查看: 3669|回复: 16
收起左侧

[病毒样本] 360报的,不敢删除,请大家看看

[复制链接]
fpp1987
发表于 2008-1-24 16:01:32 | 显示全部楼层 |阅读模式
两个。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2008-1-24 16:08:47 | 显示全部楼层
卡巴不报,上报
wangjay1980
发表于 2008-1-24 16:09:10 | 显示全部楼层
你把IO.DLL文件的名字改成UrlMon.dll,在用360扫扫,看看报不报

另一个FON文件删了吧,当是垃圾文件

[ 本帖最后由 wangjay1980 于 2008-1-24 16:10 编辑 ]
zwl2828
发表于 2008-1-24 16:33:53 | 显示全部楼层
00029A0C   75C8A60C      0   Downloaded Program Files
00029A28   75C8A628      0   Software\Microsoft\Code Store Database\NT5LockDownTest
00029A64   75C8A664      0   DllRegisterServer
00029AB3   75C8A6B3      0   u\Downloaded Program Files\
00029AD0   75C8A6D0      0   \Downloaded Components\
00029AE8   75C8A6E8      0   \Downloaded ActiveX Controls\
00029B08   75C8A708      0   \OC Cache\
00029B14   75C8A714      0   \Occache\
00029B20   75C8A720      0   {SUB_CLCID}
00029B2C   75C8A72C      0   {SUB_OLCID}
00029B38   75C8A738      0   iesetup.cif
00029B44   75C8A744      0   feature=
00029B50   75C8A750      0   JITSetupPage
00029B60   75C8A760      0   Software\Microsoft\Active Setup
00029B80   75C8A780      0   Software\Microsoft\Active Setup\Declined Install On Demand IEv5
00029BC0   75C8A7C0      0   Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
00029C08   75C8A808      0   Status
00029C3C   75C8A83C      0   Win95
00029C44   75C8A844      0   WinNT
00029C4C   75C8A84C      0   Abstract
00029C78   75C8A878      0   \shdocvw.dll
00029C88   75C8A888      0   Software\Microsoft\Windows\CurrentVersion\Uninstall
00029CBC   75C8A8BC      0   AuthorizedCDFPrefix

00075F4C   75CDEF4C      0   [RegBackup.HKLM]
00075F5E   75CDEF5E      0   HKLM,"%PATH_ZONES%"
00075F73   75CDEF73      0   HKLM,"%PATH_TEMPOL%"
00075F89   75CDEF89      0   HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache"
00075FE9   75CDEFE9      0   [Reg.HKLM]
00075FF5   75CDEFF5      0   RequiredEngine=SETUPAPI, %EngineErrorMsg%
00076020   75CDF020      0   AddReg=Zones.RegLM,TemplatePolicies.RegLM,ZoneMap.RegLM,UATokens.RegLM,ProtocolSwitches,DefaultBinaryBehaviors
00076090   75CDF090      0   [UnReg.HKLM]
0007609E   75CDF09E      0   RequiredEngine=SETUPAPI, %EngineErrorMsg%
000760C9   75CDF0C9      0   DelReg=Zones.RegLM,TemplatePolicies.RegLM,UATokens.RegLM
00076103   75CDF103      0   [ProtocolSwitches]
00076117   75CDF117      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL"
00076174   75CDF174      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL","SAPLOGON.exe",0x10001,0x0
000761EC   75CDF1EC      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL","SAPfewgsrv.exe",0x10001,0x0
00076266   75CDF266      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL","iexplore.exe",0x10001,0x1
000762DE   75CDF2DE      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL","explorer.exe",0x10001,0x1
File pos   Mem pos      ID   Text
========   =======      ==   ====
00076356   75CDF356      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL","*",0x10001,0x1
000763C3   75CDF3C3      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BEHAVIORS"
00076416   75CDF416      0   HKLM,"Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS","infopath.exe",0x10001,0x0
00076484   75CDF484      0   HKLM,"Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS","msn6.exe",0x10001,0x0
000764EE   75CDF4EE      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BEHAVIORS","iexplore.exe",0x10001,0x1
0007655C   75CDF55C      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BEHAVIORS","explorer.exe",0x10001,0x1
000765CA   75CDF5CA      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BEHAVIORS","*",0x10001,0x1
0007662D   75CDF62D      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_OBJECT_CACHING"
00076685   75CDF685      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_OBJECT_CACHING","iexplore.exe",0x10001,0x1
000766F8   75CDF6F8      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_OBJECT_CACHING","explorer.exe",0x10001,0x1
0007676B   75CDF76B      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION"
000767C3   75CDF7C3      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION","iexplore.exe",0x10001,0x1
00076836   75CDF836      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION","explorer.exe",0x10001,0x1
000768A9   75CDF8A9      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING"
00076900   75CDF900      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING","iexplore.exe",0x10001,0x1
00076972   75CDF972      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING","explorer.exe",0x10001,0x1
000769E4   75CDF9E4      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING"
00076A3B   75CDFA3B      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING","iexplore.exe",0x10001,0x1
00076AAD   75CDFAAD      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING","explorer.exe",0x10001,0x1
00076B1F   75CDFB1F      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WINDOW_RESTRICTIONS"
00076B7C   75CDFB7C      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WINDOW_RESTRICTIONS","iexplore.exe",0x10001,0x1
00076BF4   75CDFBF4      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WINDOW_RESTRICTIONS","explorer.exe",0x10001,0x1
00076C6C   75CDFC6C      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT"
00076CCB   75CDFCCB      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT","iexplore.exe",0x10001,0x1
00076D45   75CDFD45      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT","explorer.exe",0x10001,0x1
00076DBF   75CDFDBF      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN"
00076E1E   75CDFE1E      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN","iexplore.exe",0x10001,0x1
00076E98   75CDFE98      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN","explorer.exe",0x10001,0x1
00076F12   75CDFF12      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN"
00076F6D   75CDFF6D      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN","iexplore.exe",0x10001,0x0
00076FE3   75CDFFE3      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN","explorer.exe",0x10001,0x0
00077059   75CE0059      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT"
000770B4   75CE00B4      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT","iexplore.exe",0x10001,0x1
0007712A   75CE012A      0   HKLM,"Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT","explorer.exe",0x10001,0x1
000771A0   75CE01A0      0   HKLM, "%SMWCV%\Internet Settings\User Agent\Post Platform","%XPSP2_UA_TOKEN%",,""
000771F3   75CE01F3      0   [DefaultBinaryBehaviors]
0007720D   75CE020D      0   HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedBehaviors"
00077262   75CE0262      0   HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedBehaviors","#default#VML",0x10001,0x0
000772D2   75CE02D2      0   [Intranet.HackActiveX]
000772EA   75CE02EA      0   RequiredEngine=SETUPAPI, %EngineErrorMsg%
00077315   75CE0315      0   AddReg=Intranet.USActiveX
00077330   75CE0330      0   [Intranet.USActiveX]
00077346   75CE0346      0   HKCU,"%PATH_ZONES_INTRANET%","1201",0x10001,0x3
00077378   75CE0378      0   [Internet.HackActiveX]
00077390   75CE0390      0   RequiredEngine=SETUPAPI, %EngineErrorMsg%
000773BB   75CE03BB      0   AddReg=Internet.USActiveX
000773D6   75CE03D6      0   [Internet.USActiveX]
000773EC   75CE03EC      0   HKCU,"%PATH_ZONES_INTERNET%","1201",0x10001,0x3
0007741D   75CE041D      0   [Zones.RegCU]
T-G001
发表于 2008-1-24 16:38:38 | 显示全部楼层
呵呵,2楼挺好玩的
冷冷
发表于 2008-1-24 16:40:10 | 显示全部楼层

回复 4楼 zwl2828 的帖子

那是什么呢?
sam.to
发表于 2008-1-24 17:28:15 | 显示全部楼层
http://virscan.org/report/3f1930e3ea6c1df38bc9ae50e4aff4d8.html

Hello.
No malicious software was found in the attached file.
-----------------
Regards, Yury Nesmachny
Virus Analyst, Kaspersky Lab.

Ph.: +7(495) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com
wangjay1980
发表于 2008-1-24 17:32:18 | 显示全部楼层

回复 7楼 kato9096 的帖子

DLL是微软的文件
qigang
发表于 2008-1-24 20:08:46 | 显示全部楼层
不是病毒!


360误报!
小飞侠.net
发表于 2008-1-27 04:23:31 | 显示全部楼层
原帖由 qigang 于 2008-1-24 20:08 发表
不是病毒!


360误报!

准确的说是文件名+MD5
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-25 15:26 , Processed in 0.133295 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表