样本运行过程(从下往上看):
Firewall: User decision,2013/5/20 14:22:55,Allowed,"C:\ProgramData\q1be.dat, Outgoing
TCP access allowed to: 37.139.53.220:443"
Program Guard: q1be.dat,2013/5/20 14:22:52,Allowed,C:\Windows\system32\rundll32.exe
-> C:\ProgramData\q1be.dat
Program Guard: q1be.dat -> rundll32.exe,2013/5/20 14:22:47,Allowed,C:\ProgramData
\q1be.dat(0) wants to start C:\ProgramData\rundll32.exe(3908)
Firewall: User decision,2013/5/20 14:22:45,Allowed,"C:\ProgramData\q1be.dat, Outgoing
TCP access allowed to: 37.139.53.220:443"
Program Guard: q1be.dat -> rundll32.exe,2013/5/20 14:22:09,Allowed,C:\ProgramData
\q1be.dat(0) wants to start C:\Windows\system32\rundll32.exe(3968)
Program Guard: q1be.dat,2013/5/20 14:21:56,Allowed,C:\Program Files\Windows Media
Player\wmplayer.exe -> C:\ProgramData\q1be.dat
Program Guard: q1be.dat -> wmplayer.exe,2013/5/20 14:21:47,Allowed,C:\ProgramData
\q1be.dat(0) wants to write memory in C:\Program Files\Windows Media Player
\wmplayer.exe(2424)
Firewall: User decision,2013/5/20 14:21:44,Allowed,"C:\ProgramData\q1be.dat, Outgoing
TCP access allowed to: 37.139.53.220:80"
Program Guard: q1be.dat -> wmplayer.exe,2013/5/20 14:21:40,Allowed,C:\ProgramData
\q1be.dat(0) wants to change memory access protection in C:\Program Files\Windows
Media Player\wmplayer.exe(2424)
Firewall: User decision,2013/5/20 14:21:37,Allowed,"C:\ProgramData\q1be.dat, Outgoing
TCP access allowed to: 37.139.53.220:80"
Program Guard: q1be.dat -> wmplayer.exe,2013/5/20 14:21:14,Allowed,C:\ProgramData
\q1be.dat(0) wants to open C:\Program Files\Windows Media Player\wmplayer.exe(2424)
Firewall: Automatic decision,2013/5/20 14:21:12,Allowed,"C:\Program Files\Windows Media
Player\wmplayer.exe, Outgoing UDP access allowed to: 127.0.0.1:63813"
Program Guard: q1be.dat -> iexplore.exe,2013/5/20 14:20:38,Allowed,C:\ProgramData
\q1be.dat(0) wants to open C:\Program Files\Internet Explorer\iexplore.exe(2604)
Firewall: Automatic decision,2013/5/20 14:20:35,Allowed,"C:\Program Files\Internet
Explorer\iexplore.exe, Outgoing UDP access allowed to: 127.0.0.1:49542"
Program Guard: q1be.dat,2013/5/20 14:20:34,Allowed,C:\ProgramData\q1be.dat wants to
get a list of the files C:\ProgramData\*
Program Guard: q1be.dat -> iexplore.exe,2013/5/20 14:20:32,Allowed,C:\ProgramData
\q1be.dat(0) wants to start C:\Program Files\Internet Explorer\iexplore.exe(2604)
Program Guard: q1be.dat,2013/5/20 14:20:28,Allowed,C:\ProgramData\q1be.dat wants to
get a list of the files C:\ProgramData\*
Program Guard: q1be.dat -> rundll32.exe,2013/5/20 14:20:28,Allowed,C:\ProgramData
\q1be.dat(0) wants to start C:\ProgramData\rundll32.exe(2804)
Program Guard: q1be.dat,2013/5/20 14:20:22,Allowed,C:\ProgramData\rundll32.exe -> C:
\ProgramData\q1be.dat
Program Guard: q1be.dat -> rundll32.exe,2013/5/20 14:20:10,Allowed,C:\ProgramData
\q1be.dat(0) wants to start C:\ProgramData\rundll32.exe(2476)
Program Guard: 5844673.dll,2013/5/20 14:19:59,Allowed,C:\Users\Firefox3\Desktop
\5844673.dll wants to get a list of the files C:\ProgramData\*
Program Guard: 5844673.dll -> q1be.dat,2013/5/20 14:19:48,Allowed,C:\Users
\Firefox3\Desktop\5844673.dll(0) wants to load C:\ProgramData\q1be.dat(0)
Program Guard: 5844673.dll -> rundll32.exe,2013/5/20 14:19:39,Allowed,C:\Users
\Firefox3\Desktop\5844673.dll wants to create executable file C:\PROGRA~2\rundll32.exe
Program Guard: 5844673.dll,2013/5/20 14:19:32,Allowed,C:\Windows\explorer.exe -> C:
\Users\Firefox3\Desktop\5844673.dll
重启后有惊喜
详见:关于 OA free 的启动项防御 ,OA 大战 锁屏DLL |