楼上的【蒶葒铯de囙憶】这位~
请你不要传木马好不?~
1M多的木马~什么啊~
还带自动删除的~
自动删除的原理用的P处理~真垃圾~建议你去学学最新的自动删除代码~
我这里有一份汇编写的~你要我给你~
下面附上VirusTotal搜索结果~
反病毒引擎 版本 最后更新 扫描结果
a-squared 4.5.0.24 2009.07.15 Virus.Win32.Agent.COH!IK
AhnLab-V3 5.0.0.2 2009.07.15 Win-Trojan/Xema.variant
AntiVir 7.9.0.215 2009.07.15 TR/Dropper.Gen
Antiy-AVL 2.0.3.7 2009.07.15 -
Authentium 5.1.2.4 2009.07.15 W32/Agent.CM.gen!Eldorado
Avast 4.8.1335.0 2009.07.15 Win32:Rootkit-gen
AVG 8.5.0.387 2009.07.15 SHeur.CMDD
BitDefender 7.2 2009.07.15 Trojan.Generic.1431448
CAT-QuickHeal 10.00 2009.07.15 Trojan.Agent.gen
ClamAV 0.94.1 2009.07.15 Trojan.Downloader-72711
Comodo 1661 2009.07.15 TrojWare.Win32.TrojanDropper.VB.~AAAG
DrWeb 5.0.0.12182 2009.07.15 -
eSafe 7.0.17.0 2009.07.15 -
eTrust-Vet 31.6.6616 2009.07.15 Win32/SillyAutorun.ALB
F-Prot 4.4.4.56 2009.07.14 W32/Agent.CM.gen!Eldorado
F-Secure 8.0.14470.0 2009.07.15 Trojan.Win32.Agent2.edf
Fortinet 3.120.0.0 2009.07.15 -
GData 19 2009.07.15 Trojan.Generic.1431448
Ikarus T3.1.1.64.0 2009.07.15 Virus.Win32.Agent.COH
Jiangmin 11.0.706 2009.07.15 Trojan/Agent.aawy
K7AntiVirus 7.10.793 2009.07.15 Trojan.Win32.Malware.4
Kaspersky 7.0.0.125 2009.07.15 Trojan.Win32.Agent2.edf
McAfee 5677 2009.07.15 BackDoor-DRV.gen.c
McAfee+Artemis 5677 2009.07.15 BackDoor-DRV.gen.c
McAfee-GW-Edition 6.8.5 2009.07.15 Heuristic.BehavesLike.Win32.Suspicious.H
Microsoft 1.4803 2009.07.15 Trojan:WinNT/Hookmoot.gen!A
NOD32 4247 2009.07.15 Win32/FlyStudio.NFV
Norman 6.01.09 2009.07.15 W32/Obfuscated.H3!genr
nProtect 2009.1.8.0 2009.07.15 Trojan/W32.Agent2.1100083
Panda 10.0.0.14 2009.07.15 -
PCTools 4.4.2.0 2009.07.15 Trojan-PWS.QQPass.LHF
Prevx 3.0 2009.07.15 High Risk Cloaked Malware
Rising 21.38.24.00 2009.07.15 Trojan.Win32.Nodef.bsq
Sophos 4.43.0 2009.07.15 Mal/Behav-043
Sunbelt 3.2.1858.2 2009.07.15 Trojan-Spy.Win32.Agent
Symantec 1.4.4.12 2009.07.15 Trojan.Dropper
TheHacker 6.3.4.3.368 2009.07.15 Trojan/Agent2.edf
TrendMicro 8.950.0.1094 2009.07.15 TROJ_SHEUR.AYB
VBA32 3.12.10.8 2009.07.15 Trojan.Win32.Agent.bfnb
ViRobot 2009.7.15.1837 2009.07.15 -
VirusBuster 4.6.5.0 2009.07.15 Worm.Autorun.KFE
附加信息
File size: 1100083 bytes
MD5...: e1b5305805616a6f9d7288500eacb32b
SHA1..: a2db15b7b3963581558e19c8875b1ffd5ffc04c9
SHA256: 8126641e70cc0b52062b70ce65963c792b1a089c168a44405a06a9a5c3879d1b
ssdeep: 24576:ohP98hBIkJSRRkVUz7bBAFuUWBxDaoFryHqhHab:ohPMBIkGkaziEUaPFr
yHqkb
PEiD..: Armadillo v1.71
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (62.9%)
Win32 Executable Generic (14.2%)
Win32 Dynamic Link Library (generic) (12.6%)
Clipper DOS Executable (3.3%)
Generic Win/DOS Executable (3.3%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x3861
timedatestamp.....: 0x59bffa3 (Mon Dec 25 05:33:23 1972)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4dcc 0x5000 6.52 2e50996cc73c4c2fb7ea8f79cf982b26
.rdata 0x6000 0xa4a 0x1000 3.56 e5615fe4c75b4f7ba6eaedb684bf431c
.data 0x7000 0x1f58 0x2000 2.86 65f79c130923371bceab73bb68dbb967
.data 0x9000 0x38000 0x38000 7.25 d848658057541411573901f9e455dec0
.rsrc 0x41000 0x13728 0x14000 4.89 058581b8946f6526bde5d9a431f7858e
( 2 imports )
> KERNEL32.dll: GetProcAddress, LoadLibraryA, CloseHandle, WriteFile, CreateDirectoryA, GetTempPathA, ReadFile, SetFilePointer, CreateFileA, GetModuleFileNameA, GetStringTypeA, LCMapStringW, LCMapStringA, HeapAlloc, HeapFree, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersion, ExitProcess, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, RtlUnwind, GetCPInfo, GetACP, GetOEMCP, MultiByteToWideChar, GetStringTypeW
> USER32.dll: MessageBoxA, wsprintfA
( 0 exports )
PDFiD.: -
RDS...: NSRL Reference Data Set