۲۰-اسفند-۱۳۸۷, ۱۸:۰۷:۴۰
سلام
سیستم دوستم خراب شده بود تند تند مانیتور خاموش روشن میکیرد وقتی ویندوز را عوض کردم وسط نصب ویندوز ارور داد باز سعی کردم به نصب کردن درست شد وقتی رفتم تو درایوش autorun.inf را دیدیم بازش کردم واسم جالب بود
[autorun]
;Please Do Not Change This Line.
Open=RECYCLER\..\RECYCLER\autoplay.exe
;Please Do Not Change This Line.
shell\open\Command=RECYCLER\autoplay.exe -open
;Please Do Not Change This Line.
shell\open\Default=1
;Please Do Not Change This Line.
shell\explore\Command=RECYCLER\autoplay.exe -explore
;Please Do Not Change This Line.
[:))]
ویرسه تو recycle bin هر درایو بود
Microsoft Visual C++ Runtime Library
... <program name unknown> Runtime Error!
Program: HH:mm:ss dddd, MMMM dd, yyyy MM/dd/yy PM AM December November October September August July June April March February January Dec Nov Oct Sep Aug Jul Jun May Apr Mar Feb Jan Saturday Friday Thursday Wednesday Tuesday Monday Sunday Sat Fri Thu Wed Tue Mon Sun united-states united-kingdom trinidad & tobago south-korea south-africa south korea south africa slovak puerto-rico pr-china pr china nz new-zealand hong-kong holland great britain england czech china britain america usa us uk swiss swedish-finland spanish-venezuela spanish-uruguay spanish-puerto rico spanish-peru spanish-paraguay spanish-panama spanish-nicaragua spanish-modern spanish-mexican spanish-honduras spanish-guatemala spanish-el salvador spanish-ecuador spanish-dominican republic spanish-costa rica spanish-colombia spanish-chile spanish-bolivia spanish-argentina portuguese-brazilian norwegian-nynorsk norwegian-bokmal norwegian italian-swiss irish-english german-swiss german-luxembourg german-lichtenstein german-austrian french-swiss french-luxembourg french-canadian french-belgian english-usa english-us english-uk english-trinidad y tobago english-south africa english-nz english-jamaica english-ire english-caribbean english-can english-belize english-aus english-american dutch-belgian chinese-traditional chinese-singapore chinese-simplified chinese-hongkong chinese chi chh canadian belgian australian american-english american english american t|B ENU `|B ENU L|B ENU @|B ENA 8|B6-OCP ACP Norwegian-Nynorsk ccs= UTF-8 UTF-16LE UNICODE c c s = U T F - 8 U T F - 1 6 L E U N I C O D E InitializeCriticalSectionAndSpinCount kernel32.dll e+000 ہ~PA €ےےGAIsProcessorFeaturePresent KERNEL32 €€†€پ€ fmod _hypot _cabs ldexp fabs sqrt atan2 tanh cosh sinh Complete Object Locator' Class Hierarchy Descriptor' Base Class Array' Base Class Descriptor at ( Type Descriptor' `local static thread guard' `managed vector copy constructor iterator' `vector vbase copy constructor iterator' `vector copy constructor iterator' `dynamic atexit destructor for ' `dynamic initializer for ' `eh vector vbase copy constructor iterator' `eh vector copy constructor iterator' `managed vector destructor iterator' `managed vector constructor iterator' `placement delete[] closure' `placement delete closure' `omni callsig' delete[] new[] `local vftable constructor closure' `local vftable' `RTTI `EH `udt returning' `copy constructor closure' `eh vector vbase constructor iterator' `eh vector destructor iterator' `eh vector constructor iterator' `virtual displacement map' `vector vbase constructor iterator' `vector destructor iterator' `vector constructor iterator' `scalar deleting destructor' `default constructor closure' `vector deleting destructor' `vbase destructor' `string' `local static guard' `typeof' `vcall' `vbtable' `vftable' ^= |= &= <<= >>= %= /= -= += *= || && | ^ ~ () , >= > <= < % ->* + - -- ++ -> operator [] != == ! << >> delete new __unaligned __restrict __ptr64 __clrcall __fastcall __thiscall __stdcall __pascal __cdecl __based( œ†B ”†B ˆ†B |†B p†B d†B X†B P†BJanFebMarAprMayJunJulAugSepOctNovDec GetProcessWindowStation GetUserObjectInformationA GetLastActivePopup GetActiveWindow MessageBoxA USER32.DLL CONOUT$ 1#QNAN 1#INF 1#IND 1#SNAN bad allocation false true C ios_base::badbit set ios_base::failbit set ios_base::eofbit set Thumbs.dbf Thumbs.bd _version _block packet.exe blockn = %d _file_data%d dastor _dastor C:\ D:\ = e d
اینم یه سری کد از ویروسه بود فکر کنم با زبان c نوشته شده بود واسم مهمه بیبنم کار جاسوسی هم میکرده رو سیستم یا نه؟
اینم لینک ویروس
سیستم دوستم خراب شده بود تند تند مانیتور خاموش روشن میکیرد وقتی ویندوز را عوض کردم وسط نصب ویندوز ارور داد باز سعی کردم به نصب کردن درست شد وقتی رفتم تو درایوش autorun.inf را دیدیم بازش کردم واسم جالب بود
[autorun]
;Please Do Not Change This Line.
Open=RECYCLER\..\RECYCLER\autoplay.exe
;Please Do Not Change This Line.
shell\open\Command=RECYCLER\autoplay.exe -open
;Please Do Not Change This Line.
shell\open\Default=1
;Please Do Not Change This Line.
shell\explore\Command=RECYCLER\autoplay.exe -explore
;Please Do Not Change This Line.
[:))]
ویرسه تو recycle bin هر درایو بود
Microsoft Visual C++ Runtime Library
... <program name unknown> Runtime Error!
Program: HH:mm:ss dddd, MMMM dd, yyyy MM/dd/yy PM AM December November October September August July June April March February January Dec Nov Oct Sep Aug Jul Jun May Apr Mar Feb Jan Saturday Friday Thursday Wednesday Tuesday Monday Sunday Sat Fri Thu Wed Tue Mon Sun united-states united-kingdom trinidad & tobago south-korea south-africa south korea south africa slovak puerto-rico pr-china pr china nz new-zealand hong-kong holland great britain england czech china britain america usa us uk swiss swedish-finland spanish-venezuela spanish-uruguay spanish-puerto rico spanish-peru spanish-paraguay spanish-panama spanish-nicaragua spanish-modern spanish-mexican spanish-honduras spanish-guatemala spanish-el salvador spanish-ecuador spanish-dominican republic spanish-costa rica spanish-colombia spanish-chile spanish-bolivia spanish-argentina portuguese-brazilian norwegian-nynorsk norwegian-bokmal norwegian italian-swiss irish-english german-swiss german-luxembourg german-lichtenstein german-austrian french-swiss french-luxembourg french-canadian french-belgian english-usa english-us english-uk english-trinidad y tobago english-south africa english-nz english-jamaica english-ire english-caribbean english-can english-belize english-aus english-american dutch-belgian chinese-traditional chinese-singapore chinese-simplified chinese-hongkong chinese chi chh canadian belgian australian american-english american english american t|B ENU `|B ENU L|B ENU @|B ENA 8|B6-OCP ACP Norwegian-Nynorsk ccs= UTF-8 UTF-16LE UNICODE c c s = U T F - 8 U T F - 1 6 L E U N I C O D E InitializeCriticalSectionAndSpinCount kernel32.dll e+000 ہ~PA €ےےGAIsProcessorFeaturePresent KERNEL32 €€†€پ€ fmod _hypot _cabs ldexp fabs sqrt atan2 tanh cosh sinh Complete Object Locator' Class Hierarchy Descriptor' Base Class Array' Base Class Descriptor at ( Type Descriptor' `local static thread guard' `managed vector copy constructor iterator' `vector vbase copy constructor iterator' `vector copy constructor iterator' `dynamic atexit destructor for ' `dynamic initializer for ' `eh vector vbase copy constructor iterator' `eh vector copy constructor iterator' `managed vector destructor iterator' `managed vector constructor iterator' `placement delete[] closure' `placement delete closure' `omni callsig' delete[] new[] `local vftable constructor closure' `local vftable' `RTTI `EH `udt returning' `copy constructor closure' `eh vector vbase constructor iterator' `eh vector destructor iterator' `eh vector constructor iterator' `virtual displacement map' `vector vbase constructor iterator' `vector destructor iterator' `vector constructor iterator' `scalar deleting destructor' `default constructor closure' `vector deleting destructor' `vbase destructor' `string' `local static guard' `typeof' `vcall' `vbtable' `vftable' ^= |= &= <<= >>= %= /= -= += *= || && | ^ ~ () , >= > <= < % ->* + - -- ++ -> operator [] != == ! << >> delete new __unaligned __restrict __ptr64 __clrcall __fastcall __thiscall __stdcall __pascal __cdecl __based( œ†B ”†B ˆ†B |†B p†B d†B X†B P†BJanFebMarAprMayJunJulAugSepOctNovDec GetProcessWindowStation GetUserObjectInformationA GetLastActivePopup GetActiveWindow MessageBoxA USER32.DLL CONOUT$ 1#QNAN 1#INF 1#IND 1#SNAN bad allocation false true C ios_base::badbit set ios_base::failbit set ios_base::eofbit set Thumbs.dbf Thumbs.bd _version _block packet.exe blockn = %d _file_data%d dastor _dastor C:\ D:\ = e d
اینم یه سری کد از ویروسه بود فکر کنم با زبان c نوشته شده بود واسم مهمه بیبنم کار جاسوسی هم میکرده رو سیستم یا نه؟
اینم لینک ویروس