楼主: lxja360
收起左侧

[可疑文件] 在游民星空下载的游戏私处里的一个文件

  [复制链接]
hx1997
发表于 2012-2-28 20:12:23 | 显示全部楼层
lxja360 发表于 2012-2-28 20:11
别的我知道 就是“补丁系统文件”是什么意思?

原文是 Patches,其实就是“替换系统文件”的意思。
一个笨鸟
发表于 2012-2-28 20:16:38 | 显示全部楼层
ujty
发表于 2012-2-28 20:20:12 | 显示全部楼层
应该说这个介于毒和正常文件之间,比较龌龊。
donsky829
头像被屏蔽
发表于 2012-2-28 20:44:09 | 显示全部楼层
下游戏,我还是相信3DM
lxja360
 楼主| 发表于 2012-2-28 22:03:22 | 显示全部楼层
本帖最后由 lxja360 于 2012-2-28 22:04 编辑
hx1997 发表于 2012-2-28 20:12
原文是 Patches,其实就是“替换系统文件”的意思。


哦  明白了  不过这个到底是不是毒还没弄明白呢
看结果好像病毒的行为
hx1997
发表于 2012-2-28 23:51:28 | 显示全部楼层
lxja360 发表于 2012-2-28 22:03
哦  明白了  不过这个到底是不是毒还没弄明白呢
看结果好像病毒的行为

很可疑,都加载驱动了,暂时不要使用先。

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> kernel32]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\Documents and Settings\Administrator\Lb\Privates\Content\levels\record.znb]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\NetSafe0]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\NetSafe0]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\NetSafe0]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\WINDOWS\system32\alrsvcfoe.dll]
Write to system directory. (Suspicious)


Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\WINDOWS\system32\alrsvcfoe.dll]
Write to system directory. (Suspicious)

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\NetSafe0]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\websafe]


Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\NetSafe0]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\PIPE\lsarpc]

Adjust Privileges [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe  ]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Cookies\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Cookies\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\History\History.IE5\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\History\History.IE5\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\PIPE\lsarpc]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\PIPE\lsarpc]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\PIPE\lsarpc]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\PIPE\lsarpc]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\PIPE\lsarpc]

Write to file [C:\Documents and Settings\Administrator\桌面\Privates\Privates.exe   -> \\.\PIPE\lsarpc]
绅博周幸
发表于 2012-2-29 07:14:39 | 显示全部楼层
hx1997 发表于 2012-2-28 23:51
很可疑,都加载驱动了,暂时不要使用先。

Write to file [C:\Documents and Settings\Administrator\桌 ...

File privates_exe declared CLEAN
绅博周幸
发表于 2012-2-29 07:14:59 | 显示全部楼层
ujty 发表于 2012-2-28 20:20
应该说这个介于毒和正常文件之间,比较龌龊。

不是病毒
saga3721
发表于 2012-2-29 07:36:48 | 显示全部楼层
原来是可伶可俐
hx1997
发表于 2012-2-29 17:49:54 | 显示全部楼层
本帖最后由 hx1997 于 2012-2-29 18:04 编辑
绅博周幸 发表于 2012-2-29 07:14
File privates_exe declared CLEAN


那它为什么要加载驱动和替换系统文件呢?

卡巴入库了。

https://www.virustotal.com/file/ ... nalysis/1330509762/
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-9-25 14:46 , Processed in 0.190773 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表