查看: 4459|回复: 23
收起左侧

[病毒样本] 流氓之王万能搜索(WNSO)样本[FC2FF7]

[复制链接]
chenrui19930
发表于 2007-8-7 13:45:54 | 显示全部楼层 |阅读模式
试试啊无法删除,谁敢跑跑?

[ 本帖最后由 chenrui19930 于 2007-8-7 21:37 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
pluto1313
发表于 2007-8-7 13:50:09 | 显示全部楼层
何以可怕?
chenrui19930
 楼主| 发表于 2007-8-7 13:50:44 | 显示全部楼层

回复 #2 pluto1313 的帖子

不能删掉也!
solcroft
发表于 2007-8-7 13:56:55 | 显示全部楼层
呼呼呼~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
1688388728
发表于 2007-8-7 14:00:13 | 显示全部楼层
感染: not-a-virus:AdWare.Win32.Dm.y
文件: find.dll
目录: C:\Documents and Settings\Administrator\Local Settings\Temp
进程: MPSVC2.exe
The EQs
发表于 2007-8-7 14:05:25 | 显示全部楼层
ESS好可爱的窗口。。。尤其是那个感叹号
The EQs
发表于 2007-8-7 14:06:26 | 显示全部楼层
Scan performed at: 2007-8-7 14:05:48
Scanning Log
NOD32 version 2440 (20070806) NT
Command line: C:\Documents and Settings\EQ2\桌面\wnso
Operating memory - is OK

Date: 7.8.2007  Time: 14:05:53
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\wnso\
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?find.dll - Win32/Adware.DM application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?SoBar.dll - Win32/Adware.DM application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?wsorem.dll - Win32/Adware.DM application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?wsomain.exe - Win32/Adware.DM application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?citing.dll - Win32/Adware.DM application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?RunExe.exe - Win32/Adware.DM application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?roreg.sys - Win32/Adware.WSearch application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?front.sys - Win32/Adware.WSearch application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\wnso\wnso\RGGZS\RG.exe ?NSIS ?main.dll - Win32/Adware.DM application - was a part of the deleted object
Number of scanned files: 23
Number of threats found: 9
Number of files cleaned: 1
Time of completion: 14:05:54 Total scanning time: 1 sec (00:00:01)
微点卫士
发表于 2007-8-7 14:14:51 | 显示全部楼层
驱逐舰挂

微点:
木马名称:Trojan-Clicker.Win32.Agent.gk

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\WSOMAIN.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-Downloader.Win32.Agent.dza

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RUNEXE.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-Clicker.Win32.Agent.fl

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\ROREG.SYS
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-Clicker.Win32.Agent.fp

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\FRONT.SYS
是木马程序!
已成功阻止其运行,是否要删除此文件?
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\WNSO\RGGZS\RG.EXE
协议类型:TCP
本地地址:0.0.0.0
本地端口:1641
远端地址:218.83.175.154(上海)
远端端口:80
taihuxian
发表于 2007-8-7 15:24:51 | 显示全部楼层
Malicious code found in file C:\Documents and Settings\user\桌面\wnso[1]\wnso\RGGZS\RG.exe.
Infection: Rootkit.Win32.Agent.fs
Action: failed.
chenrui19930
 楼主| 发表于 2007-8-7 15:27:43 | 显示全部楼层

我说,怎么没人敢安装呢?试下啊 [:27:]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 01:23 , Processed in 0.161696 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表