| 网站首页 | 业界新闻 | 小组 | 威客 | 人才 | 下载频道 | 博客 | 代码贴 | 在线编程 | 编程论坛
欢迎加入我们,一同切磋技术
用户名:   
 
密 码:  
共有 2155 人关注过本帖
标题:求助:如何找到“木马”代码?
只看楼主 加入收藏
yuma
Rank: 12Rank: 12Rank: 12
来 自:银河系
等 级:贵宾
威 望:37
帖 子:1934
专家分:3012
注 册:2009-12-22
收藏
得分:0 
误报你就不用管了。


你把有问题的EXE文件发上来,我给你做一下免杀。

[ 本帖最后由 yuma 于 2012-7-22 13:30 编辑 ]

心生万象,万象皆程序!
本人计算机知识网:http://bbs.为防伸手党,本站已停止会员注册。
2012-07-22 13:27
jrs123
Rank: 2
等 级:论坛游民
威 望:1
帖 子:627
专家分:14
注 册:2006-9-5
收藏
得分:0 
再制作二页EXE文件检测是否有“木马”代码,结果没有发现“木马”
为了进一步确认“木马”是否就是在27b.exe上面,于是又独立制作了27c.exe和28a.exe,检测结果是这二页都没有“木马”代码;
那么究竟那一组代码是“木马”代码,现将有关页码代码发如下,请您用火眼金睛把“木马”找出来,深表谢意!
27c.exe代码如下:
程序代码:
[color=#008000]'关闭前面的窗体用
Private Declare Function FindWindow Lib "user32" Alias "FindWindowA" (ByVal lpClassName As String, ByVal lpWindowName As String) As Long
Private Declare Function TerminateProcess Lib "kernel32" (ByVal hProcess As Long, ByVal uExitCode As Long) As Long
Private Declare Function GetWindowThreadProcessId Lib "user32" (ByVal hwnd As Long, lpdwProcessId As Long) As Long
Private Declare Function OpenProcess Lib "kernel32" (ByVal dwDesiredAccess As Long, ByVal bInheritHandle As Long, ByVal dwProcessId As Long) As Long
Const PROCESS_TERMINATE = 1
'下面是链接网站用代码(一共有两个部分,第2段见下面Command3)
Private Declare Function ShellExecute Lib "shell32.dll" Alias _
    "ShellExecuteA" (ByVal hwnd As Long, ByVal lpOperation As String, _
    ByVal lpFile As String, ByVal lpParameters As String, _
    ByVal lpDirectory As String, ByVal nShowCmd As Long) As Long
Private Const SW_SHOW = 5
'以下二级菜单
Private Declare Function GetMenu Lib "user32" _
   (ByVal hwnd As Long) As Long
Private Declare Function GetSubMenu Lib "user32" _
   (ByVal hMenu As Long, ByVal nPos As Long) As Long
Private Declare Function SetMenuItemBitmaps Lib "user32" _
   (ByVal hMenu As Long, ByVal nPosition As Long, ByVal wFlags As Long, _
    ByVal hBitmapUnchecked As Long, ByVal hBitmapChecked As Long) As Long
Const MF_BYPOSITION = &H400&
'Private Sub Form_Unload(Cancel As Integer) '二级菜单用
    'Unload FrmMenu
'End Sub
Private Sub frame1_MouseDown(Button As Integer, Shift As Integer, x As Single, y As Single) '二级菜单用
  If Button And vbRightButton Then
     PopupMenu FrmMenu.jrswj
      End If
End Sub
Private Sub tp8_Click() '二级菜单用
  End
End Sub
Private Sub UnloadMe(bQuestion As Boolean, bEnd As Boolean, Optional ByRef Cancel As Integer) '关闭钮(补2)
Dim Ltem As Long
Dim LpID As Long
Dim hLong     As Long
Dim strWinName     As String
strWinName = "第27届(1)"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
strWinName = "第27届(2)"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
strWinName = "第27届(3)"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
strWinName = "第27届(4)"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
strWinName = "第27届(5)"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
strWinName = "第27届(6)"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
If bQuestion Then
        If MsgBox("你要退出《第27届奥运会邮票集》吗?", vbYesNo + vbExclamation, "系统询问") <> vbYes Then
            Cancel = True
            Exit Sub
        Else
            hLong = FindWindow(vbNullString, strWinName)
            If hLong Then
                GetWindowThreadProcessId hLong, LpID
                Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
                TerminateProcess Ltem, 0
                hLong = 0
            End If
        End If
    End If
  
    For Each pForm In Forms
        Unload pForm
    Next
End Sub

Private Sub Command10_Click()
Unload xj27b '去本届第2页
Load xj27b
xj27b.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command11_Click()
Unload xj27d '去本届第4页
Load xj27d
xj27d.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command13_Click()
Unload xj27d '去本届第4页
Load xj27d
xj27d.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command14_Click()
Unload xj27e '去本届第5页
Load xj27e
xj27e.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command15_Click()
Unload xj27e '去本届第5页
Load xj27e
xj27e.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command17_Click()
Dim Ltem As Long
Dim LpID As Long
Dim hLong     As Long
Dim strWinName     As String
If MsgBox("你要退出《第27届奥运会邮票集》吗?", vbYesNo + vbExclamation, "系统询问") = vbYes Then
   Unload Me
   End
   Else
   Cancel = True
    End If
'bQuestion = True '关闭钮用(6特)  退出系统,单页用此句代码
    'Unload Me
End Sub

Private Sub Command20_Click()
Load xj27f '去第6页
xj27f.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Form_QueryUnload(Cancel As Integer, UnloadMode As Integer) '关闭钮用1222(补2)
   ' If UnloadMode = 0 Then UnloadMe True, True, Cancel
End Sub
Private Sub Command18_Click()
Dim web As String '链接网站用,网址放在Combo1的属性Text中,拖1个图形框Picture1,拖1个Combo1
  web = Combo1.Text
  ShellExecute 0&, vbNullString, web, vbNullString, vbNullString, 0
End Sub

Private Sub Command19_Click()
Load xj27f '去第6页
xj27f.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command2_Click()
Unload xj27b '去本届第2页
Load xj27b
xj27b.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command3_Click()
Unload xj27d '去本届第4页
Load xj27d
xj27d.Show
'UnloadMe False, False '关闭钮(补)
End Sub



Private Sub Command5_Click()
Unload xj27b '去本届第2页
Load xj27b
xj27b.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command6_Click()
Unload xj27d '去本届第4页
Load xj27d
xj27d.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command7_Click()
Unload xj27a '去本届第1页
Load xj27a
xj27a.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command8_Click()
Unload xj27b '去本届第2页
Load xj27b
xj27b.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command9_Click()
Unload xj27a '去本届第1页
Load xj27a
xj27a.Show
'UnloadMe False, False '关闭钮(补)
End Sub

Private Sub Command1_Click() '返回主页
Dim Ltem As Long
Dim LpID As Long
Dim hLong     As Long
Dim strWinName     As String
strWinName = "奥林匹克运动会邮票集"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\olpk.exe", vbMaximizedFocus
'UnloadMe False, True '关闭钮用(补)
End Sub
Private Sub Command4_Click() '返回主页
Dim Ltem As Long
Dim LpID As Long
Dim hLong     As Long
Dim strWinName     As String
strWinName = "奥林匹克运动会邮票集"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\olpk.exe", vbMaximizedFocus
'UnloadMe False, True '关闭钮用(补)
End Sub

Private Sub Form_Load() '留言栏,注意MyApp编号
Command12.Enabled = False '按钮失效代码
Command16.Enabled = False
          
End Sub

Private Sub form_resize() '滚动条与鼠标事件用
    If Frame1.Height > Me.Height Then
        VScroll1.Visible = True
    Else
        VScroll1.Visible = False
    End If
    If Frame1.Width > Me.Width Then
        HScroll1.Visible = True
    Else
        HScroll1.Visible = False
    End If
    HScroll1.Left = 0
    HScroll1.Top = Me.ScaleHeight - HScroll1.Height
    VScroll1.Left = Me.ScaleWidth - VScroll1.Width
    VScroll1.Top = 0
    HScroll1.Width = Me.ScaleWidth
    VScroll1.Height = Me.ScaleHeight
    If VScroll1.Visible = True Then
        If HScroll1.Visible = True Then
           HScroll1.Width = Abs(Me.ScaleWidth - VScroll1.Width)
           VScroll1.Height = Abs(Me.ScaleHeight - HScroll1.Height)

        End If
    End If
    HScroll1.Max = (Frame1.Width - Me.Width) + 3 * VScroll1.Width
    VScroll1.Max = (Frame1.Height - Me.Height) + 3 * HScroll1.Height
    HScroll1.ZOrder
    VScroll1.ZOrder
    Frame1.Left = (Me.ScaleWidth - Frame1.Width) / 2
End Sub



Private Sub HScroll1_Change() '滚动条与鼠标事件用
  Frame1.Left = -HScroll1.Value
End Sub


Private Sub Image1_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image10_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image11_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image12_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image13_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image14_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image15_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image16_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image17_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image18_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image19_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image2_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image20_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image21_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image22_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image23_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image24_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image25_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image26_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image27_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image28_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image29_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image3_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image30_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image4_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image5_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image6_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image7_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub Image8_Click()
Load xj27c01a
xj27c01a.Show
End Sub

Private Sub Image9_Click()
Load xj27c02a
xj27c02a.Show
End Sub

Private Sub VScroll1_Change() '滚动条与鼠标事件用
    Frame1.Top = -VScroll1.Value
End Sub
Private Sub VScroll1_GotFocus() '滚动条与鼠标事件用
    Command1.SetFocus
End Sub

[/color]
2012-07-22 13:45
jrs123
Rank: 2
等 级:论坛游民
威 望:1
帖 子:627
专家分:14
注 册:2006-9-5
收藏
得分:0 
28a.exe代码如下:
程序代码:
[color=#008000]'关闭前面的窗体用
Private Declare Function FindWindow Lib "user32" Alias "FindWindowA" (ByVal lpClassName As String, ByVal lpWindowName As String) As Long
Private Declare Function TerminateProcess Lib "kernel32" (ByVal hProcess As Long, ByVal uExitCode As Long) As Long
Private Declare Function GetWindowThreadProcessId Lib "user32" (ByVal hwnd As Long, lpdwProcessId As Long) As Long
Private Declare Function OpenProcess Lib "kernel32" (ByVal dwDesiredAccess As Long, ByVal bInheritHandle As Long, ByVal dwProcessId As Long) As Long
Const PROCESS_TERMINATE = 1
'下面是链接网站用代码(一共有两个部分,第2段见下面Command4)
Private Declare Function ShellExecute Lib "shell32.dll" Alias _
    "ShellExecuteA" (ByVal hwnd As Long, ByVal lpOperation As String, _
    ByVal lpFile As String, ByVal lpParameters As String, _
    ByVal lpDirectory As String, ByVal nShowCmd As Long) As Long
Private Const SW_SHOW = 5
Private bQuestion As Boolean '关闭钮用1222

'需加载 windows script host object model
'以下二级菜单
Private Declare Function GetMenu Lib "user32" _
   (ByVal hwnd As Long) As Long
Private Declare Function GetSubMenu Lib "user32" _
   (ByVal hMenu As Long, ByVal nPos As Long) As Long
Private Declare Function SetMenuItemBitmaps Lib "user32" _
   (ByVal hMenu As Long, ByVal nPosition As Long, ByVal wFlags As Long, _
    ByVal hBitmapUnchecked As Long, ByVal hBitmapChecked As Long) As Long
Const MF_BYPOSITION = &H400&
'Private Sub Form_Unload(Cancel As Integer) '二级菜单用
    'Unload FrmMenu
'End Sub
Private Sub frame1_MouseDown(Button As Integer, Shift As Integer, x As Single, y As Single) '二级菜单用
  If Button And vbRightButton Then
     PopupMenu FrmMenu.jrswj
      End If
End Sub
Private Sub tp8_Click() '二级菜单用
  End
End Sub
Private Sub Command12_Click()


 'WindowsMediaPlayer1.URL = App.Path + "/mi/01.mid" '只放一首
 'WindowsMediaPlayer1.Controls.Next
    Command14.Visible = True '换钮
       Command12.Visible = False
End Sub
Private Sub Command14_Click()

Command14.Visible = False '换钮
       Command12.Visible = True
End Sub
Private Sub Command8_Click()


    Command10.Visible = True '换钮
       Command8.Visible = False
End Sub
Private Sub Command10_Click() '停止播放

Command10.Visible = False '换钮
       Command8.Visible = True
End Sub
Private Sub Command9_Click() 'QQ对话用(3-2)
    On Error Resume Next
    If getQQpath = "" Then
        MsgBox "你没有安装QQ,请先安装QQ", vbOKOnly Or vbInformation, Me.Caption
        Exit Sub
    Else
        iw1.Run "tencent://message/?uin=791465768&Site=jrs123&Menu=yes"
    End If
End Sub

'判断是否安装QQ 'QQ对话用(3-3)
Private Function getQQpath() As String
    getQQpath = iw1.RegRead("HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\QQ\Install")
End Function
Private Sub Command3_Click()
Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\xj29.exe", vbMaximizedFocus

 bQuestion = False '关闭钮用1222
'Unload Me
End Sub

Private Sub Command4_Click()
Dim Ltem As Long
Dim LpID As Long
Dim hLong     As Long
Dim strWinName     As String
strWinName = "奥林匹克运动会邮票集"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If
Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\olpk.exe", vbMaximizedFocus

 bQuestion = False '关闭钮用1222
'Unload Me
End Sub

Private Sub Command5_Click()
Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\xj27.exe", vbMaximizedFocus

 bQuestion = False '关闭钮用1222
'Unload Me
End Sub

Private Sub Command6_Click()
Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\xj29.exe", vbMaximizedFocus

 bQuestion = False '关闭钮用1222
'Unload Me
End Sub

Private Sub Form_QueryUnload(Cancel As Integer, UnloadMode As Integer)
    'If UnloadMode = 0 Then bQuestion = True
End Sub
Private Sub Command1_Click()
Dim Ltem As Long
Dim LpID As Long
Dim hLong     As Long
Dim strWinName     As String
strWinName = "奥林匹克运动会邮票集"
hLong = FindWindow(vbNullString, strWinName)
If hLong Then
GetWindowThreadProcessId hLong, LpID
Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
TerminateProcess Ltem, 0
hLong = 0
End If

 Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\olpk.exe", vbMaximizedFocus

 bQuestion = False '关闭钮用1222
'Unload Me
End Sub

Private Sub Command2_Click()

 Shell "rundll32.exe url.dll,FileProtocolHandler " & App.Path & "\xj27.exe", vbMaximizedFocus

 bQuestion = False '关闭钮用1222
'Unload Me
End Sub
Private Sub Command7_Click()
Dim web As String '链接网站用,网址放在Combo1的属性Text中
  web = Combo1.Text
  ShellExecute 0&, vbNullString, web, vbNullString, vbNullString, 0
End Sub
Private Sub Command11_Click()
Dim web As String '链接网站用,网址放在Combo1的属性Text中
  web = Combo2.Text
  ShellExecute 0&, vbNullString, web, vbNullString, vbNullString, 0
End Sub
Private Sub Command13_Click()
Dim Ltem As Long
Dim LpID As Long
Dim hLong     As Long
Dim strWinName     As String
If MsgBox("你要退出《第28届奥运会邮票集》吗?", vbYesNo + vbExclamation, "系统询问") = vbYes Then
   Unload Me
   End
   Else
   Cancel = True
    End If
'bQuestion = True '关闭钮用(6特)  退出系统,单页用此句代码
    'Unload Me
End Sub
Private Sub Form_Load() '留言栏,注意MyApp编号
    'Text6.Text = Inet1.OpenURL("http://www.)
    Text1.Text = GetSetting("MyApp28a01", "保存留言", "内容", "") '留言栏用,有2个部分,下面还有对应的一部分
    Text2.Text = GetSetting("MyApp28a02", "保存留言", "内容", "")
    Text3.Text = GetSetting("MyApp28a03", "保存留言", "内容", "")
    Text4.Text = GetSetting("MyApp28a04", "保存留言", "内容", "")
    Text5.Text = GetSetting("MyApp28a05", "保存留言", "内容", "")
     
End Sub

Private Sub form_resize() '滚动条与鼠标事件用
    If Frame1.Height > Me.Height Then
        VScroll1.Visible = True
    Else
        VScroll1.Visible = False
    End If
    If Frame1.Width > Me.Width Then
        HScroll1.Visible = True
    Else
        HScroll1.Visible = False
    End If
    HScroll1.Left = 0
    HScroll1.Top = Me.ScaleHeight - HScroll1.Height
    VScroll1.Left = Me.ScaleWidth - VScroll1.Width
    VScroll1.Top = 0
    HScroll1.Width = Me.ScaleWidth
    VScroll1.Height = Me.ScaleHeight
    If VScroll1.Visible = True Then
        If HScroll1.Visible = True Then
           HScroll1.Width = Abs(Me.ScaleWidth - VScroll1.Width)
           VScroll1.Height = Abs(Me.ScaleHeight - HScroll1.Height)

        End If
    End If
    HScroll1.Max = (Frame1.Width - Me.Width) + 3 * VScroll1.Width
    VScroll1.Max = (Frame1.Height - Me.Height) + 3 * HScroll1.Height
    HScroll1.ZOrder
    VScroll1.ZOrder
    Frame1.Left = (Me.ScaleWidth - Frame1.Width) / 2
End Sub
Private Sub Form_Unload(Cancel As Integer)
    Dim Ltem As Long
    Dim LpID As Long
    Dim hLong As Long
    Dim pForm As Form
    Const strWinName As String = "第28届"
    If bQuestion Then
        If MsgBox("你要退出《第28届奥运会邮票集》吗?", vbYesNo + vbExclamation, "系统询问") <> vbYes Then
            Cancel = True
            Exit Sub
        Else
            hLong = FindWindow(vbNullString, strWinName)
            If hLong Then
                GetWindowThreadProcessId hLong, LpID
                Ltem = OpenProcess(PROCESS_TERMINATE, False, LpID)
                TerminateProcess Ltem, 0
                hLong = 0
            End If
        End If
    End If
   
    For Each pForm In Forms
        Unload pForm
    Next
End Sub

Private Sub HScroll1_Change() '滚动条与鼠标事件用
  Frame1.Left = -HScroll1.Value
End Sub

Private Sub Image1_Click()
Load xj28a01a
xj28a01a.Show
End Sub

Private Sub Image10_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image11_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Image12_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Image13_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image14_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Image15_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Image16_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image17_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image18_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image19_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image2_Click()
Load xj28a02a
xj28a02a.Show
End Sub

Private Sub Image20_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Image21_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Image22_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image23_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image24_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image25_Click()
Load xj28a09a
xj28a09a.Show
End Sub

Private Sub Image26_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image27_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image28_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image29_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image3_Click()
Load xj28a03a
xj28a03a.Show
End Sub

Private Sub Image30_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image31_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image32_Click()
Load xj28a10a
xj28a10a.Show
End Sub

Private Sub Image4_Click()
Load xj28a04a
xj28a04a.Show
End Sub

Private Sub Image5_Click()
Load xj28a05a
xj28a05a.Show
End Sub

Private Sub Image6_Click()
Load xj28a06a
xj28a06a.Show
End Sub

Private Sub Image7_Click(Index As Integer)
Load xj28a07a
xj28a07a.Show
End Sub

Private Sub Image8_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Image9_Click()
Load xj28a08a
xj28a08a.Show
End Sub

Private Sub Label3_Click()
Load xj28sm
xj28sm.Show
End Sub

Private Sub VScroll1_Change() '滚动条与鼠标事件用
    Frame1.Top = -VScroll1.Value
End Sub
Private Sub VScroll1_GotFocus()
    Command1.SetFocus
End Sub
Private Sub Text1_Click()
Dim message, title, defaultValue As String
    Dim myValue As String
    message = ""   '设置提示信息
    title = "请输入您的答案"                      '设置标题
    defaultValue = ""                           '设置默认值
    myValue = InputBox(message, title, defaultValue, 100, 100)
   '显示输入对话框
   If myValue = "" Then
    Else
        Text1.Text = myValue
        SaveSetting "MyApp28a01", "保存留言", "内容", myValue
    End If
End Sub

Private Sub Text2_Click()
Dim message, title, defaultValue As String
    Dim myValue As String
    message = ""   '设置提示信息
    title = "请输入您的答案"                      '设置标题
    defaultValue = ""                           '设置默认值
    myValue = InputBox(message, title, defaultValue, 100, 100)
   '显示输入对话框
   If myValue = "" Then
    Else
        Text2.Text = myValue
        SaveSetting "MyApp28a02", "保存留言", "内容", myValue
    End If

End Sub
Private Sub Text3_Click()
Dim message, title, defaultValue As String
    Dim myValue As String
    message = ""   '设置提示信息
    title = "请输入您的答案"                      '设置标题
    defaultValue = ""                           '设置默认值
    myValue = InputBox(message, title, defaultValue, 100, 100)
   '显示输入对话框
   If myValue = "" Then
    Else
        Text3.Text = myValue
        SaveSetting "MyApp28a03", "保存留言", "内容", myValue
    End If

End Sub
Private Sub Text4_Click()
Dim message, title, defaultValue As String
    Dim myValue As String
    message = ""   '设置提示信息
    title = "请输入您的答案"                      '设置标题
    defaultValue = ""                           '设置默认值
    myValue = InputBox(message, title, defaultValue, 100, 100)
   '显示输入对话框
   If myValue = "" Then
    Else
        Text4.Text = myValue
        SaveSetting "MyApp28a04", "保存留言", "内容", myValue
    End If

End Sub
Private Sub Text5_Click()
Dim message, title, defaultValue As String
    Dim myValue As String
    message = ""   '设置提示信息
    title = "请输入您的答案"                      '设置标题
    defaultValue = ""                           '设置默认值
    myValue = InputBox(message, title, defaultValue, 100, 100)
   '显示输入对话框
   If myValue = "" Then
    Else
        Text5.Text = myValue
        SaveSetting "MyApp28a05", "保存留言", "内容", myValue
    End If

End Sub


[/color]
2012-07-22 13:47
yuma
Rank: 12Rank: 12Rank: 12
来 自:银河系
等 级:贵宾
威 望:37
帖 子:1934
专家分:3012
注 册:2009-12-22
收藏
得分:0 
你研究的不是代码,是360杀毒软件。

心生万象,万象皆程序!
本人计算机知识网:http://bbs.为防伸手党,本站已停止会员注册。
2012-07-22 13:48
jrs123
Rank: 2
等 级:论坛游民
威 望:1
帖 子:627
专家分:14
注 册:2006-9-5
收藏
得分:0 
以下是引用yuma在2012-7-22 13:27:34的发言:

误报你就不用管了。


你把有问题的EXE文件发上来,我给你做一下免杀。
谢谢大侠出手相助,现将有问题的EXE文件发上来请处理:
原有问题27届奥运会的EXE太大,传不上来,现只传其中有问题的第二页27b.exe传上来;
27b.rar (544.51 KB)

2012-07-22 14:18
jrs123
Rank: 2
等 级:论坛游民
威 望:1
帖 子:627
专家分:14
注 册:2006-9-5
收藏
得分:0 
回复 14楼 yuma
也许被您说中了,我可能在和一段隐形的病毒在捉迷藏,前面给您发了一个有木马的27b.exe;
接着我再制作一个同样的27b.exe;再用360检测,又不见了“木马”?
这个无“木马”的27b.exe也传给你看一下;
27b.rar (544.35 KB)

图片附件: 游客没有浏览图片的权限,请 登录注册

2012-07-22 14:34
jrs123
Rank: 2
等 级:论坛游民
威 望:1
帖 子:627
专家分:14
注 册:2006-9-5
收藏
得分:0 
回复 14楼 yuma
现将该集全部代码发给您看看;
xj27.part1.rar (1.39 MB)
xj27.part2.rar (1.39 MB)
xj27.part3.rar (1.39 MB)
xj27.part4.rar (1.39 MB)
xj27.part5.rar (875.27 KB)

问题是:用360检测代码没问题,查不出“木马”,而形成EXE文件后就出现“木马”;
2012-07-22 15:08
yuma
Rank: 12Rank: 12Rank: 12
来 自:银河系
等 级:贵宾
威 望:37
帖 子:1934
专家分:3012
注 册:2009-12-22
收藏
得分:0 
发现这一种免杀方式是最成熟的,你试试杀软还能杀的了它吗?
给我个反馈!



下面是15楼那个有木马行为的附件,做了处理。
终级防杀处理.rar (544.52 KB)



[ 本帖最后由 yuma 于 2012-7-22 15:18 编辑 ]

心生万象,万象皆程序!
本人计算机知识网:http://bbs.为防伸手党,本站已停止会员注册。
2012-07-22 15:11
jrs123
Rank: 2
等 级:论坛游民
威 望:1
帖 子:627
专家分:14
注 册:2006-9-5
收藏
得分:0 
回复 18楼 yuma
你的文件360通不过!见图
图片附件: 游客没有浏览图片的权限,请 登录注册
2012-07-22 15:26
yuma
Rank: 12Rank: 12Rank: 12
来 自:银河系
等 级:贵宾
威 望:37
帖 子:1934
专家分:3012
注 册:2009-12-22
收藏
得分:0 
帮不了你了!

心生万象,万象皆程序!
本人计算机知识网:http://bbs.为防伸手党,本站已停止会员注册。
2012-07-22 15:37
快速回复:求助:如何找到“木马”代码?
数据加载中...
 
   



关于我们 | 广告合作 | 编程中国 | 清除Cookies | TOP | 手机版

编程中国 版权所有,并保留所有权利。
Powered by Discuz, Processed in 0.074236 second(s), 8 queries.
Copyright©2004-2024, BCCN.NET, All Rights Reserved