查看: 2560|回复: 9
收起左侧

[病毒样本] Rootkit.Win32.InsApc.m postcard.exe

[复制链接]
Nblock
发表于 2008-10-23 09:40:24 | 显示全部楼层 |阅读模式
Recently, a new Worm/Trojan has been very "popular" in our Net world. This worm uses email and various phishing Web sites to spread and infect computers. When the worm breaks into the system, it installs a kernel driver to protect itself. With the help of the driver, it then injects and runs malicious code from the legitimate process "services.exe". So, it can bypass firewalls easily and open a back door for the bad guys.

This worm contains an SMTP client engine and a peer-to-peer client component. Obviously, these components are prepared for spamming or mass-mailing purposes.

During my research, I found that this worm used variousrootkit techniques to protect itself (such as hiding files, registers, ports, and the like), so it's not easily detected and removed. The worm also used a custom packer and encryption to protect itself. In the driver that the worm dropped, we learned that it employs a user-mode APC to inject malicious code (embedded) into the process named "services.exe".




http://blog.csdn.net/Kendiv/archive/2008/10/15/3078531.aspx

Kaspersky--Email-Worm.Win32.Zhelatin.afy

Rising--Worm.Mail.Win32.Zhelatin.aga

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
yurius
发表于 2008-10-23 10:07:20 | 显示全部楼层
McAfee 已自动阻止和删除 病毒。

关于此 病毒
已检测到: W32/Nuwar@MM (病毒), W32/Nuwar@MM (病毒)
位置: C:\Documents and Settings\xxx\桌面\virus\postcard.exe

病毒是一种可以自我复制的程序,可能会损害您的计算机、危害其安全性并损坏重要文件。
hzyw
头像被屏蔽
发表于 2008-10-23 10:29:04 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2008-10-23 12:18:22 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\morgan\Desktop\postcard.rar'
C:\Users\morgan\Desktop\
  postcard.rar
    [0] Archive type: RAR
    --> postcard.exe
      [DETECTION] Contains recognition pattern of the WORM/Zhelatin.ZM worm
    [NOTE]      The file was deleted!
aerbeisi
发表于 2008-10-23 12:33:50 | 显示全部楼层
F:\postcard.rar > RAR > postcard.exe - Win32/Nuwar.DG 蠕虫 的变种
欠妳緈諨
发表于 2008-10-23 12:51:54 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Sherry.ai
发表于 2008-10-23 13:11:42 | 显示全部楼层
Worm.Mail.Win32.Zhelatin.aga瑞星秒
kingmuro
头像被屏蔽
发表于 2008-10-23 13:20:40 | 显示全部楼层
诺顿10.1版本  杀

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
niu880601
头像被屏蔽
发表于 2008-10-23 13:37:15 | 显示全部楼层
运行w32tm.exe,意图改时间!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
lingbo110120
发表于 2008-10-23 17:00:57 | 显示全部楼层
postcard.exe - Win32/Nuwar.DG 蠕虫 的变种
NOD KILL
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-11 11:07 , Processed in 0.121419 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表