楼主: firefox3
收起左侧

[可疑文件] 挂马集团开发出一系列wgsdgsdgdsgsd产品,现在给大家介绍一下wgsdgsdgdsgsd的截屏功能

  [复制链接]
firefox3
 楼主| 发表于 2012-12-18 23:34:10 | 显示全部楼层
hx1997 发表于 2012-12-18 23:31
行行行 我好心告诉你们  双击就行了
以后我就不说了 你们自己琢磨  我走了

真小气  我都没说什么
hx1997
发表于 2012-12-18 23:36:59 | 显示全部楼层
firefox3 发表于 2012-12-18 23:34
真小气  我都没说什么

我提醒一句就有人说我横
我只不过以彼之道还施彼身罢了
firefox3
 楼主| 发表于 2012-12-18 23:38:25 | 显示全部楼层
hx1997 发表于 2012-12-18 23:36
我提醒一句就有人说我横
我只不过以彼之道还施彼身罢了

我错了 你永远都是真理
hx1997
发表于 2012-12-18 23:41:36 | 显示全部楼层
firefox3 发表于 2012-12-18 23:38
我错了 你永远都是真理

知道就好

样本猎人 你每天怎么这么多时间 不上课又不上班的??
darkwolf_99
发表于 2012-12-18 23:44:09 | 显示全部楼层
本帖最后由 darkwolf_99 于 2012-12-18 23:45 编辑
hx1997 发表于 2012-12-18 23:27
死板 这是 EXE!!


惯性思维了,大佬教训的是



Created:      2012/12/18 23:29:48
Summary:      Program Guard: wgsdgsdgdsgsd.exe
Description:  C:\Windows\explorer.exe -> C:\1\wgsdgsdgdsgsd.exe
Event type:   Program Guard(9)
Event action: Allowed(2)

Created:      2012/12/18 23:30:05
Summary:      Program Guard: wgsdgsdgdsgsd.exe -> fela.exe
Description:  C:\1\wgsdgsdgdsgsd.exe wants to create executable file C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe
Event type:   Suspicious file(13)
Event action: Allowed(2)

Created:      2012/12/18 23:30:27
Summary:      Program Guard: wgsdgsdgdsgsd.exe -> fela.exe
Description:  C:\1\wgsdgsdgdsgsd.exe(2712) wants to start C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe(2396)
Event type:   Program Guard(9)
Event action: Allowed(2)

Created:      2012/12/18 23:30:35
Summary:      Program Guard: fela.exe
Description:  C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe -> C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe
Event type:   Program Guard(9)
Event action: Allowed(2)

Created:      2012/12/18 23:30:42
Summary:      Program Guard: wgsdgsdgdsgsd.exe -> tmp4df0ea02.bat
Description:  C:\1\wgsdgsdgdsgsd.exe wants to create executable file C:\Users\Evangeline\AppData\Local\Temp\tmp4df0ea02.bat
Event type:   Suspicious file(13)
Event action: Allowed(2)

Created:      2012/12/18 23:30:48
Summary:      Program Guard: fela.exe -> dwm.exe
Description:  C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe(2252) wants to open C:\Windows\System32\dwm.exe(1184)
Event type:   Program Guard(9)
Event action: Blocked(3)

Created:      2012/12/18 23:30:48
Summary:      Program Guard: kernel event
Description:  OADriver: OB_OPERATION_HANDLE_CREATE, 2252 -> 1184, Mask: 147A - 1410
Event type:   Kernel event(26)
Event action: None(1)
Processes:
  PID:    1184        Name: dwm.exe
  PID:    2252        Name: fela.exe

Created:      2012/12/18 23:30:55
Summary:      Program Guard: wgsdgsdgdsgsd.exe -> tmp4df0ea02.bat
Description:  C:\1\wgsdgsdgdsgsd.exe wants to modify executable file C:\Users\Evangeline\AppData\Local\Temp\tmp4df0ea02.bat
Event type:   Suspicious file(13)
Event action: Allowed(2)

Created:      2012/12/18 23:30:56
Summary:      Program Guard: cmd.exe
Description:  C:\Windows\SysWOW64\cmd.exe was trusted automatically.
Event type:   Program Guard(22)
Event action: Trusted(6)

Created:      2012/12/18 23:30:58
Summary:      Program Guard: fela.exe -> explorer.exe
Description:  C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe(2252) wants to open C:\Windows\explorer.exe(1224)
Event type:   Program Guard(9)
Event action: Blocked(3)


Created:      2012/12/18 23:30:58
Summary:      Program Guard: kernel event
Description:  OADriver: OB_OPERATION_HANDLE_CREATE, 2252 -> 1224, Mask: 147A - 1410
Event type:   Kernel event(26)
Event action: None(1)
Processes:
  PID:    1224        Name: explorer.exe
  PID:    2252        Name: fela.exe


Created:      2012/12/18 23:31:02
Summary:      Program Guard: wgsdgsdgdsgsd.exe -> cmd.exe
Description:  C:\1\wgsdgsdgdsgsd.exe(2712) wants to start C:\Windows\SysWOW64\cmd.exe(2080)
Event type:   Program Guard(9)
Event action: Blocked(3)

Created:      2012/12/18 23:31:08
Summary:      Program Guard: fela.exe -> VMwareTray.exe
Description:  C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe(2252) wants to open C:\Program Files\VMware\VMware Tools\VMwareTray.exe(1396)
Event type:   Program Guard(9)
Event action: Blocked(3)

Created:      2012/12/18 23:31:08
Summary:      Program Guard: kernel event
Description:  OADriver: OB_OPERATION_HANDLE_CREATE, 2252 -> 1396, Mask: 147A - 1410
Event type:   Kernel event(26)
Event action: None(1)
Processes:
  PID:    1396        Name: VMwareTray.exe
  PID:    2252        Name: fela.exe

Created:      2012/12/18 23:31:12
Summary:      Program Guard: fela.exe -> vmtoolsd.exe
Description:  C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe(2252) wants to open C:\Program Files\VMware\VMware Tools\vmtoolsd.exe(1420)
Event type:   Program Guard(9)
Event action: Blocked(3)

Created:      2012/12/18 23:31:12
Summary:      Program Guard: kernel event
Description:  OADriver: OB_OPERATION_HANDLE_CREATE, 2252 -> 1420, Mask: 147A - 1410
Event type:   Kernel event(26)
Event action: None(1)
Processes:
  PID:    1420        Name: vmtoolsd.exe
  PID:    2252        Name: fela.exe

Created:      2012/12/18 23:31:18
Summary:      Program Guard: fela.exe -> SpyShelter.exe
Description:  C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe(2252) wants to open C:\Program Files (x86)\SpyShelter Firewall\SpyShelter.exe(1436)
Event type:   Program Guard(9)
Event action: Blocked(3)

每个进程都要摸一遍,阻止摸所有进程,再继续

Created:      2012/12/18 23:31:41
Summary:      Autorun detected: fela.exe
Description:  C:\Users\Evangeline\AppData\Roaming\Voqail\fela.exe
Event type:   Autorun(10)
Event action: Blocked(3)


然后是联网,全阻止

最后是
Created:      2012/12/18 23:31:44
Summary:      Program Guard: kernel event
Description:  OADriver: Registry, PID: 2252, Act:  8, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-2706782817-1821914486-2580403393-1000\Software\Microsoft\Windows\CurrentVersion\Run\Soevy - Deny (rule)
Event type:   Kernel event(26)
Event action: None(1)
Processes:
  PID:    2252        Name: fela.exe

Created:      2012/12/18 23:31:49
Summary:      Program Guard: kernel event
Description:  OADriver: OB_OPERATION_HANDLE_CREATE, 2252 -> 1184, Mask: 147A - 1410
Event type:   Kernel event(26)
Event action: None(1)
Processes:
  PID:    1184        Name: dwm.exe
  PID:    2252        Name: fela.exe

fela.exe进程不停的试上面的动作,导致彪U,过了几分钟没反应,任务管理器结束进程,重启无异常

这种exe的应该更容易拦截些吧

评分

参与人数 1人气 +1 收起 理由
hx1997 + 1 俺是大佬哇哈哈哈哈

查看全部评分

firefox3
 楼主| 发表于 2012-12-18 23:46:05 | 显示全部楼层
hx1997 发表于 2012-12-18 23:41
知道就好

样本猎人 你每天怎么这么多时间 不上课又不上班的??

养老中
hx1997
发表于 2012-12-18 23:48:14 | 显示全部楼层
firefox3 发表于 2012-12-18 23:46
养老中

老爷爷(奶奶?)晚安
firefox3
 楼主| 发表于 2012-12-18 23:50:45 | 显示全部楼层
hx1997 发表于 2012-12-18 23:48
老爷爷(奶奶?)晚安

晚安
darkwolf_99
发表于 2012-12-18 23:52:20 | 显示全部楼层
firefox3 发表于 2012-12-18 23:50
晚安

这种没那种好玩,

晚安,兔
firefox3
 楼主| 发表于 2012-12-18 23:53:23 | 显示全部楼层
darkwolf_99 发表于 2012-12-18 23:52
这种没那种好玩,

晚安,兔

晚安
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-2 16:56 , Processed in 0.123785 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表