Virus with Wine
Linux/Journal / 2007/08/03 11:33
nidev@ariscrane ~/InklChat-0.5 $ ls config inklchat.exe msvcr71.dll python24.dll system nidev@ariscrane ~/InklChat-0.5 $ wine inklchat.exe- ( inklchat 0.5 인데, 바이러스가 감염되어 있다. )
- (참고로 inklchat 0.5는 인클봇을 운영하시는 분이 만든 IRC클라.)
libGL warning: 3D driver claims to not support visual 0x4b wine: Unhandled page fault on read access to 0x7e7eaf4e at address 0x407a22 (thread 0009), starting debugger... Unhandled exception: page fault on read access to 0x7e7eaf4e in 32-bit code (0x00407a22).- (inklchat.exe에 걸린 바이러스는 이상한 메모리 명령을 보내는
- 기능이 있다. 그래서 wine에서 실행시 죽게된다.)
Register dump: CS:0073 SS:007b DS:007b ES:007b FS:0033 GS:003b EIP:00407a22 ESP:0033ff04 EBP:00006a00 EFLAGS:00010206( - 00 - RIP1) EAX:00000000 EBX:7e7eaf00 ECX:00000000 EDX:00000000 ESI:00407a00 EDI:7ffdf000 Stack dump: 0x0033ff04: 0033ffe8 0040285a 7ee66641 7ffdf000 0x0033ff14: 00000000 00000000 00000000 00000000 0x0033ff24: 00000000 00000000 ffffffff 7ee24030 0x0033ff34: 7ee37c10 7ee9f888 00110440 7ffdf000 0x0033ff44: 0033ffe8 aec98c89 05fcdc74 00000001 0x0033ff54: 10012a03 00000000 00000000 00000000 Backtrace: =>1 0x00407a22 in inklchat (+0x7a22) (0x00006a00) 2 0x00000000 (0x00000000) 0x00407a22: cmpl $0x73696854,0x4e(%ebx) Modules: Module Address Debug info Name (50 modules) PE 400000- 40e000 Export inklchat ELF 7bf00000-7bf03000 Deferred <wine-loader> PE 7c360000-7c3b6000 Deferred msvcr71 ELF 7dcef000-7dcf8000 Deferred libxcursor.so.1 ELF 7dcf8000-7dd15000 Deferred imm32<elf> \-PE 7dd00000-7dd15000 \ imm32 ELF 7dd15000-7dd1b000 Deferred libxrandr.so.2 ELF 7dd1b000-7dd1e000 Deferred libxinerama.so.1 ELF 7e419000-7e439000 Deferred libexpat.so.1 ELF 7e439000-7e662000 Deferred r200_dri.so ELF 7e662000-7e66b000 Deferred libdrm.so.2 ELF 7e66b000-7e670000 Deferred libxfixes.so.3 ELF 7e670000-7e673000 Deferred libxdamage.so.1 ELF 7e673000-7e6c9000 Deferred libgl.so.1 ELF 7e6c9000-7e6ce000 Deferred libxdmcp.so.6 ELF 7e6ce000-7e6d1000 Deferred libxau.so.6 ELF 7e6d1000-7e7b8000 Deferred libx11.so.6 ELF 7e7b8000-7e7c5000 Deferred libxext.so.6 ELF 7e7c5000-7e7ca000 Deferred libxxf86vm.so.1 ELF 7e7ca000-7e7e1000 Deferred libice.so.6 ELF 7e7e1000-7e7ea000 Deferred libsm.so.6 ELF 7e7eb000-7e7f3000 Deferred libxrender.so.1 ELF 7e7f5000-7e883000 Deferred winex11<elf> \-PE 7e800000-7e883000 \ winex11 ELF 7e8bf000-7e9d2000 Deferred libxml2.so.2 ELF 7e9d2000-7e9fb000 Deferred libfontconfig.so.1 ELF 7e9fb000-7ea0d000 Deferred libz.so.1 ELF 7ea0d000-7ea84000 Deferred libfreetype.so.6 ELF 7ea8f000-7ead4000 Deferred advapi32<elf> \-PE 7eaa0000-7ead4000 \ advapi32 ELF 7ead4000-7eb66000 Deferred gdi32<elf> \-PE 7eaf0000-7eb66000 \ gdi32 ELF 7eb66000-7ec9b000 Deferred user32<elf> \-PE 7eb80000-7ec9b000 \ user32 ELF 7ec9b000-7eca8000 Deferred libksc.so ELF 7eca8000-7ecad000 Deferred euc-kr.so ELF 7edf8000-7ef18000 Deferred kernel32<elf> \-PE 7ee10000-7ef18000 \ kernel32 ELF 7ef18000-7ef22000 Deferred libnss_files.so.2 ELF 7ef22000-7ef2c000 Deferred libnss_nis.so.2 ELF 7ef2c000-7ef42000 Deferred libnsl.so.1 ELF 7ef42000-7ef65000 Deferred libm.so.6 ELF 7ef65000-7f000000 Deferred ntdll<elf> \-PE 7ef80000-7f000000 \ ntdll ELF b7ce6000-b7cee000 Deferred libnss_compat.so.2 ELF b7cef000-b7cf3000 Deferred libdl.so.2 ELF b7cf3000-b7e1b000 Deferred libc.so.6 ELF b7e1b000-b7e31000 Deferred libpthread.so.0 ELF b7e3c000-b7f50000 Deferred libwine.so.1 ELF b7f51000-b7f6d000 Deferred ld-linux.so.2 Threads: process tid prio (all id:s are in hex) 00000008 (D) Z:\home\nidev\InklChat-0.5\inklchat.exe 00000009 0 <==- There is no comment needed. ;)
- 바이러스 종류는 Win32.Virut.5131
'Linux > Journal' 카테고리의 다른 글
| Alex씨가 Gentoo Xeffects 메인테이너를 그만두었습니다. (0) | 2007/09/08 |
|---|---|
| xcb 지원이 포함된 libX11에서 swt를 사용하는 어플 실행문제 해결 (0) | 2007/08/12 |
| Virus with Wine (4) | 2007/08/03 |
| Crazy Beryl! (8) | 2007/07/26 |
| ck-sources 최종릴리스. さようなら... (2) | 2007/07/15 |
| 리눅스에서 FLV동영상 파일의 음원 추출하기 (2) | 2007/07/14 |
