|
动画介绍:NOD32 秒杀,现在我们一步一步的来分析调试,先把winexec注释起来,还杀,证明和winexec这个API无关,那么问题就在 UrlDownloadToFile上,继续调试,看看还杀不,因为现在杀软都锁定EXE文件的,让服务器的文件非EXE即可,随便改个还杀,证明和 Pchar(’D:\1.exe’) 有关系,因为其他参数都被我们忽视了,让本地文件也非EXE。
A-Squared Found nothing AntiVir Found TR/Delphi.Downloader.Gen ArcaVir Found Trojan.Spy.Keylogger.As Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found Trojan.DownLoader.origin F-Prot Antivirus Found Possibly a new variant of W32/Downloader-WebExe-based!Maximus F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found Trojan-Downloader.Win32.Small.cnx Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found Mal/DelpDldr-C VirusBuster Found nothing VBA32 Found Win32.Trojan.Downloader (http://...) (probable variant) |