查看: 2755|回复: 15
收起左侧

[病毒样本] 1个

[复制链接]
无尽藏海
发表于 2008-3-4 21:59:17 | 显示全部楼层 |阅读模式
实际上是一个……

[ 本帖最后由 无尽藏海 于 2008-3-4 22:02 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wangjay1980
发表于 2008-3-4 22:03:41 | 显示全部楼层
K

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qigang
发表于 2008-3-4 22:07:06 | 显示全部楼层

5/0

rising20.34.12未知!
gaojun7206
发表于 2008-3-4 22:17:09 | 显示全部楼层
Number of Objects = 0002 (dec), Imagebase = 00400000h

   Object01:  .text   RVA: 00001000 Offset: 00000200 Size: 00000A00 Flags: E0000020
   Object02:  .data   RVA: 00002000 Offset: 00000C00 Size: 00001800 Flags: E00000A0

+++++++++++++++++++ RESOURCE INFORMATION +++++++++++++++++++

        There are no Resources in This Application.

+++++++++++++++++++ MENU INFORMATION +++++++++++++++++++

        There are no Menus in This Application.

+++++++++++++++++ DIALOG INFORMATION +++++++++++++++++++

        There are no Dialogs in This Application.

+++++++++++++++++++ IMPORTED FUNCTIONS +++++++++++++++++++
Number of Imported Modules =    1 (decimal)

   Import Module 001: KERNEL32.dll

+++++++++++++++++++ IMPORT MODULE DETAILS +++++++++++++++++

   Import Module 001: KERNEL32.dll

Addr:00001800 hint(0177) Name: 得到模块句柄
Addr:00000C00 hint(00AF) Name: ExitProcess

+++++++++++++++++++ EXPORTED FUNCTIONS +++++++++++++++++++
Number of Exported Functions =    0 (decimal)



Code Offset = 00000600, Code Size = 0000BC00
Data Offset = 0000C200, Data Size = 00012000

Number of Objects = 0003 (dec), Imagebase = 00400000h

   Object01:  .text   RVA: 00001000 Offset: 00000600 Size: 0000BC00 Flags: E0000020
   Object02:  .rsrc   RVA: 0001D000 Offset: 0000C200 Size: 00012000 Flags: C0000040
   Object03:  _紫凛_  RVA: 00035000 Offset: 0001E200 Size: 00001200 Flags: E0000020

+++++++++++++++++++ RESOURCE INFORMATION +++++++++++++++++++

Number of Resource Types =    7 (decimal)

   Resource Type 001: RT_BITMAP
   Resource Type 002: RT_ICON
    Resource Type 003: RT_DIALOG
   Resource Type 004: RT_STRING
   Resource Type 005: RT_RCDATA
   Resource Type 006: RT_GROUP_ICON
    Resource Type 007: RT_UNKNOWN:00000018

+++++++++++++++++++ MENU INFORMATION +++++++++++++++++++

        There are no Menus in This Application.

+++++++++++++++++ DIALOG INFORMATION +++++++++++++++++++

        There are no Dialogs in This Application.

+++++++++++++++++++ IMPORTED FUNCTIONS +++++++++++++++++++
Number of Imported Modules =    9 (decimal)

   Import Module 001: Kernel32.dll
   Import Module 002: ADVAPI32.DLL
   Import Module 003: KERNEL32.DLL
   Import Module 004: COMCTL32.DLL
   Import Module 005: COMDLG32.DLL
   Import Module 006: GDI32.DLL
   Import Module 007: SHELL32.DLL
   Import Module 008: USER32.DLL
   Import Module 009: OLE32.DLL

+++++++++++++++++++ IMPORT MODULE DETAILS +++++++++++++++++

   Import Module 001: Kernel32.dll

Addr:00035E6D hint(0000) Name: GetProcAddress
Addr:00035E7E hint(0000) Name: 装载dll
Addr:00035E8D hint(0000) Name: 得到模块句柄
Addr:00035EA0 hint(0000) Name: 页面分配内存
Addr:00035EAF hint(0000) Name: 页面释放内存

   Import Module 002: ADVAPI32.DLL

Addr:00035734 hint(0000) Name: AdjustTokenPrivileges

   Import Module 003: KERNEL32.DLL

Addr:00035761 hint(0000) Name: 关闭句柄

   Import Module 004: COMCTL32.DLL

Addr:80000011 hint(0011) Name: COMCTL32:NoName0000

   Import Module 005: COMDLG32.DLL

Addr:00035799 hint(0000) Name: CommDlgExtendedError

   Import Module 006: GDI32.DLL

Addr:000357C5 hint(0000) Name: DeleteObject

   Import Module 007: SHELL32.DLL

Addr:000357E6 hint(0000) Name: SHBrowseForFolderA

   Import Module 008: USER32.DLL

Addr:0003580F hint(0000) Name: CharToOemA

   Import Module 009: OLE32.DLL

Addr:0003582F hint(0000) Name: CLSIDFromString

+++++++++++++++++++ EXPORTED FUNCTIONS +++++++++++++++++++
Number of Exported Functions =    0 (decimal)

[ 本帖最后由 gaojun7206 于 2008-3-4 22:18 编辑 ]
gho
发表于 2008-3-4 22:18:35 | 显示全部楼层
avast miss
beyondcloud
发表于 2008-3-4 22:20:08 | 显示全部楼层
nod 飘
傻猪猪米走鸡
发表于 2008-3-4 22:51:04 | 显示全部楼层
极少见楼主发帖……好事情……
taiw_1144
发表于 2008-3-4 23:05:14 | 显示全部楼层
发现未知间谍软件,是否删除?
程序:
C:\DOCUMENTS AND SETTINGS\JINLING\LOCAL SETTINGS\TEMP\RAR$EX00.562\传奇私服病毒清理和加速工具.EXE
木马程序生成以下文件:
1) C:\DOCUMENTS AND SETTINGS\JINLING\LOCAL SETTINGS\TEMP\RARSFX0\传奇私服端_病毒清理.EXE
是否删除木马程序及其衍生物?
lengxue624
发表于 2008-3-4 23:12:41 | 显示全部楼层
红伞扫描也过
ccw8642
发表于 2008-3-4 23:16:42 | 显示全部楼层
结果: 发现1个恶意软件
Trojan-Dropper.Win32.Agent.fbg (病毒)
C:\Users\ccw\Documents\Downloads\Compressed\传奇私服病毒清理和加速工具.rar\传奇私服病毒清理和加速工具.exe

结果: 发现1个恶意软件Trojan.Win32.Inject.zg (病毒)
  • C:\Users\ccw\Documents\Downloads\Compressed\传奇私服端_病毒清理.rar\传奇私服端_病毒清理.exe


[ 本帖最后由 ccw8642 于 2008-3-4 23:17 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 12:27 , Processed in 0.131296 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表