楼主: 小v可
收起左侧

[病毒样本] 我朋友给病毒加了壳!他说免杀NOD32!

[复制链接]
Lelouch
发表于 2009-7-27 10:56:26 | 显示全部楼层
date/time: 2009-7-27 10:55:53
filename: yangben.rar
original path: c:\Documents and Settings\Administrator\桌面\
filesize: 66.09 KB
virusname: Generic.Qhost
suggestion: Save & Delete
signatureId: 914441
yaofo7kafan
头像被屏蔽
发表于 2009-7-27 11:41:57 | 显示全部楼层
瑞星2010为什么清除了病毒,让我重启,却增加了个账户,C D盘全共享了? 郁闷,瑞星我对你2次失望。
Sherry.ai
发表于 2009-7-27 11:54:33 | 显示全部楼层
无壳bat
qqqx123
发表于 2009-7-27 11:54:57 | 显示全部楼层
确实过了
495228535
头像被屏蔽
发表于 2009-7-27 13:01:53 | 显示全部楼层
原帖由 strawman0719 于 2009-7-27 00:13 发表
@echo off
%na2q%
%random%%random%%random%%random%%random%%random%%random%
%1xp5%
%random%%random%%random%%random%%random%%random%%random%
%bcsw%
%random%%random%%random%%random%%random%%random%% ...


看来不过如此[:26:]
寻找周宇轩
发表于 2009-7-27 13:10:49 | 显示全部楼层
一个asp木马加一个批处理,添加新帐户后会被远程控制,C盘共享为了能拿到管理员权限,可是,这样的病毒只有用社工才会有人上当运行吧
寻找周宇轩
发表于 2009-7-27 13:15:30 | 显示全部楼层
%Q博士% norton*
%Q博士% av*
%Q博士% fire*
%Q博士% anti*
%Q博士% spy*
%Q博士% bullguard
%Q博士% PersFw
%Q博士% KAV*
%Q博士% ZONEALARM
%Q博士% SAFEWEB
%Q博士% OUTPOST
%Q博士% nv*
%Q博士% nav*
%Q博士% F-*
%Q博士% ESAFE
%Q博士% cle
%Q博士% BLACKICE
%Q博士% def*
这几个关键进程杀掉

%Q博士2% 127.0.0.1 www.google.com > %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.google.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.symantec.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.free-av.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.free-av.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.antivir.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.antivir.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.kaspersky.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.kaspersky.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.microsoft.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.microsoft.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.sophos.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.sophos.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.symantec.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.hijackthis.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.spychecker.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.trendmicro.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.trendmicro.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.lavasoftusa.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.yahoo.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.yahoo.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.lycos.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 www.lycos.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 google.com > %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 google.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 symantec.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 free-av.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 free-av.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 antivir.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 antivir.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 kaspersky.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 kaspersky.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 microsoft.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 microsoft.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 sophos.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 sophos.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 symantec.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 hijackthis.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 spychecker.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 trendmicro.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 trendmicro.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 lavasoftusa.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 yahoo.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 yahoo.de >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 lycos.com >> %windir%\system32\drivers\etc\hosts
%Q博士2% 127.0.0.1 lycos.de >> %windir%\system32\drivers\etc\hosts


这几个网站在host里指向127.0.0.1
yaofo7kafan
头像被屏蔽
发表于 2009-7-27 13:53:07 | 显示全部楼层
为什么运行Q博士  微丶不拦截阿
q4068586
发表于 2009-7-27 13:59:35 | 显示全部楼层
AVG
受感染的 BAT/Generic";
wangyunxi80
头像被屏蔽
发表于 2009-7-27 18:11:39 | 显示全部楼层
红伞轻松干掉
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-17 19:21 , Processed in 0.102036 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表