本帖最后由 pkuyzy 于 2016-7-13 08:13 编辑
软件原帖
http://bbs.kafan.cn/thread-2048210-1-1.html
链接: https://pan.baidu.com/s/1bZqHdW 密码: isrg
这是哈勃的行为分析,报高度风险
https://habo.qq.com/file/showdetail?pk=ADcGYl1qB2IIPFs5
关键行为
行为描述: 打开注册表_检测虚拟机相关
详情信息:
\REGISTRY\MACHINE\Software\VMware, Inc.
行为描述: 设置特殊文件夹属性
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 获取TickCount值
详情信息:
TickCount = 5360518, SleepMilliseconds = 50.
TickCount = 5360612, SleepMilliseconds = 50.
TickCount = 5360659, SleepMilliseconds = 50.
TickCount = 5360675, SleepMilliseconds = 50.
TickCount = 5360721, SleepMilliseconds = 50.
TickCount = 5360737, SleepMilliseconds = 50.
TickCount = 5360753, SleepMilliseconds = 50.
TickCount = 5360768, SleepMilliseconds = 50.
TickCount = 5360784, SleepMilliseconds = 50.
TickCount = 5360862, SleepMilliseconds = 50.
TickCount = 5360878, SleepMilliseconds = 50.
TickCount = 5360893, SleepMilliseconds = 50.
TickCount = 5360925, SleepMilliseconds = 50.
TickCount = 5360940, SleepMilliseconds = 50.
TickCount = 5360987, SleepMilliseconds = 50.
求问一下各位大神,为什么迅雷破解版要检测虚拟机相关呢?
@轩夏 @好想用EMSI @蓝天二号 @Eset小粉絲 @aboringman @心醉咖啡 @驭龙 @霄栋 @
windows7爱好者 |