楼主: nosferatu
收起左侧

[病毒样本] 红伞一个

[复制链接]
hyxuzhimin
发表于 2008-1-24 12:52:40 | 显示全部楼层
大蜘蛛报, ESS过
觅寒枚
发表于 2008-1-24 13:13:52 | 显示全部楼层
不是病毒
chenyilong58
发表于 2008-1-24 14:43:40 | 显示全部楼层
哈哈,现过卡巴,在过红伞,最后FS搞定
qigang
发表于 2008-1-24 20:18:35 | 显示全部楼层
广告插件!
tracydk
发表于 2008-1-24 20:20:05 | 显示全部楼层
不是病毒
xiaohf
发表于 2008-1-24 20:42:56 | 显示全部楼层
2008-01-24 20:41:44        应用程序保护(修改其它进程内存)     操作:阻止
进程路径:C:\Documents and Settings\xiaohf\Local Settings\Temp\Rar$EX00.203\wfpdisable.exe
目标进程:C:\WINDOWS\system32\winlogon.exe
NobleT
发表于 2008-1-24 20:44:32 | 显示全部楼层
Scan name: [Custom Scan]
Path to scan: F:\|

Normal scan
Also scan: Inside subfolders, Compressed files, Streams

Scan started: 2008-1-24, 20:43:48
---------------------------------------------------------------------

[Clean]        Boot sector on drive F:
[Clean]        Boot sector on drive E:
[Clean]        Boot sector on drive D:
[Clean]        Boot sector on drive G:
[Clean]        Boot sector on drive C:
[Clean]        Master Boot Record on disk 0
[Clean]        F:\Diskeeper\IfaastMon.dat
[Clean]        F:\Diskeeper\IFaastRegions.dat
[Clean]        F:\RECYCLER\S-1-5-21-1606980848-1390067357-839522115-500\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-1606980848-1390067357-839522115-500\INFO2
[Clean]        F:\RECYCLER\S-1-5-21-343818398-1123561945-1801674531-500\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-343818398-1123561945-1801674531-500\INFO2
[Clean]        F:\RECYCLER\S-1-5-21-746137067-725345543-839522115-1003\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-746137067-725345543-839522115-1003\INFO2
[Clean]        F:\RECYCLER\S-1-5-21-776561741-651377827-725345543-500\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-776561741-651377827-725345543-500\INFO2
[Clean]        F:\RECYCLER\S-1-5-21-776561741-854245398-725345543-500\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-776561741-854245398-725345543-500\INFO2
[Clean]        F:\RECYCLER\S-1-5-21-789336058-1292428093-682003330-500\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-789336058-1292428093-682003330-500\INFO2
[Clean]        F:\RECYCLER\S-1-5-21-790525478-1844823847-839522115-500\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-790525478-1844823847-839522115-500\INFO2
[Found application]         <W32/Wfpdisable.A (exact, not disinfectable)>        F:\wfpdisable.rar->wfpdisable.exe
[Contains infected objects]        F:\wfpdisable.rar
[Quarantined]        F:\wfpdisable.rar->wfpdisable.exe

---------------------------------------------------------------------
Scan ended:        2008-1-24, 20:43:49
Duration:        0:00:01

Scan result:

Scanned files:                 23
Infected objects:         1
Disinfected objects:         0
Quarantined files:         1
zwl2828
发表于 2008-1-24 21:51:45 | 显示全部楼层
000054F8   004060F8      0   SeDebugPrivilege
00005528   00406128      0   -------------------------------------------------
0000555C   0040615C      0   (C) 2003 andreas@atstake.com
0000557C   0040617C      0   until next reboot
00005590   00406190      0   wfpdisable - Disables Windows File Protection
000055C0   004061C0      0   WFP disabled.
000055CE   004061CE      0   Reboot machine to re-enable it.
000055F0   004061F0      0   WaitForSingleObject failed
0000560C   0040620C      0   CreateRemoteThread failed %d
0000562C   0040622C      0   OpenProcess failed %d
00005644   00406244      0   Could not enable debug privileges
00005668   00406268      0   GetProcAddress failed
00005680   00406280      0   sfc.dll could not be loaded
000056A0   004062A0      0   sfc.dll
000056D9   004062D9      0    (8PX
000056E1   004062E1      0   700WP
000056F9   004062F9      0   ppxxxx
00005724   00406324      0   (null)
0000572C   0040632C      0   CorExitProcess
0000573C   0040633C      0   mscoree.dll
00005748   00406348      0   runtime error
0000575C   0040635C      0   TLOSS error
0000576C   0040636C      0   SING error
0000577C   0040637C      0   DOMAIN error
ngh55
发表于 2008-1-25 10:11:36 | 显示全部楼层
avast  passed
长空之鹰
发表于 2008-1-25 13:26:48 | 显示全部楼层
小a P版 MISS
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-25 21:23 , Processed in 0.103049 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表