12
返回列表 发新帖
楼主: mofunzone
收起左侧

[病毒样本] dhcpsrv.exe [md5:fc48ed]

[复制链接]
BING126
头像被屏蔽
发表于 2008-5-13 20:29:24 | 显示全部楼层
McAfee  MISS
qigang
发表于 2008-5-13 20:32:13 | 显示全部楼层

回复 9楼 qianwenxiang 的帖子

RS20.44.12未杀!
qigang
发表于 2008-5-13 20:33:01 | 显示全部楼层

2/0

RS20.44.12未杀!
Palkia
发表于 2008-5-13 21:51:45 | 显示全部楼层
nothing~
allinwonderi
发表于 2008-5-13 22:17:48 | 显示全部楼层
TO Frisk
电影结束了
发表于 2008-5-13 22:23:48 | 显示全部楼层
那个下载下来的...
这个东西很好....
过了TF默认规则....

The following Registry Keys were created:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NEW_DRV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NEW_DRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NEW_DRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\new_drv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\new_drv\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\new_drv\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NEW_DRV
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NEW_DRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NEW_DRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv\Enum
HKEY_USERS\.DEFAULT\Software\Microsoft\InetData
HKEY_CURRENT_USER\Software\Microsoft\InetData
The newly created Registry Values are:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NEW_DRV\0000\Control]
*NewlyCreated* = 0x00000000
ActiveService = "new_drv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NEW_DRV\0000]
Service = "new_drv"
Legacy = 0x00000001
ConfigFlags = 0x00000000
Class = "LegacyDriver"
ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
DeviceDesc = "!!!!"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NEW_DRV]
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\new_drv\Enum]
0 = "Root\LEGACY_NEW_DRV\0000"
Count = 0x00000001
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\new_drv\Security]
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\new_drv]
Type = 0x00000001
Start = 0x00000003
ErrorControl = 0x00000000
ImagePath = "%Windir%\new_drv.sys"
DisplayName = "!!!!"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NEW_DRV\0000\Control]
*NewlyCreated* = 0x00000000
ActiveService = "new_drv"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NEW_DRV\0000]
Service = "new_drv"
Legacy = 0x00000001
ConfigFlags = 0x00000000
Class = "LegacyDriver"
ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
DeviceDesc = "!!!!"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NEW_DRV]
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv\Enum]
0 = "Root\LEGACY_NEW_DRV\0000"
Count = 0x00000001
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv\Security]
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv]
Type = 0x00000001
Start = 0x00000003
ErrorControl = 0x00000000
ImagePath = "%Windir%\new_drv.sys"
DisplayName = "!!!!"
[HKEY_CURRENT_USER\Software\Microsoft\InetData]
k1 = 0x79FCEEF5
k2 = 0x4E037159
version = "230"
Attention! The newly created hidden Registry Value is:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
ttool = "%Windir%\9129837.exe"

so that 9129837.exe runs every time Windows starts

The following Registry Value was deleted:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
C:\Documents and Settings\UserName\Application Data\Microsoft\Installer\ = ""
C:\WINDOWS\Installer\{4275B162-C5C0-4912-9522-E92FE1C4E21D}\ = ""
C:\Documents and Settings\UserName\Application Data\Microsoft\Installer\{3966BA0C-23BA-4B20-9B9D-7561DEC54E6A}\ = ""
C:\Config.Msi\ = ""
C:\Program Files\VMware\VMware Tools\Drivers\memctl\ = ""
C:\Program Files\VMware\VMware Tools\TPOG3\ = ""
C:\Program Files\VMware\VMware Tools\TPOG3\amd64\ = ""
C:\Program Files\VMware\VMware Tools\TPOG3\i386\ = ""
C:\Program Files\VMware\VMware Tools\vmci\ = ""
C:\WINDOWS\Installer\{3B410500-1802-488E-9EF1-4B11992E0440}\ = ""

[ 本帖最后由 电影结束了 于 2008-5-13 22:25 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-13 01:47 , Processed in 0.099821 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表