티스토리 툴바

블로그 이미지
나이데브의 디지털릭 판타지. 나이데브

카테고리

분류 전체보기 (361)
Linux (120)
Win32/64 (7)
ProgPost (16)
내 이야기 (179)
LiveUSB Dev (17)
Game (7)
허튼 짓 (6)
Zaurus (8)
Total326,057
Today8
Yesterday46

'바이러스'에 해당되는 글 1건

  1. 2007/08/03 Virus with Wine (4)

Virus with Wine

Linux/Journal / 2007/08/03 11:33
  1. nidev@ariscrane ~/InklChat-0.5 $ ls
  2. config  inklchat.exe  msvcr71.dll  python24.dll  system
  3. nidev@ariscrane ~/InklChat-0.5 $ wine inklchat.exe
  4. ( inklchat 0.5 인데, 바이러스가 감염되어 있다. )
  5. (참고로 inklchat 0.5는 인클봇을 운영하시는 분이 만든 IRC클라.)
  6. libGL warning: 3D driver claims to not support visual 0x4b
  7. wine: Unhandled page fault on read access to 0x7e7eaf4e at address 0x407a22 (thread 0009), starting debugger...
  8. Unhandled exception: page fault on read access to 0x7e7eaf4e in 32-bit code (0x00407a22).
  9. (inklchat.exe에 걸린 바이러스는 이상한 메모리 명령을 보내는
  10. 기능이 있다. 그래서 wine에서 실행시 죽게된다.)
  11. Register dump:
  12.  CS:0073 SS:007b DS:007b ES:007b FS:0033 GS:003b
  13.  EIP:00407a22 ESP:0033ff04 EBP:00006a00 EFLAGS:00010206(   - 00      - RIP1)
  14.  EAX:00000000 EBX:7e7eaf00 ECX:00000000 EDX:00000000
  15.  ESI:00407a00 EDI:7ffdf000
  16. Stack dump:
  17. 0x0033ff04:  0033ffe8 0040285a 7ee66641 7ffdf000
  18. 0x0033ff14:  00000000 00000000 00000000 00000000
  19. 0x0033ff24:  00000000 00000000 ffffffff 7ee24030
  20. 0x0033ff34:  7ee37c10 7ee9f888 00110440 7ffdf000
  21. 0x0033ff44:  0033ffe8 aec98c89 05fcdc74 00000001
  22. 0x0033ff54:  10012a03 00000000 00000000 00000000
  23. Backtrace:
  24. =>1 0x00407a22 in inklchat (+0x7a22) (0x00006a00)
  25.   2 0x00000000 (0x00000000)
  26. 0x00407a22: cmpl        $0x73696854,0x4e(%ebx)
  27. Modules:
  28. Module  Address                 Debug info      Name (50 modules)
  29. PE        400000-  40e000       Export          inklchat
  30. ELF     7bf00000-7bf03000       Deferred        <wine-loader>
  31. PE      7c360000-7c3b6000       Deferred        msvcr71
  32. ELF     7dcef000-7dcf8000       Deferred        libxcursor.so.1
  33. ELF     7dcf8000-7dd15000       Deferred        imm32<elf>
  34.   \-PE  7dd00000-7dd15000       \               imm32
  35. ELF     7dd15000-7dd1b000       Deferred        libxrandr.so.2
  36. ELF     7dd1b000-7dd1e000       Deferred        libxinerama.so.1
  37. ELF     7e419000-7e439000       Deferred        libexpat.so.1
  38. ELF     7e439000-7e662000       Deferred        r200_dri.so
  39. ELF     7e662000-7e66b000       Deferred        libdrm.so.2
  40. ELF     7e66b000-7e670000       Deferred        libxfixes.so.3
  41. ELF     7e670000-7e673000       Deferred        libxdamage.so.1
  42. ELF     7e673000-7e6c9000       Deferred        libgl.so.1
  43. ELF     7e6c9000-7e6ce000       Deferred        libxdmcp.so.6
  44. ELF     7e6ce000-7e6d1000       Deferred        libxau.so.6
  45. ELF     7e6d1000-7e7b8000       Deferred        libx11.so.6
  46. ELF     7e7b8000-7e7c5000       Deferred        libxext.so.6
  47. ELF     7e7c5000-7e7ca000       Deferred        libxxf86vm.so.1
  48. ELF     7e7ca000-7e7e1000       Deferred        libice.so.6
  49. ELF     7e7e1000-7e7ea000       Deferred        libsm.so.6
  50. ELF     7e7eb000-7e7f3000       Deferred        libxrender.so.1
  51. ELF     7e7f5000-7e883000       Deferred        winex11<elf>
  52.   \-PE  7e800000-7e883000       \               winex11
  53. ELF     7e8bf000-7e9d2000       Deferred        libxml2.so.2
  54. ELF     7e9d2000-7e9fb000       Deferred        libfontconfig.so.1
  55. ELF     7e9fb000-7ea0d000       Deferred        libz.so.1
  56. ELF     7ea0d000-7ea84000       Deferred        libfreetype.so.6
  57. ELF     7ea8f000-7ead4000       Deferred        advapi32<elf>
  58.   \-PE  7eaa0000-7ead4000       \               advapi32
  59. ELF     7ead4000-7eb66000       Deferred        gdi32<elf>
  60.   \-PE  7eaf0000-7eb66000       \               gdi32
  61. ELF     7eb66000-7ec9b000       Deferred        user32<elf>
  62.   \-PE  7eb80000-7ec9b000       \               user32
  63. ELF     7ec9b000-7eca8000       Deferred        libksc.so
  64. ELF     7eca8000-7ecad000       Deferred        euc-kr.so
  65. ELF     7edf8000-7ef18000       Deferred        kernel32<elf>
  66.   \-PE  7ee10000-7ef18000       \               kernel32
  67. ELF     7ef18000-7ef22000       Deferred        libnss_files.so.2
  68. ELF     7ef22000-7ef2c000       Deferred        libnss_nis.so.2
  69. ELF     7ef2c000-7ef42000       Deferred        libnsl.so.1
  70. ELF     7ef42000-7ef65000       Deferred        libm.so.6
  71. ELF     7ef65000-7f000000       Deferred        ntdll<elf>
  72.   \-PE  7ef80000-7f000000       \               ntdll
  73. ELF     b7ce6000-b7cee000       Deferred        libnss_compat.so.2
  74. ELF     b7cef000-b7cf3000       Deferred        libdl.so.2
  75. ELF     b7cf3000-b7e1b000       Deferred        libc.so.6
  76. ELF     b7e1b000-b7e31000       Deferred        libpthread.so.0
  77. ELF     b7e3c000-b7f50000       Deferred        libwine.so.1
  78. ELF     b7f51000-b7f6d000       Deferred        ld-linux.so.2
  79. Threads:
  80. process  tid      prio (all id:s are in hex)
  81. 00000008 (D) Z:\home\nidev\InklChat-0.5\inklchat.exe
  82.         00000009    0 <==
  83. There is no comment needed. ;)
  84. 바이러스 종류는 Win32.Virut.5131
Posted by 나이데브

최근에 달린 댓글

최근에 받은 트랙백

글 보관함