看到有網友回報 msnpp 被 Kaspersky, NOD32 偵測到 Backdoor.Win32.Clampi.f 木馬,
一開始以為是有用 ASPack 壓過的關係, 後來用 Source 重編的檔案,
就被卡巴偵測出有木馬, 但是掃 Compiler (PureBasic) 又 OK,
進一步 trace 的結果, 會導致誤報的是連網頁那行程式,
ShellExecute_(hParent,"open","http://pank.org/im/?msnpp=1","","",#SW_SHOWNORMAL)
把這行註解掉重編, 卡巴就沒叫了
後來改成另一種寫法
RunProgram("cmd.exe", "/c Start http://pank.org/im/?msnpp=1","",#PB_Program_Hi\
de)
也不再用 ASPack 壓了, 為了讓大家安心, 網站上的程式已 Update
提供相關檔案, 讓有興趣的人研究一下
之前的版本(會讓某些防毒軟體誤報)
Souce Code msnpp_test.pb
執行檔 msnpp_test.exe
修改後的版本
Souce Code msnpp.pb
執行檔 msnpp.exe
編譯環境是 PureBasic 4.31 32bit + jaPBE 版本, 執行檔都沒有用 ASPack 壓, 所以比之前的 27K 大一些
兩個版本只差一行, 就是前面所提的連網頁部份.
IM: October 2009 Archives
Recent Entries
About this Archive
This page is an archive of entries in the IM category from October 2009.
IM: August 2009 is the previous archive.
IM: May 2010 is the next archive.
Find recent content on the main index or look in the archives to find all content.
IM: Monthly Archives
Categories
- 3C (21)
- Bookmark (77)
- Data (161)
- FreeBSD (28)
- Fun (4)
- Game (5)
- Google (24)
- Hosting (15)
- IM (16)
- Life (25)
- Linux (139)
- Misc (63)
- My Program (7)
- Network (36)
- News (245)
- Notes (385)
- Photo (7)
- Programming (17)
- Security (2)
- Shell (12)
- Software (266)
- SQL (17)
- Travel (8)
- Tutorial (6)
- Windows (29)
- [GuestBook] (1)
- Cloud (7)
- Other OS (1)
Monthly Archives
- September 2011 (8)
- August 2011 (25)
- July 2011 (19)
- June 2011 (13)
- May 2011 (12)
- April 2011 (18)
- March 2011 (14)
- February 2011 (7)
- January 2011 (7)
- December 2010 (6)
- November 2010 (16)
- October 2010 (17)
- September 2010 (11)
- August 2010 (6)
- July 2010 (10)
- June 2010 (10)
- May 2010 (14)
- April 2010 (14)
- March 2010 (16)
- February 2010 (4)
- January 2010 (13)
- December 2009 (10)
- November 2009 (18)
- October 2009 (11)
- September 2009 (14)
- August 2009 (10)
- July 2009 (6)
- June 2009 (5)
- May 2009 (3)
- April 2009 (12)
- March 2009 (18)
- February 2009 (7)
- January 2009 (14)
- December 2008 (15)
- November 2008 (12)
- October 2008 (9)
- September 2008 (10)
- August 2008 (13)
- July 2008 (28)
- June 2008 (17)
- May 2008 (13)
- April 2008 (15)
- March 2008 (7)
- February 2008 (5)
- January 2008 (2)
- November 2007 (4)
- October 2007 (8)
- September 2007 (7)
- August 2007 (3)
- July 2007 (10)
- June 2007 (4)
- May 2007 (5)
- April 2007 (9)
- March 2007 (11)
- February 2007 (7)
- January 2007 (4)
- December 2006 (9)
- November 2006 (14)
- October 2006 (10)
- September 2006 (9)
- August 2006 (6)
- July 2006 (15)
- June 2006 (22)
- May 2006 (17)
- April 2006 (13)
- March 2006 (18)
- February 2006 (10)
- January 2006 (28)
- December 2005 (17)
- November 2005 (15)
- October 2005 (18)
- September 2005 (24)
- August 2005 (39)
- July 2005 (14)
- June 2005 (22)
- May 2005 (32)
- April 2005 (27)
- March 2005 (32)
- February 2005 (20)
- January 2005 (38)
- December 2004 (49)
- November 2004 (38)
- October 2004 (24)
- September 2004 (23)
- August 2004 (38)
- July 2004 (39)
- June 2004 (38)
- May 2004 (17)
- April 2004 (32)
- March 2004 (15)
- February 2004 (6)
- January 2004 (19)
- December 2003 (19)
- November 2003 (15)
- October 2003 (15)
- September 2003 (12)
- August 2003 (20)
- July 2003 (26)
Recent Comments