Ejemplo n.º 1
0
        static ProgramStartList malwareStartList(int max_running_time)
        {
            ProgramStartList descr_list;

            #region Program start description for windows programs cmd msimn etc
            descr_list = new ProgramStartList();
            descr_list.last().image_dir        = "Z:\\Malware\\Launch\\Virus.Win32.Parite.a";
            descr_list.last().image_filename   = "Virus.Win32.Parite.a_spooIsv.exe";
            descr_list.last().max_running_time = max_running_time;
            descr_list += ProgramStartDescription.findExecutablesRecursive("z:\\Malware\\Launch");

            //descr_list.last().command_line = "";

            //descr_list += new ProgramStartDescription();
            //descr_list.last().image_dir = "C:\\Malware\\Virus.Win32.Virut.av";
            //descr_list.last().image_filename = "explorer.exe";
            //descr_list.last().command_line = "";

            //descr_list.last().image_dir = "C:\\Malware\\Worm.Win32.AutoRun.afdh";
            //descr_list.last().image_filename = "sEtuP.exe";
            //descr_list.last().command_line = "";
            //descr_list.last().max_running_time = max_running_time;
            //descr_list += new ProgramStartDescription();
            //descr_list.last().image_dir = "C:\\Program Files\\Internet Explorer";
            //descr_list.last().image_filename = "iexplore.exe";
            //descr_list.last().command_line = " http://bbc.com";
            //descr_list.last().max_running_time = max_running_time;
            #endregion
            return(descr_list);
        }
Ejemplo n.º 2
0
        static ProgramStartList windowsProgramStartList(int max_running_time)
        {
            ProgramStartList descr_list = new ProgramStartList();

            #region Program start description for windows programs cmd msimn etc
            descr_list.last().image_dir        = "C:\\Windows\\system32";
            descr_list.last().image_filename   = "cmd.exe";
            descr_list.last().command_line     = " /c dir";
            descr_list.last().max_running_time = max_running_time;
            descr_list += " /c dir c:\\Windows\\system32";
            descr_list += " /c dir c:\\Windows";
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\Outlook Express";
            descr_list.last().image_filename   = "msimn.exe";
            descr_list.last().command_line     = "";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\Internet Explorer";
            descr_list.last().image_filename   = "iexplore.exe";
            descr_list.last().command_line     = " http://bbc.com";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\Opera";
            descr_list.last().image_filename   = "opera.exe";
            descr_list.last().command_line     = " http://bbc.com";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\Far";
            descr_list.last().image_filename   = "far.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\Messenger";
            descr_list.last().image_filename   = "msmsgs.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\Movie Maker";
            descr_list.last().image_filename   = "moviemk.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\MSN\\MSNCoreFiles";
            descr_list.last().image_filename   = "msn6.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\Windows Media Player";
            descr_list.last().image_filename   = "wmplayer.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Program Files\\WinRar";
            descr_list.last().image_filename   = "WinRar.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Windows";
            descr_list.last().image_filename   = "explorer.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += descr_list.last().getExecutables();
            descr_list += new ProgramStartDescription();
            descr_list.last().image_dir        = "C:\\Windows\\system32";
            descr_list.last().image_filename   = "accwiz.exe";
            descr_list.last().command_line     = " ";
            descr_list.last().max_running_time = max_running_time;
            descr_list += descr_list.last().getExecutables();
            //descr_list += new ProgramStartDescription();
            //descr_list.last().image_dir = "C:\\Documents and Settings\\amd\\Desktop";
            //descr_list.last().image_filename = "Test_Files_Handles.exe";
            ////descr_list.last().command_line = " 50 10000";
            //descr_list.last().command_line = " ";
            //descr_list.last().max_running_time = 60 * 4;
            #endregion
            return(descr_list);
        }