查看: 2860|回复: 9
收起左侧

[病毒样本] 这个相机里的毒,上传virus total已经过了所有杀软

[复制链接]
CGW
发表于 2009-9-22 14:13:31 | 显示全部楼层 |阅读模式
这个文件是个三星相机图片名,确是个exe文件,插在相机里面,请高手分析一下。

我上传到virus total都不报毒,不知道该不该删。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
成功注册
发表于 2009-9-22 14:45:26 | 显示全部楼层
kav很垃圾,啥也没查出来
tun
发表于 2009-9-22 14:47:01 | 显示全部楼层
上传的附件已经没有内容,垃圾文件
shirenlau
发表于 2009-9-22 15:46:00 | 显示全部楼层
确实是垃圾文件
yyylll66
发表于 2009-9-22 16:30:16 | 显示全部楼层
内容:
REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment.
REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a
REM different startup file is specified in an application's PIF.
REM Install CD ROM extensions
lh C:\WINDOWS\system32\mscdexnt.exe
REM Install network redirector (load before dosx.exe)
lh C:\WINDOWS\system32\redir
REM Install DPMI support
lh C:\WINDOWS\system32\dosx
REM The following line enables Sound Blaster 2.0 support on NTVDM.
REM The command for setting the BLASTER environment is as follows:
REM    SET BLASTER=A220 I5 D1 P330
REM    where:
REM        A    specifies the sound blaster's base I/O port
REM        I    specifies the interrupt request line
REM        D    specifies the 8-bit DMA channel
REM        P    specifies the MPU-401 base I/O port
REM        T    specifies the type of sound blaster card
REM                 1 - Sound Blaster 1.5
REM                 2 - Sound Blaster Pro I
REM                 3 - Sound Blaster 2.0
REM                 4 - Sound Blaster Pro II
REM                 6 - SOund Blaster 16/AWE 32/32/64
REM
REM    The default value is A220 I5 D1 T3 and P330.  If any of the switches is
REM    left unspecified, the default value will be used. (NOTE, since all the
REM    ports are virtualized, the information provided here does not have to
REM    match the real hardware setting.)  NTVDM supports Sound Blaster 2.0 only.
REM    The T switch must be set to 3, if specified.
SET BLASTER=A220 I5 D1 P330 T3
REM To disable the sound blaster 2.0 support on NTVDM, specify an invalid
REM SB base I/O port address.  For example:
REM    SET BLASTER=A0
以及
REM Windows MS-DOS Startup File
REM
REM CONFIG.SYS vs CONFIG.NT
REM CONFIG.SYS is not used to initialize the MS-DOS environment.
REM CONFIG.NT is used to initialize the MS-DOS environment unless a
REM different startup file is specified in an application's PIF.
REM
REM ECHOCONFIG
REM By default, no information is displayed when the MS-DOS environment
REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
REM the command echoconfig to CONFIG.NT or other startup file.
REM
REM NTCMDPROMPT
REM When you return to the command prompt from a TSR or while running an
REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
REM other startup file.
REM
REM DOSONLY
REM By default, you can start any type of application when running
REM COMMAND.COM. If you start an application other than an MS-DOS-based
REM application, any running TSR may be disrupted. To ensure that only
REM MS-DOS-based applications can be started, add the command dosonly to
REM CONFIG.NT or other startup file.
REM
REM EMM
REM You can use EMM command line to configure EMM(Expanded Memory Manager).
REM The syntax is:
REM
REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM]
REM
REM     AltRegSets
REM         specifies the total Alternative Mapping Register Sets you
REM         want the system to support. 1 <= AltRegSets <= 255. The
REM         default value is 8.
REM     BaseSegment
REM         specifies the starting segment address in the Dos conventional
REM         memory you want the system to allocate for EMM page frames.
REM         The value must be given in Hexdecimal.
REM         0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
REM         16KB boundary. The default value is 0x4000
REM     RAM
REM         specifies that the system should only allocate 64Kb address
REM         space from the Upper Memory Block(UMB) area for EMM page frames
REM         and leave the rests(if available) to be used by DOS to support
REM         loadhigh and devicehigh commands. The system, by default, would
REM         allocate all possible and available UMB for page frames.
REM
REM     The EMM size is determined by pif file(either the one associated
REM     with your application or _default.pif). If the size from PIF file
REM     is zero, EMM will be disabled and the EMM line will be ignored.
REM
dos=high, umb
device=C:\WINDOWS\system32\himem.sys
files=40
country=086,936,C:\WINDOWS\system32\country.sys
shell=C:\WINDOWS\System32\command.com /p C:\WINDOWS\system32

英文彻底还给老师了,好像没什么问题。。。
521HDL
发表于 2009-9-22 16:59:14 | 显示全部楼层
费尔没发现!
sam.to
发表于 2009-9-22 17:43:21 | 显示全部楼层
原帖由 成功注册 于 2009-9-22 14:45 发表
kav很垃圾,啥也没查出来

不报是垃圾?什么都报便不垃圾????
BitDefender
发表于 2009-9-22 19:13:50 | 显示全部楼层

回复 2楼 成功注册 的帖子

注意言辞 看你就被扣过分
BING126
头像被屏蔽
发表于 2009-9-22 22:07:57 | 显示全部楼层
McAfee miss
winxp0286
发表于 2009-9-22 22:25:33 | 显示全部楼层
ESET NOD 3.0 miss

TO ESET!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 09:40 , Processed in 1.862394 second(s), 4 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表