本帖最後由 dg6546money 於 2010-6-20 04:30 編輯  
 
絕對是原創的...WW 
請VISTA和WIN7的使用者把程式設定到在WINDOWS XP SP2/SP3的相容性下執行 
 
就是之前那種登入方法..給懶人寫了程式(粗製濫造的無聊之作而已) 
 
VISUAL BASIC寫成 
 
喜歡的可以下載 
 
掃毒(可能用了SHELL代碼吧,被誤判了WW): 
 
檔案 login.exe 接收於 2010.03.10 13:42:14 (UTC) 
 
結果: 1/42 (2.39%) 
 
 
 
 
| 反病毒引擎 | 版本 | 最後更新 | 掃瞄結果 |  | a-squared | 4.5.0.50 | 2010.03.10 | - |  | AhnLab-V3 | 5.0.0.2 | 2010.03.09 | - |  | AntiVir | 8.2.1.180 | 2010.03.10 | - |  | Antiy-AVL | 2.0.3.7 | 2010.03.10 | - |  | Authentium | 5.2.0.5 | 2010.03.10 | - |  | Avast | 4.8.1351.0 | 2010.03.10 | - |  | Avast5 | 5.0.332.0 | 2010.03.10 | - |  | AVG | 9.0.0.787 | 2010.03.09 | - |  | BitDefender | 7.2 | 2010.03.10 | - |  | CAT-QuickHeal | 10.00 | 2010.03.10 | - |  | ClamAV | 0.96.0.0-git | 2010.03.10 | - |  | Comodo | 4091 | 2010.02.28 | - |  | DrWeb | 5.0.1.12222 | 2010.03.10 | - |  | eSafe | 7.0.17.0 | 2010.03.09 | - |  | eTrust-Vet | 35.2.7351 | 2010.03.10 | - |  | F-Prot | 4.5.1.85 | 2010.03.10 | - |  | F-Secure | 9.0.15370.0 | 2010.03.10 | - |  | Fortinet | 4.0.14.0 | 2010.03.09 | - |  | GData | 19 | 2010.03.10 | - |  | Ikarus | T3.1.1.80.0 | 2010.03.10 | - |  | Jiangmin | 13.0.900 | 2010.03.10 | - |  | K7AntiVirus | 7.10.993 | 2010.03.09 | - |  | Kaspersky | 7.0.0.125 | 2010.03.10 | - |  | McAfee | 5915 | 2010.03.09 | - |  | McAfee+Artemis | 5915 | 2010.03.09 | - |  | McAfee-GW-Edition | 6.8.5 | 2010.03.10 | - |  | Microsoft | 1.5502 | 2010.03.10 | - |  | NOD32 | 4931 | 2010.03.10 | - |  | Norman | 6.04.08 | 2010.03.10 | - |  | nProtect | 2009.1.8.0 | 2010.03.10 | - |  | Panda | 10.0.2.2 | 2010.03.09 | - |  | PCTools | 7.0.3.5 | 2010.03.10 | - |  | Prevx | 3.0 | 2010.03.10 | - |  | Rising | 22.38.02.03 | 2010.03.10 | - |  | Sophos | 4.51.0 | 2010.03.10 | - |  | Sunbelt | 5812 | 2010.03.10 | - |  | Symantec | 20091.2.0.41 | 2010.03.10 | Suspicious.Insight |  | TheHacker | 6.5.2.0.228 | 2010.03.10 | - |  | TrendMicro | 9.120.0.1004 | 2010.03.10 | - |  | VBA32 | 3.12.12.2 | 2010.03.09 | - |  | ViRoBOT | 2010.3.10.2220 | 2010.03.10 | - |  | VirusBuster | 5.0.27.0 | 2010.03.10 | - |  
 | 附加訊息 |  | File size: 20480 bytes |  | MD5...: 90336528c850799f6e5b352b59bff7e9 |  | SHA1..: 893aad3c4adbf65b73471eeac354499cdbad2c4a |  | SHA256: b24e5d9e3cd6ed606247abbbca8f850434d5d41ab259c1d5c7a9ee03acf3dd1e |  ssdeep: 96:e7ZhZUOySli8/mzkSUSZWhiXiTFZUCjzwUsnSGJJsLqq9fhX8eUc6yUdh2XT8 
5Uf:1E5ThiyTfUozbqSG0qCO7c6l29E25T 
 |  | PEiD..: - |  PEInfo: PE Structure information 
 
( base data ) 
entrypointaddress.: 0x1190 
timedatestamp.....: 0x4b979b92 (Wed Mar 10 13:16:02 2010) 
machinetype.......: 0x14c (I386) 
 
( 3 sections ) 
name viradd virsiz rawdsiz ntrpy md5 
.text 0x1000 0x1e9c 0x2000 4.35 0841ece2930267705d3a72d664c792fb 
.data 0x3000 0x9f0 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110 
.rsrc 0x4000 0x984 0x1000 2.16 c72c59ede63029f0d3bf6859fa74f4fa 
 
( 1 imports )  
> MSVBVM60.DLL: _CIcos, _adj_fptan, __vbaFreeVar, __vbaEnd, _adj_fdiv_m64, __vbaFreeObjList, _adj_fprem1, __vbaStrCat, __vbaHresultCheckObj, _adj_fdiv_m32, __vbaObjSet, _adj_fdiv_m16i, _adj_fdivr_m16i, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, _adj_fpatan, EVENT_SINK_Release, -, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaFPException, _CIlog, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, -, _CIatan, __vbaStrMove, _allmul, _CItan, _CIexp 
 
( 0 exports )  
 |  RDS...: NSRL Reference Data Set 
- |  | pdfid.: - |  trid..: Generic Win/DOS Executable (49.9%) 
DOS Executable Generic (49.8%) 
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) |  sigcheck: 
publisher....: n/a 
copyright....: n/a 
product......: Project1 
description..: n/a 
original name: login.exe 
internal name: login 
file version.: 1.00 
comments.....: n/a 
signers......: - 
signing date.: - 
verified.....: Unsigned 
 |  
  
 
載點: 
 
因為那個誤判,可能大家還在懷擬有病毒吧,所以我決定放出源碼 
 |