查看: 2608|回复: 13
收起左侧

[病毒样本] 鸽子

[复制链接]
tonger2003
发表于 2008-6-24 22:03:35 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aaad2008
发表于 2008-6-24 22:04:56 | 显示全部楼层
Win32:Delf-HME [Trj]
wangjay1980
发表于 2008-6-24 22:13:24 | 显示全部楼层


2008-6-24 JAY22:08:13 Win32 Cabinet Self-Extractor  Process exit C:\Documents and Settings\Owner\桌面\Chinese Simplifiedlang.exe
2008-6-24 JAY22:08:13 Win32 Cabinet Self-Extractor Denied: KLSystemData/KLStartupRegKeys/Main_Run Delete hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
2008-6-24 JAY22:08:13 Win32 Cabinet Self-Extractor Denied: KLSystemData/FD-C/ Delete C:\Documents and Settings\Owner\Local Settings\Temp\IXP000.TMP
2008-6-24 JAY22:08:13 Win32 Cabinet Self-Extractor Denied: KLSystemData/FD-C/ Delete C:\Documents and Settings\Owner\Local Settings\Temp\IXP000.TMP\100.exe
2008-6-24 JAY22:08:13 Win32 Cabinet Self-Extractor Denied: KLSystemData/FD-C/ Delete C:\Documents and Settings\Owner\Local Settings\Temp\IXP000.TMP\100.exe
2008-6-24 JAY22:07:57 Win32 Cabinet Self-Extractor Denied: KLSystemData/KLStartupRegKeys/Main_Run Modification hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
2008-6-24 JAY22:07:57 Win32 Cabinet Self-Extractor  Create C:\Documents and Settings\Owner\Local Settings\Temp\IXP000.TMP\100.exe
2008-6-24 JAY22:07:57 Win32 Cabinet Self-Extractor : KLSystemData/FD-C/ Create C:\DOCUME~1\Owner\LOCALS~1\Temp\IXP000.TMP\100.exe
2008-6-24 JAY22:07:57 Win32 Cabinet Self-Extractor : KLSystemData/FD-C/ Create C:\DOCUME~1\Owner\LOCALS~1\Temp\IXP000.TMP\TMP4351$.TMP
2008-6-24 JAY22:07:57 Win32 Cabinet Self-Extractor  Process start C:\Documents and Settings\Owner\桌面\Chinese Simplifiedlang.exe
2008-6-24 JAY22:07:57 Win32 Cabinet Self-Extractor  Placed in group Low Restricted
2008-6-24 JAY22:07:51 Windows Explorer  Rename C:\Documents and Settings\Owner\桌面\Chinese Simplifiedlang.exe
2008-6-24 JAY22:07:51 Windows Explorer  Create C:\Documents and Settings\Owner\桌面\Chinese Simplifiedlang.exe


2008-6-24 JAY22:08:13 100.exe  Process exit C:\DOCUME~1\Owner\LOCALS~1\Temp\IXP000.TMP\100.exe
2008-6-24 JAY22:08:13 100.exe Denied: KLSystemData/KLStartupRegKeys/Main_Run Delete hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
2008-6-24 JAY22:08:13 100.exe Denied: KLSystemData/FD-C/ Delete C:\Documents and Settings\Owner\Local Settings\Temp\IXP001.TMP
2008-6-24 JAY22:08:13 100.exe Denied: KLSystemData/FD-C/ Delete C:\Documents and Settings\Owner\Local Settings\Temp\IXP001.TMP\4.exe
2008-6-24 JAY22:08:13 100.exe Denied: KLSystemData/FD-C/ Delete C:\Documents and Settings\Owner\Local Settings\Temp\IXP001.TMP\4.exe
2008-6-24 JAY22:08:00 100.exe Denied: KLSystemData/KLStartupRegKeys/Main_Run Modification hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
2008-6-24 JAY22:08:00 100.exe  Create C:\Documents and Settings\Owner\Local Settings\Temp\IXP001.TMP\4.exe
2008-6-24 JAY22:08:00 100.exe : KLSystemData/FD-C/ Create C:\DOCUME~1\Owner\LOCALS~1\Temp\IXP001.TMP\4.exe
2008-6-24 JAY22:07:59 100.exe : KLSystemData/FD-C/ Create C:\DOCUME~1\Owner\LOCALS~1\Temp\IXP001.TMP\TMP4351$.TMP
2008-6-24 JAY22:07:59 100.exe  Process start C:\DOCUME~1\Owner\LOCALS~1\Temp\IXP000.TMP\100.exe
2008-6-24 JAY22:07:59 100.exe  Placed in group Low Restricted

[ 本帖最后由 wangjay1980 于 2008-6-24 22:34 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qigang
发表于 2008-6-24 22:25:15 | 显示全部楼层

5/0

RS20.50.10未杀!
LQ55
头像被屏蔽
发表于 2008-6-24 22:39:33 | 显示全部楼层
卡巴7.0没反映
yk1234
发表于 2008-6-24 22:42:04 | 显示全部楼层
Tr/Dropper.Gen
scottxzt
发表于 2008-6-25 00:29:14 | 显示全部楼层
--> Chinese Simplified.lang.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was successfully wiped!
无尽藏海
发表于 2008-6-25 00:32:12 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
a256886572008
发表于 2008-6-25 12:12:48 | 显示全部楼层
2008-06-25 12:04:18        文件保护(创建文件)     操作:使用隔离区操作
进程路径:D:\桌面\virus\Chinese Simplified.lang\4.exe
文件路径:C:\WINDOWS\system32\servicne.exe

2008-06-25 12:04:18        文件保护(修改文件)     操作:使用隔离区操作
进程路径:D:\桌面\virus\Chinese Simplified.lang\4.exe
文件路径:(隐藏文件)C:\EQSandBox\C\WINDOWS\system32\servicne.exe

2008-06-25 12:04:19        应用程序保护(访问服务管理器)     操作:使用隔离区操作
进程路径:D:\桌面\virus\Chinese Simplified.lang\4.exe


提出真毒
电影结束了
发表于 2008-6-25 12:19:06 | 显示全部楼层
F:\Chinese_Simplified.lang.rar>>Chinese Simplified.lang.exe  TrojanDropper.Gen.jpam.arc  木马
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-1 21:43 , Processed in 0.134680 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表