查看: 3223|回复: 10
收起左侧

[病毒样本] 超高质量的样本啊。。。

[复制链接]
金山升级精灵
发表于 2009-9-26 17:48:22 | 显示全部楼层 |阅读模式
怎么全都过了?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
尤金卡巴斯基
发表于 2009-9-26 18:13:50 | 显示全部楼层
100.exe_

No malicious code was found in this file.
rzqevergo
头像被屏蔽
发表于 2009-9-26 18:34:00 | 显示全部楼层
to symantec
yyylll66
发表于 2009-9-26 19:59:16 | 显示全部楼层
就系统临时文件夹里有scs1.tmp与scs2.tmp,好像没问题!

内容:

REM Windows MS-DOS Startup File
REM
REM CONFIG.SYS vs CONFIG.NT
REM CONFIG.SYS is not used to initialize the MS-DOS environment.
REM CONFIG.NT is used to initialize the MS-DOS environment unless a
REM different startup file is specified in an application's PIF.
REM
REM ECHOCONFIG
REM By default, no information is displayed when the MS-DOS environment
REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
REM the command echoconfig to CONFIG.NT or other startup file.
REM
REM NTCMDPROMPT
REM When you return to the command prompt from a TSR or while running an
REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
REM other startup file.
REM
REM DOSONLY
REM By default, you can start any type of application when running
REM COMMAND.COM. If you start an application other than an MS-DOS-based
REM application, any running TSR may be disrupted. To ensure that only
REM MS-DOS-based applications can be started, add the command dosonly to
REM CONFIG.NT or other startup file.
REM
REM EMM
REM You can use EMM command line to configure EMM(Expanded Memory Manager).
REM The syntax is:
REM
REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM]
REM
REM     AltRegSets
REM         specifies the total Alternative Mapping Register Sets you
REM         want the system to support. 1 <= AltRegSets <= 255. The
REM         default value is 8.
REM     BaseSegment
REM         specifies the starting segment address in the Dos conventional
REM         memory you want the system to allocate for EMM page frames.
REM         The value must be given in Hexdecimal.
REM         0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
REM         16KB boundary. The default value is 0x4000
REM     RAM
REM         specifies that the system should only allocate 64Kb address
REM         space from the Upper Memory Block(UMB) area for EMM page frames
REM         and leave the rests(if available) to be used by DOS to support
REM         loadhigh and devicehigh commands. The system, by default, would
REM         allocate all possible and available UMB for page frames.
REM
REM     The EMM size is determined by pif file(either the one associated
REM     with your application or _default.pif). If the size from PIF file
REM     is zero, EMM will be disabled and the EMM line will be ignored.
REM
dos=high, umb
device=C:\WINDOWS\system32\himem.sys
files=40
country=086,936,C:\WINDOWS\system32\country.sys
shell=C:\WINDOWS\System32\command.com /p C:\WINDOWS\system32
王子带着刀
发表于 2009-9-26 20:04:39 | 显示全部楼层
实机双击了  没有拦住

yyylll66
发表于 2009-9-26 20:05:57 | 显示全部楼层
一点问题也没有,你放心双击,不会有一点危害!

真正全过杀软的是偶提供的一个样本,危害在24楼附件里!有兴趣你实机试试?呵呵

http://bbs.kafan.cn/thread-564057-1-1.html

[ 本帖最后由 yyylll66 于 2009-9-26 20:07 编辑 ]
zengjinxin
发表于 2009-9-26 20:08:19 | 显示全部楼层
MD的阻止的日志

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
813kr
发表于 2009-9-26 20:11:59 | 显示全部楼层
没发现有多大问题
IllusionWing
发表于 2009-9-26 20:15:49 | 显示全部楼层
没毒..
yyylll66
发表于 2009-9-26 20:16:38 | 显示全部楼层
就是一点问题也没有,而不是有那么一点点问题也好撒!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 07:59 , Processed in 0.084589 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表