查看: 4093|回复: 10
收起左侧

[病毒样本] 597aaf

[复制链接]
lanvin
发表于 2007-11-11 21:15:23 | 显示全部楼层 |阅读模式
ummary:
 escription  Risk
   utostart capabilities: This executable registers processes to be executed at
 ystem start. This could result in unwanted actions to be performed
 utomatically.
    hanges security settings of Internet Explorer: This system alteration could
 eriousley affect safety surfing the World Wide Web.
   

 able of Contents
 xpand all  collapse all
 eneral information

 ample.EXE

 VMP~1.EXE

 wwin.exe

 rwtsn32.exe
  
 . General Information
  
 ime needed: 37 s
   eport created: 11/11/07, 13:08:44
   ermination reason: All tracked processes have exited
   rogram version: 1.5
  
 . sample.EXE
    General information about this executable
   nalysis Reason: Primary Analysis Subject
   ilename: sample.EXE
   D5: 597aaf02779b13e72723bc50a2b821ec
   HA-1: b5a544648ac29ce179f071a7d9dd25450b50b29e
   ile Size: 406528 Bytes
 ommand Line: "C:\sample.EXE"
   rocess-status at analysis end: dead
   xit Code: 0
  
  Load-time Dlls
  
  Run-time Dlls
  
  Ikarus Virus Scanner
   ackdoor.Win32.Beastdoor.l (Sig-Id:157611)

 .a) sample.EXE - Registry Activities
    Registry Values Deleted:
   ey Name
 KLM\​Software\​Microsoft\​Windows\​CurrentVersion\​RunOnce  wextract_cleanup0
  
  Registry Values Modified:
  
  Registry Values Read:
  
 .b) sample.EXE - File Activities
    Files Deleted:
   :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE

  Files Created:
   :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE
 :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\TMP4351$.TMP

  Files Read:
   IPE\lsarpc

  Files Modified:
   ountPointManager
 IPE\lsarpc

  Directories Created:
   :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP

  File System Control Communication:
   ile Control Code Times
 IPE\lsarpc  0x0011C017  1
  
  Device Control Communication:
   ile Control Code Times
 :  0x5046280  1
   ountPointManager  0x7143432  1
  
 .c) sample.EXE - Process Activities
    Processes Created:
   xecutable Command Line
 :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE
  
 . 2VMP~1.EXE
    General information about this executable
   nalysis Reason: Started by sample.EXE
   ilename: 2VMP~1.EXE
   ommand Line: C:\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE
   rocess-status at analysis end: dead
   xit Code: -1073741819
  
  Load-time Dlls
  
  Run-time Dlls
  
 .a) 2VMP~1.EXE - Registry Activities
    Registry Values Read:
  
 .b) 2VMP~1.EXE - File Activities
    Files Created:
   :\DOCUME~1\andy\LOCALS~1\Temp\c23a_appcompat.txt

  Files Read:
   IPE\lsarpc

  Files Modified:
   :\DOCUME~1\andy\LOCALS~1\Temp\c23a_appcompat.txt
 IPE\lsarpc

  File System Control Communication:
   ile Control Code Times
 IPE\lsarpc  0x0011C017  6
  
  Device Control Communication:
   ile Control Code Times
 Device\KsecDD  0x3735560  1
  
  Memory Mapped Files:
   ile Name
 :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE
 :\Documents and Settings\andy\Local Settings\Temp\IXP000.TMP\2VMP~1.EXE
 :\WINDOWS\system32\kernel32.dll

 .c) 2VMP~1.EXE - Process Activities
    Processes Created:
   xecutable Command Line
 :\WINDOWS\system32\dwwin.exe -x -s 152
   :\WINDOWS\system32\drwtsn32 -p 480 -e 116 -g
  
  Thread Overview:
   ime Number of threads
 fter 34 seconds 0
  
 .d) 2VMP~1.EXE - Other Activities
    Windows SEH exceptions:
  
 . dwwin.exe
    General information about this executable
   nalysis Reason: Started by 2VMP~1.EXE
   ilename: dwwin.exe
   D5: 7c25440617eee6f69709aa8c915d2c32
   HA-1: 40747172146706013a3334d475b5df0116c56643
   ile Size: 180224 Bytes
 ommand Line: C:\WINDOWS\system32\dwwin.exe -x -s 152
   rocess-status at analysis end: dead
   xit Code: 0
  
  Load-time Dlls
  
  Run-time Dlls
  
  Popups
   indow Name Window Text
 VMP~1.EXE  &Don't Send 2VMP~1.EXE has encountered a problem and needs to close.
 e are sorry for the inconvenience. 2VMP~1.EXE has encountered a problem and
 eeds to close. We are sorry for the inconvenience. If you were in the middle of
 omething, the information you were working on might be lost. Please tell
 icrosoft about this problem. We have created an error report that you can send
 o us. We will treat this report as confidential and anonymous. To see what data
 his error report contains, Details &Send Error Report
  
 .a) dwwin.exe - Registry Activities
    Registry Values Modified:
  
  Registry Values Read:
  
  Monitored Registry Keys:
   ey Name Watch subtree Notify Filter Count
 KLM\​Software\​Microsoft\​Tracing\​RASAPI32  0  Attributes Change,Value Change,Security
 escriptor Change  2
  
 .b) dwwin.exe - File Activities
    Files Deleted:
   :\DOCUME~1\andy\LOCALS~1\Temp\7D2EE.dmp
 :\DOCUME~1\andy\LOCALS~1\Temp\c23a_appcompat.txt

  Files Created:
   :\DOCUME~1\andy\LOCALS~1\Temp\7D2EE.dmp

  Files Read:
   :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE
 :\WINDOWS\win.ini
 IPE\lsarpc
 :\autoexec.bat

  Files Modified:
   IPE\lsarpc

  File System Control Communication:
   ile Control Code Times
 IPE\lsarpc  0x0011C017  16
  
  Device Control Communication:
   ile Control Code Times
 nnamed file  0x3735560  7
  
  Memory Mapped Files:
  
 .c) dwwin.exe - Process Activities
    Thread Overview:
   ime Number of threads
 fter 20 seconds 1
   fter 30 seconds 0
  
  Foreign Memory Regions Read:
   rocess: C:\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE

 . drwtsn32.exe
    General information about this executable
   nalysis Reason: Started by 2VMP~1.EXE
   ilename: drwtsn32.exe
   D5: c9f5e1de6da983e89e714ed80c11f000
   HA-1: 1717b633478fb107d3c26344f710328b93ae550c
   ile Size: 45568 Bytes
 ommand Line: C:\WINDOWS\system32\drwtsn32 -p 480 -e 116 -g
   rocess-status at analysis end: dead
   xit Code: 0
  
  Load-time Dlls
  
  Run-time Dlls
  
 .a) drwtsn32.exe - Registry Activities
    Registry Values Modified:
  
  Registry Values Read:
  
 .b) drwtsn32.exe - File Activities
    Files Created:
   :\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log
 :\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp

  Files Read:
   :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE
 :\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log
 IPE\lsarpc

  Files Modified:
   IPE\lsarpc

  Directories Created:
   :\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson

  File System Control Communication:
   ile Control Code Times
 IPE\lsarpc  0x0011C017  3
  
  Device Control Communication:
   ile Control Code Times
 nnamed file  0x3735560  7
  
  Memory Mapped Files:
  
 .c) drwtsn32.exe - Process Activities
    Remote Threads Created:
   ffected Process
 :\DOCUME~1\andy\LOCALS~1\Temp\IXP000.TMP\2VMP~1.EXE

  Thread Overview:
   ime Number of threads
 fter 32 seconds 1
   fter 34 seconds 0
   fter 35 seconds 0
  

[ 本帖最后由 lanvin 于 2007-11-11 21:17 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
nosferatu
头像被屏蔽
发表于 2007-11-11 21:18:46 | 显示全部楼层
avira pass
Nerazzurri
发表于 2007-11-11 21:20:32 | 显示全部楼层

上报

Hello,

sample.exek - Trojan.Win32.Pakes.box

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Vladimir Krylov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

[ 本帖最后由 Kav6.0 于 2007-11-11 22:03 编辑 ]
9998053
发表于 2007-11-11 21:21:15 | 显示全部楼层
kv2008 pass
无尽藏海
发表于 2007-11-11 21:39:24 | 显示全部楼层
过红伞
A-Squared  Found nothing
AntiVir  Found nothing
ArcaVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found Win32/PolyCrypt  
BitDefender  Found nothing
ClamAV  Found nothing
CPsecure  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
F-Secure Anti-Virus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
Panda Antivirus  Found nothing
Rising Antivirus  Found nothing
Sophos Antivirus  Found nothing
VirusBuster  Found nothing
VBA32  Found Backdoor.XiaoBird.226 (paranoid heuristics)
平淡
发表于 2007-11-11 21:42:25 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qigang
发表于 2007-11-11 22:11:01 | 显示全部楼层
很多没报,真是够毒。。
BING126
头像被屏蔽
发表于 2007-11-11 22:57:39 | 显示全部楼层
文件 sample.EXE 接收于 2007.11.11 15:45:57 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32007.11.10.02007.11.09-
AntiVir7.6.0.342007.11.09-
Authentium4.93.82007.11.10-
Avast4.7.1074.02007.11.10-
AVG7.5.0.5032007.11.11Win32/PolyCrypt
BitDefender7.22007.11.11-
CAT-QuickHeal9.002007.11.10-
ClamAV0.91.22007.11.11-
DrWeb4.44.0.091702007.11.11-
eSafe7.0.15.02007.11.08-
eTrust-Vet31.2.52842007.11.09-
Ewido4.02007.11.11-
FileAdvisor12007.11.11-
Fortinet3.11.0.02007.10.19-
F-Prot4.4.2.542007.11.10-
F-Secure6.70.13030.02007.11.10-
IkarusT3.1.1.122007.11.11Trojan-Downloader.Win32.Delf.asz
Kaspersky7.0.0.1252007.11.11-
McAfee51602007.11.09-
Microsoft1.30072007.11.11-
NOD32v226522007.11.11-
Norman5.80.022007.11.09-
Panda9.0.0.42007.11.10-
Rising20.17.62.002007.11.11-
Sophos4.23.02007.11.11-
Sunbelt2.2.907.02007.11.09-
Symantec102007.11.11-
TheHacker6.2.9.1232007.11.10-
VBA323.12.2.42007.11.11suspected of Backdoor.XiaoBird.226 (paranoid heuristics)
VirusBuster4.3.26:92007.11.11-
Webwasher-Gateway6.0.12007.11.11Trojan.Hupigon.Gen
cy6266812
发表于 2007-11-11 23:34:11 | 显示全部楼层
AVAST没报
uhthn2002
发表于 2007-11-12 00:22:47 | 显示全部楼层
Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Standard Database - 850
Paranoia Database - 48663
Heuristics Analysis - Excessive
Scan in - C:\Documents and Settings\Uhthn\Desktop\sample.EXE

C:\Documents and Settings\Uhthn\Desktop\sample.EXE - Infected BACKDOOR.PCCLIENT.1 - Deleted

1 Files scanned
1 Infected files found
0 Suspected files found
0 Files disinfected
1 Files deleted
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 06:20 , Processed in 0.124867 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表