¶å½ä»¤è¡ä¸ç使ç¨æ¹æ³ä¸ºï¼Rundll32.exe DLLname,Functionname [Arguments]
DLLname为éè¦æ§è¡çDLLæ件åï¼Functionname为åè¾¹éè¦æ§è¡çDLLæ件çå
·ä½å¼åºå½æ°ï¼[Arguments]为å¼åºå½æ°çå
·ä½åæ°ã
ç¥è°Rundll32.exeçä½ç¨ (ææ¯èé¸)
常ç¨Windows9xçæåä¸å®å¯¹Rundll32.exeåRundll.exeè¿ä¸¤ä¸ªæ¡£æ¡ä¸ä¼éçå§ï¼ä¸è¿,ç±æ¼è¿ä¸¤ä¸ªç¨å¼çåè½åå
åªéæ¼å¨å¾®è½¯å
é¨ä½¿ç¨ï¼å èçæ£ç¥éå¦ä½ä½¿ç¨å®ä»¬çæåæ³å¿
ä¸å¤ãé£ä¹å¥½ï¼å¦æä½ è¿ä¸æ¸
æ¥çè¯ï¼é£ä¹å°±è®©ææ¥åè¯ä½ å§ã
é¦å
ï¼è¯·ä½ å个å°å®éªï¼è¯·äºå
ä¿åå¥½ä½ æ£å¨æ§è¡çç¨å¼çç»æï¼å¦å...ï¼ï¼ç¹å»âå¼å§ï¼ç¨å¼ï¼Msï¼Dosæ¹å¼âï¼è¿å
¥Dosè§çªï¼ç¶åé®å
¥rundll32.exe user.exe,restartwindowsï¼åæä¸å车é®ï¼è¿æ¶ä½ å°çå°ï¼æºå¨è¢«éå¯äºï¼æä¹æ ·ï¼æ¯ä¸æ¯å¾æ趣ï¼
å½ç¶ï¼Rundllçåè½ç»ä¸ä»
ä»
æ¯éå¯ä½ çæºå¨ãå
¶å®ï¼Rundllè
ï¼é¡¾åæä¹ï¼æ§è¡Dllä¹ï¼å®çåè½å°±æ¯ä»¥å½ä»¤åçæ¹å¼å¼å«Windowsçå¨æé¾ç»åºï¼Rundll32.exeä¸Rundll.exeçåºå«å°±å¨æ¼åè
æ¯å¼å«32ä½çé¾ç»åºï¼èåè
æ¯è¿ç¨æ¼16ä½çé¾ç»åºï¼å®ä»¬çå½ä»¤æ ¼å¼æ¯ï¼
RUNDLL.EXE ï¼ï¼
è¿éè¦æ³¨æä¸ç¹ï¼1.Dllæ¡£æ¡åä¸ä¸è½å«æç©ºæ ¼ï¼æ¯å¦è¯¥æ¡£æ¡ä½æ¼c:\ProgramFiles\ç®å½ï¼ä½ è¦æè¿ä¸ªè·¯å¾æ¹æc:\Prograï½1\ï¼2.Dllæ¡£æ¡åä¸Dllå
¥å£ç¹é´çéå·ä¸è½å°ï¼å¦åç¨å¼å°åºé并ä¸ä¸ä¼ç»åºä»»ä½èµè®¯ï¼3.è¿æ¯æéè¦çä¸ç¹ï¼Rundllä¸è½ç¨æ¥å¼å«å«è¿åå¼åæ°çDllï¼ä¾å¦Win32APIä¸çGetUserName(),GetTextFace()çãå¨Visual Basicä¸ï¼æä¾äºä¸æ¡æ§è¡å¤é¨ç¨å¼çæ令Shell,æ ¼å¼ä¸ºï¼
Shell âå½ä»¤åâ
å¦æè½é
åRundll32.exeç¨å¥½Shellæ令ï¼ä¼ä½¿æ¨çVBç¨å¼æ¥æç¨å
¶ä»æ¹æ³é¾ä»¥çè³æ æ³å®ç°çææï¼ä»ä»¥éå¯ä¸ºä¾ï¼ä¼ ç»çæ¹æ³éè¦ä½ å¨VBå·¥ç¨ä¸å
建ç«ä¸ä¸ªæ¨¡ç»ï¼ç¶ååå
¥WinAPIç声æï¼æåæè½å¨ç¨å¼ä¸å¼å«ãèç°å¨åªéä¸å¥:
Shell ârundll32.exe user.exe,restartwindowsâå°±æå®äºï¼æ¯ä¸æ¯æ¹ä¾¿å¤äºï¼
å®é
ä¸ï¼Rundll32.exeå¨å¼å«åç§Windowsæ§å¶é¢æ¿åç³»ç»é项æ¹é¢æèç¬ç¹çä¼å¿ãä¸é¢ï¼æå°±å°æ¬äººå¨å ç¹ç½ä¸æ¶éçæå
³Rundllçæ令å举å¦ä¸ï¼å¾æç¨çï¼è½çå»ä½ å¾å¤å¼å«Windows APIçæ¶é´ï¼ï¼ï¼ï¼ä¾å¤§å®¶å¨ç¨å¼è®¾è®¡ä¸å¼ç¨ï¼
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL
åè½: æ¾ç¤ºæ§å¶é¢æ¿
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL access.cpl,,1
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼è¾
å©é项ï¼é®çâé项è§çª
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL access.cpl,,2
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼è¾
å©é项ï¼å£°é³âé项è§çª
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL access.cpl,,3
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼è¾
å©é项ï¼æ¾ç¤ºâé项è§çª
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL access.cpl,,4
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼è¾
å©é项ï¼æ»é¼ âé项è§çª
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL access.cpl,,5
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼è¾
å©é项ï¼ä¼ ç»âé项è§çª
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL sysdm.cpl @1
åè½: æ§è¡âæ§å¶é¢æ¿ï¼æ·»å æ°ç¡¬ä½âå导ã
å½ä»¤å: rundll32.exe shell32.dll,SHHelpShortcuts_RunDLL AddPrinter
åè½: æ§è¡âæ§å¶é¢æ¿ï¼æ·»å æ°å°è¡¨æºâå导ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL appwiz.cpl,,1
åè½: æ¾ç¤º âæ§å¶é¢æ¿ï¼æ·»å /å é¤ç¨å¼ï¼å®è£
/å¸è½½â é¢æ¿ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL appwiz.cpl,,2
åè½: æ¾ç¤º âæ§å¶é¢æ¿ï¼æ·»å /å é¤ç¨å¼ï¼å®è£
Windowsâ é¢æ¿ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL appwiz.cpl,,3
åè½: æ¾ç¤º âæ§å¶é¢æ¿ï¼æ·»å /å é¤ç¨å¼ï¼å¯å¨çâ é¢æ¿ã
å½ä»¤å: rundll32.exe syncui.dll,Briefcase_Create
åè½: å¨æ¡é¢ä¸å»ºç«ä¸ä¸ªæ°çâæçå
¬æå
âã
å½ä»¤å: rundll32.exe diskcopy.dll,DiskCopyRunDll
åè½: æ¾ç¤ºå¤å¶è½¯ç¢è§çª
å½ä»¤å: rundll32.exe apwiz.cpl,NewLinkHere ï¼
1
åè½: æ¾ç¤ºâ建ç«å¿«æ·æ¹å¼âç对è¯æ¡ï¼æ建ç«çå¿«æ·æ¹å¼çä½ç½®ç±ï¼
1åæ°å³å®ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL timedate.cpl,,0
åè½: æ¾ç¤ºâæ¥æä¸æ¶é´âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL timedate.cpl,,1
åè½: æ¾ç¤ºâæ¶åºâé项è§çªã
å½ä»¤å: rundll32.exe rnaui.dll,RnaDial [æ个æ¨å·è¿æ¥çå称]
åè½: æ¾ç¤ºæ个æ¨å·è¿æ¥çæ¨å·è§çªãå¦æå·²ç»æ¨å·è¿æ¥ï¼åæ¾ç¤ºç®åçè¿æ¥ç¶æçè§çªã
å½ä»¤å: rundll32.exe rnaui.dll,RnaWizard
åè½: æ¾ç¤ºâæ°å»ºæ¨å·è¿æ¥âå导çè§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL desk.cpl,,0
åè½: æ¾ç¤ºâæ¾ç¤ºå±æ§ï¼èæ¯âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL desk.cpl,,1
åè½: æ¾ç¤ºâæ¾ç¤ºå±æ§ï¼è¤å±ä¿æ¤âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL desk.cpl,,2
åè½: æ¾ç¤ºâæ¾ç¤ºå±æ§ï¼å¤è§âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL desk.cpl,,3
åè½: æ¾ç¤ºæ¾ç¤ºâæ¾ç¤ºå±æ§ï¼å±æ§âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,SHHelpShortcuts_RunDLL FontsFolder
åè½: æ¾ç¤ºWindowsçâåä½âæ¡£æ¡å¤¹ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL main.cpl @3
åè½: åæ ·æ¯æ¾ç¤ºWindowsçâåä½âæ¡£æ¡å¤¹ã
å½ä»¤å: rundll32.exe shell32.dll,SHformatDrive
åè½: æ¾ç¤ºæ ¼å¼å软ç¢å¯¹è¯æ¡ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL joy.cpl,,0
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼æ¸¸ææ§å¶å¨ï¼ä¸è¬âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL joy.cpl,,1
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼æ¸¸ææ§å¶å¨ï¼è¿é¶âé项è§çªã
å½ä»¤å: rundll32.exe mshtml.dll,PrintHTML (HTMLææ¡£)
åè½: åå°HTMLææ¡£ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL mlcfg32.cpl
åè½: æ¾ç¤ºMicrosoft Exchangeä¸è¬é项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL main.cpl @0
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼æ»é¼ â é项 ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL main.cpl @1
åè½: æ¾ç¤º âæ§å¶é¢æ¿ï¼é®çå±æ§ï¼é度âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL main.cpl @1,,1
åè½: æ¾ç¤º âæ§å¶é¢æ¿ï¼é®çå±æ§ï¼è¯è¨âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL main.cpl @2
åè½: æ¾ç¤ºWindowsâå°è¡¨æºâæ¡£æ¡å¤¹ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL main.cpl @3
åè½: æ¾ç¤ºWindowsâåä½âæ¡£æ¡å¤¹ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL main.cpl @4
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼è¾å
¥æ³å±æ§ï¼è¾å
¥æ³âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL modem.cpl,,add
åè½: æ§è¡âæ·»å æ°è°å¶è§£è°å¨âå导ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,,0
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼å¤åªä½å±æ§ï¼é³é¢âå±æ§é¡µã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,,1
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼å¤åªä½å±æ§ï¼è§é¢âå±æ§é¡µã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,,2
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼å¤åªä½å±æ§ï¼MIDIâå±æ§é¡µã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,,3
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼å¤åªä½å±æ§ï¼CDé³ä¹âå±æ§é¡µã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,,4
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼å¤åªä½å±æ§ï¼è®¾å¤âå±æ§é¡µã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl @1
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼å£°é³âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL netcpl.cpl
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼ç½è·¯âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL odbccp32.cpl
åè½: æ¾ç¤ºODBC32èµæ管çé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,OpenAs_RunDLL {drive:\path\filename}
åè½: æ¾ç¤ºæå®æ¡£æ¡(drive:\path\filename)çâæå¼æ¹å¼â对è¯æ¡ã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL password.cpl
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼å¯ç âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL powercfg.cpl
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼çµæºç®¡çå±æ§âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,SHHelpShortcuts_RunDLL PrintersFolder
åè½: æ¾ç¤ºWindowsâå°è¡¨æºâæ¡£æ¡å¤¹ã(årundll32.exe shell32.dll,Control_RunDLL main.cpl @2)
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL intl.cpl,,0
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼åºå设置å±æ§ï¼åºå设置âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL intl.cpl,,1
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼åºå设置å±æ§ï¼æ°åâé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL intl.cpl,,2
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼åºå设置å±æ§ï¼è´§å¸âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL intl.cpl,,3
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼åºå设置å±æ§ï¼æ¶é´âé项è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL intl.cpl,,4
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼åºå设置å±æ§ï¼æ¥æâé项è§çªã
å½ä»¤å: rundll32.exe desk.cpl,InstallScreenSaver [è¤å±ä¿æ¤æ¡£æ¡å]
åè½: å°æå®çè¤å±ä¿æ¤æ¡£æ¡è®¾ç½®ä¸ºWindowsçå±ä¿ï¼å¹¶æ¾ç¤ºè¤å±ä¿æ¤å±æ§è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL sysdm.cpl,,0
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼ç³»ç»å±æ§ï¼ä¼ ç»âå±æ§è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL sysdm.cpl,,1
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼ç³»ç»å±æ§ï¼è®¾å¤ç®¡çå¨âå±æ§è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL sysdm.cpl,,2
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼ç³»ç»å±æ§ï¼ç¡¬ä½é
置档æ¡âå±æ§è§çªã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL sysdm.cpl,,3
åè½: æ¾ç¤ºâæ§å¶é¢æ¿ï¼ç³»ç»å±æ§ï¼æ§è½âå±æ§è§çªã
å½ä»¤å: rundll32.exe user.exe,restartwindows
åè½: 强è¡å
³éææç¨å¼å¹¶éå¯æºå¨ã
å½ä»¤å: rundll32.exe user.exe,exitwindows
åè½: 强è¡å
³éææç¨å¼å¹¶å
³æºã
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL telephon.cpl
åè½: æ¾ç¤ºâæ¨å·å±æ§âé项è§çª
å½ä»¤å: rundll32.exe shell32.dll,Control_RunDLL themes.cpl
åè½: æ¾ç¤ºâæ¡é¢ä¸»æ¨âé项é¢æ¿
å½ç¶ï¼ä¸æ¢æ¯VisualBasicï¼è±¡Delphi.VisualCï¼ï¼çå
¶ä»ç¨å¼è®¾è®¡è¯è¨ä¹å¯ä»¥éè¿å¼å«å¤é¨å½ä»¤çæ¹æ³æ¥ä½¿ç¨Rundllçè¿äºåè½ï¼å
·ä½æ¹æ³è¿éå°±ä¸å详ç»åè¿°äºãçµæ´»ç使ç¨Rundll,ä¸å®ä¼ä½¿ä½ çç¨å¼è®¾è®¡è½»è½»æ¾æ¾ï¼è¾¾å°äºåååçææï¼
温馨提示:内容为网友见解,仅供参考