本帖最后由 c/mm 于 2018-8-13 01:38 编辑
Dr.WEB实机测试 扫描MISS 双击拦截部分 但还是悲催的被替换关联文件 大部分系统关联程序无法运行 破坏系统文件 禁止用户使用任务管理器 结束进程 禁止用户访问注册表等,无限CMD.EXE弹窗 更改鼠标样式 %windows%下生成隐藏木马EXE文件并且有加驱服务随机生成SYS文件!
Preventive Protection event: Modify protected disk sectors
id: 7172, timestamp: 01:00:09.690, type: FileVolWrite (1), flags: 1 (wait: 1)
sid: S-1-5-21-839627113-1048685324-2973982688-1001, cid: 11528/7972:\Device\HarddiskVolume3\Users\cb8217\Desktop\123\王境泽病毒.exe
context: start addr: 0x1206040, image: 0x400000:\Device\HarddiskVolume3\Users\cb8217\Desktop\123\王境泽病毒.exe
hips: type: 2, action: deny [5]
type: 0, new: 1, cmd: "C:\Users\cb8217\Desktop\123\王境泽病毒.exe"
fileinfo: size: 12213248, easize: 40, attr: 0x20, buildtime: 12.08.2018 21:09:42.000, ctime: 12.08.2018 23:52:25.687, atime: 13.08.2018 00:59:58.986, mtime: 12.08.2018 21:09:44.000, descr: 真香!, ver: 1.0.0.0, company: CHN星空 QQ2970427073, oname:
hash: d4717ec67b2744f1fb2377edf0f7a044129dfe62 status: unsigned, pe32, new_pe / unsigned / unknown / unknown
object: \Device\Harddisk0\DR0
area: Protective MBR [5], offset: 0x0, size: 512
\Device\HarddiskVolume3\Users\cb8217\Desktop\123\王境泽病毒.exe-11528!\Device\Harddisk0\DR0/Protective MBR ==> Ok
send user blocked alert
id: 7172 ==> denied [5], time: 20.872792 ms
Preventive Protection event: Change protected value
id: 8291, timestamp: 01:00:27.645, type: RegSetValue (14), flags: 1 (wait: 1)
sid: S-1-5-21-839627113-1048685324-2973982688-1001, cid: 10436/10480:\Device\HarddiskVolume3\Windows\3.exe
context: start addr: 0x4dd3e0, image: 0x400000:\Device\HarddiskVolume3\Windows\3.exe
hips: type: 9, action: deny [5]
cmd: "C:\Windows\3.exe"
fileinfo: size: 344064, easize: 40, attr: 0x2, buildtime: 12.08.2018 21:04:31.000, ctime: 13.08.2018 01:00:21.299, atime: 13.08.2018 01:00:23.456, mtime: 13.08.2018 01:00:21.299, descr: 真香!, ver: 1.0.0.0, company: CHN星空 QQ2970427073, oname:
hash: b53dd07d87c32f091e66b51d13c21f7dc4238c43 status: unsigned, pe32, new_pe / unsigned / unknown / unknown
key: \REGISTRY\MACHINE\SOFTWARE\Classes\.exe, access: 0x0
value: , type: sz
current content:
00000000: 65 00 78 00 65 00 66 00 69 00 6c 00 65 00 00 00 e.x.e.f.i.l.e...
new content:
00000000: 65 00 78 00 65 00 00 00 e.x.e...
send user blocked alert
id: 8291 ==> denied [5], time: 0.362690 ms
Preventive Protection event: Change protected value
id: 8303, timestamp: 01:00:27.655, type: RegSetValue (14), flags: 1 (wait: 1)
sid: S-1-5-21-839627113-1048685324-2973982688-1001, cid: 10436/10480:\Device\HarddiskVolume3\Windows\3.exe
context: start addr: 0x4dd3e0, image: 0x400000:\Device\HarddiskVolume3\Windows\3.exe
hips: type: 9, action: deny [5]
cmd: "C:\Windows\3.exe"
fileinfo: size: 344064, easize: 40, attr: 0x2, buildtime: 12.08.2018 21:04:31.000, ctime: 13.08.2018 01:00:21.299, atime: 13.08.2018 01:00:23.456, mtime: 13.08.2018 01:00:21.299, descr: 真香!, ver: 1.0.0.0, company: CHN星空 QQ2970427073, oname:
hash: b53dd07d87c32f091e66b51d13c21f7dc4238c43 status: unsigned, pe32, new_pe / unsigned / unknown / unknown
key: \REGISTRY\MACHINE\SOFTWARE\Classes\.bat, access: 0x0
value: , type: sz
current content:
00000000: 62 00 61 00 74 00 66 00 69 00 6c 00 65 00 00 00 b.a.t.f.i.l.e...
new content:
00000000: 62 00 61 00 74 00 00 00 b.a.t...
send user blocked alert
id: 8303 ==> denied [5], time: 0.312300 ms
服务已安装在系统中。
服务名称: hyf55
服务文件名: C:\Users\cb8217\AppData\Local\Temp\RD5D39O.sys
服务类型: 内核模式驱动程序
服务启动类型: 按需启动
服务帐户:
服务已安装在系统中。
服务名称: hyf55
服务文件名: C:\Users\cb8217\AppData\Local\Temp\l49M87Y.sys
服务类型: 内核模式驱动程序
服务启动类型: 按需启动
服务帐户:
DrWeb ARKApi: Neutralized object: \device\harddiskvolume3\users\cb8217\appdata\local\temp\l49m87y.sys - deleted [threat name: {Trojan.Rootkit.22030:1}, action: 2, type: 0, ret: 8]
DrWeb ARKApi: cure service: name = \Registry\Machine\System\ControlSet001\Services\hyf55, status 0x0
DrWeb ARKApi: cure service: name = \Registry\Machine\System\ControlSet001\Services\hyf55, status 0x0
DrWeb ARKApi: Neutralized object: \device\harddiskvolume3\users\cb8217\appdata\local\temp\rd5d39o.sys - deleted [threat name: {Trojan.Rootkit.22030:1}, action: 2, type: 0, ret: 8]
隐藏的可疑木马:待会上传 |