12
返回列表 发新帖
楼主: xiaoyingwu
收起左侧

[分享] 一个可以制作自己的木查杀工具的软件(由于技术问题,速度有点慢,请谅解)

[复制链接]
xiaoyingwu
 楼主| 发表于 2017-1-13 11:19:35 | 显示全部楼层
kinerarten 发表于 2017-1-13 09:23
有捆绑么?怕怕,技术不过关不敢乱下载

没捆绑,只是扫描速度有点慢
xiaoyingwu
 楼主| 发表于 2017-1-13 11:20:16 | 显示全部楼层
kinerarten 发表于 2017-1-13 09:23
有捆绑么?怕怕,技术不过关不敢乱下载

没捆绑,只是扫描速度有点慢
神龟Turmi
发表于 2017-1-15 20:55:51 | 显示全部楼层
xiaoyingwu 发表于 2017-1-13 11:20
没捆绑,只是扫描速度有点慢

开源嘛?
xiaoyingwu
 楼主| 发表于 2017-1-15 20:59:13 | 显示全部楼层

VB写的,要吗。要我就发地址
神龟Turmi
发表于 2017-1-15 21:00:42 | 显示全部楼层
xiaoyingwu 发表于 2017-1-15 20:59
VB写的,要吗。要我就发地址


我懂了 SHA1或者MD5的扫描器对吧?
来一份~我欣赏一下!给你加分哦
xiaoyingwu
 楼主| 发表于 2017-1-15 21:11:56 | 显示全部楼层
神龟Turmi 发表于 2017-1-15 21:00
我懂了 SHA1或者MD5的扫描器对吧?
来一份~我欣赏一下!给你加分哦

不是,读取EXE文件内容(通常是乱码),判断书否存在某些字符
一下是VB代码
Screen.MousePointer = vbHourglass
    'ProblemScan v1.0 by Alan Dipert
    'Currently Scans for the following trojan servers:
        'NetBus v1.6
        'NetBus v1.7
        'NetBus v2.1 Pro
        'Subseven v1.8
        'Subseven v1.9
        'Subseven v2.0
        'Subseven v2.1
        'Subseven v2.1 GOLD
        'Back Orifice v1.2
        'Back Orifice v1.2 Encrypted variant
        'Back Orifice v2000
   
    'buffer and binary breakdown variables
    Dim filename As String, buffer As String
   
    'message box variables
    Dim resultsMSG As String, msgResult As VbMsgBoxResult, deletion As String
   
   
    'boolean declarations - "Are these strings in the file?"
    Dim netbus16total As Integer, netbus17total As Integer, netbus21total As Integer
    Dim subseven18total As Integer, subseven19total As Integer, subseven20total As Integer
    Dim subseven21total As Integer, subseven21goldtotal As Integer, bo12total As Integer, bo2ktotal As Integer
    Dim bo12encryptedtotal As Integer
   
    'NetBus versions
    Dim netbus16 As Boolean, netbus17 As Boolean, netbus21 As Boolean
   
    'SubSeven versions
    Dim subseven18 As Boolean, subseven19 As Boolean, subseven20 As Boolean, subseven21 As Boolean, subseven21gold As Boolean
   
    'Back Orifice versions
    Dim bo12 As Boolean, bo2k As Boolean, bo12encrypted As Boolean
   
    'other
   
    'begin NetBus series scan sequence
    Dim server As String
    netbus16total = 0
    server = "No trojan server was found."
    deletion = "The file has been deleted."


    filename = f1.Path


    If filename = "" Then
        MsgBox "Please select a file to scan.", vbOKOnly, Scanner
        GoTo end1
    End If
    Open filename For Binary As 1
        Do While Not EOF(1)
            buffer = Space(4096)
            Get 1, , buffer
            DoEvents
            If InStr(buffer, "

评分

参与人数 1人气 +1 收起 理由
神龟Turmi + 1 兑现承诺加分。。。

查看全部评分

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-17 00:40 , Processed in 0.099592 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表