本帖最后由 墨家小子 于 2016-1-8 14:07 编辑
现在我怀着沉痛的心情向大家宣布一个消息,经过本贴样本的双击治疗,我样本区赫赫有名的声纳同学因病……此处省略一万字,望各地前来吊唁的先生们、女士们念在以往声纳同学勤奋努力的面子少喷!
注销之后可杀不少,但是两处关键的启动项及其木马文件都不杀,造成声纳不停的杀来杀去
还是HMPA,先于声纳拦截,省心:
[mw_shl_code=css,true]2016/1/8 10:09:15,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\lite595.exe" )
2016/1/8 10:09:26,C:\Users\AA\Desktop\1\lite595.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\msiexec.exe")
2016/1/8 10:09:28,C:\Windows\SysWOW64\msiexec.exe,50,Allowed ;使用 DNS 解析服务访问网络
2016/1/8 10:09:36,C:\Windows\SysWOW64\msiexec.exe,48,Allowed ;出站网络访问
2016/1/8 10:09:39,C:\Windows\SysWOW64\msiexec.exe,47,Allowed ;创建交换数据流 (C:\ProgramData\msojglxqp.exe:Zone.Identifier)
2016/1/8 10:09:40,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows,Load)
2016/1/8 10:09:42,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run)
2016/1/8 10:09:43,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,80835775)
2016/1/8 10:09:58,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38712921.exe)
2016/1/8 10:10:12,C:\Users\AA\AppData\Local\Temp\KB38712921.exe,53,Allowed ;执行应用程序 ("C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\Navw32.exe")
2016/1/8 10:10:25,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38726281.exe)
2016/1/8 10:10:27,C:\Users\AA\AppData\Local\Temp\KB38712921.exe,53,Allowed ;执行应用程序 (C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\Navw32.exe)
2016/1/8 10:10:34,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,47,Allowed ;创建交换数据流 (C:\ProgramData\CreativeAudio\w5ecu5mk59.exe:Zone.Identifier)
2016/1/8 10:10:38,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:10:41,C:\Users\AA\AppData\Local\Temp\KB38726281.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\msiexec.exe")
2016/1/8 10:10:43,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:10:45,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Internet Explorer\Main,NoProtectedModeBanner)
2016/1/8 10:10:47,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:10:48,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:10:52,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=6332))
2016/1/8 10:10:54,C:\Windows\SysWOW64\msiexec.exe,50,Allowed ;使用 DNS 解析服务访问网络
2016/1/8 10:10:55,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:10:56,C:\Windows\SysWOW64\msiexec.exe,48,Allowed ;出站网络访问
2016/1/8 10:10:58,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:10:59,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,50,Allowed ;使用 DNS 解析服务访问网络
2016/1/8 10:11:01,C:\Windows\SysWOW64\msiexec.exe,47,Allowed ;创建交换数据流 (C:\ProgramData\msxkrd.exe:Zone.Identifier)
2016/1/8 10:11:03,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,48,Allowed ;出站网络访问
2016/1/8 10:11:04,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows,Load)
2016/1/8 10:11:06,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:11:07,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run)
2016/1/8 10:11:09,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:11:10,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,2077409781)
2016/1/8 10:11:15,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:11:27,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38798609.exe)
2016/1/8 10:11:28,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:11:44,C:\Users\AA\AppData\Local\Temp\KB38798609.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:11:48,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38814265.exe)
2016/1/8 10:11:50,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:11:51,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,KdjSaS011arhaaa)
2016/1/8 10:11:52,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:12:03,C:\Users\AA\AppData\Local\Temp\KB38814265.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:12:04,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,KdjSaS011arhaaa)
2016/1/8 10:12:08,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38835593.exe)
2016/1/8 10:12:10,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:12:11,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,wfdaaab1ab)
2016/1/8 10:12:13,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:12:24,C:\Users\AA\AppData\Local\Temp\KB38835593.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:12:26,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,wfdaaab1ab)
2016/1/8 10:12:30,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38856046.exe)
2016/1/8 10:12:32,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:12:34,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:12:36,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,we12z3b1ab)
2016/1/8 10:12:47,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:12:51,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38878046.exe)
2016/1/8 10:12:52,C:\Users\AA\AppData\Local\Temp\KB38856046.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:12:54,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,we12z3b1ab)
2016/1/8 10:12:56,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:12:57,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:13:06,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,wfda6g4144a)
2016/1/8 10:13:09,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38898750.exe)
2016/1/8 10:13:11,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:13:12,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,wfda6g4144a)
2016/1/8 10:13:12,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\nis.exe,53,Allowed ;执行应用程序 ("C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\symerr.exe" /consent)
2016/1/8 10:13:14,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:13:32,C:\Users\AA\AppData\Local\Temp\KB38878046.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:13:46,C:\Users\AA\AppData\Local\Temp\KB38898750.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:13:47,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:13:49,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:13:50,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,w6a6g24144a)
2016/1/8 10:13:52,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:13:54,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38934578.exe)
2016/1/8 10:13:57,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,w6a6g24144a)
2016/1/8 10:13:58,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,w6ab61fg44a)
2016/1/8 10:14:07,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:14:09,C:\Users\AA\AppData\Local\Temp\KB38934578.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:14:12,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,w6ab61fg44a)
2016/1/8 10:14:14,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:14:16,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:14:17,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,w6abZZb44ea)
2016/1/8 10:14:19,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38961437.exe)
2016/1/8 10:14:21,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,w6abZZb44ea)
2016/1/8 10:14:22,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:14:23,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:14:37,C:\Users\AA\AppData\Local\Temp\KB38961437.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:14:38,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:14:41,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB38986968.exe)
2016/1/8 10:14:43,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:14:44,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:14:46,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,w6a5678b44ea)
2016/1/8 10:14:56,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:14:57,C:\Users\AA\AppData\Local\Temp\KB38986968.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:15:00,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,w6a5678b44ea)
2016/1/8 10:15:03,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB39008937.exe)
2016/1/8 10:15:04,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,w6a56ab78b44ea)
2016/1/8 10:15:05,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:15:07,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,w6a56ab78b44ea)
2016/1/8 10:15:09,C:\Users\AA\AppData\Local\Temp\KB39008937.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2016/1/8 10:15:11,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:15:13,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,w6bn7ea)
2016/1/8 10:15:14,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:15:15,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,w6bn7ea)
2016/1/8 10:15:16,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:15:17,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:15:19,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:15:40,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:15:42,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/8 10:15:43,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2016/1/8 10:15:49,C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\navw32.exe,26,Terminated ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
[/mw_shl_code]
|