查看: 4934|回复: 26
收起左侧

[病毒样本] PpDowN.exe

[复制链接]
ahzsmzkf
发表于 2008-8-9 04:10:30 | 显示全部楼层 |阅读模式
没见过这么无耻的流氓

http://mtv3gp.com/down1.htm




sltgr
发表于 2008-8-9 07:45:10 | 显示全部楼层
2008/8/9 7:43:12        Detected: Heur.Downloader        C:\Users\Niya\Downloads\PpDowN\PpDowN.exe/stream/data0002/uu.exe
zwl2828
发表于 2008-8-9 07:59:51 | 显示全部楼层
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}]
"CLSID"="{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}"
"Default Visible"="Yes"
"ButtonText"="66免费电影-6d6d.net"
"Exec"="http://www.6d6d.net"
"HotIcon"="%windir%\\system32\\66.ICO"
"Icon"="%windir%\\system32\\66.ICO"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"NoUpdateCheck"=dword:00000001
"NoJITSetup"=dword:00000001
"Disable Script Debugger"="yes"
"Show_ChannelBand"="No"
"Anchor Underline"="yes"
"Cache_Update_Frequency"="Once_Per_Session"
"Display Inline Images"="yes"
"Do404Search"=hex:01,00,00,00
"Save_Session_History_On_Exit"="no"
"Show_FullURL"="no"
"Show_StatusBar"="yes"
"Show_ToolBar"="yes"
"Show_URLinStatusBar"="yes"
"Show_URLToolBar"="yes"
"Start Page"="http://www.6d6d.net"
"Use_DlgBox_Colors"="yes"
"Search Page"="http://www.6d6d.net"
"FullScreen"="no"
"Enable AutoImageResize"="yes"
"CNSMenu"=dword:de809d5c
"CNSHint"=dword:00000001
"CNSReset"=dword:de809d5c
"CNSEnable"=dword:00000001
"CNSList"=dword:00000001
"CNSAutoUpdate"=dword:00000001
"Use Search Asst"="no"
"Search Bar"="http://www.6d6d.net"
"Enable Browser Extensions"="yes"
"NotifyDownloadComplete"="yes"
"Use FormSuggest"="yes"
"ShowedCheckBrowser"="Yes"
"Check_Associations"="Yes"
"Error Dlg Displayed On Every Error"="no"
"AddToFavoritesExpanded"=dword:00000001


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoActiveDesktopChanges"=dword:1
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName"="name"
"Source"="http://www.6d6d.net"
"SubscribedURL"="http://www.6d6d.net"
"OriginalStateInfo"=hex:18,00,00,00,64,ff,ff,ff,03,00,00,00,9d,00,00,00,0f,00,00,00,01,00,00,40
"Position"=hex:2c,00,00,00,64,ff,ff,ff,03,00,00,00,9d,00,00,00,0f,00,00,00,ec,03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00
"RestoredStateInfo"=hex:01,40,6c,74,00,00,00,00,01,00,0c,3b,30,bc,10,00,34,2d,93,7c,a4,6c,07,00
"CurrentState"=dword:40000001
"Flags"=dword:00002002
aribeth199
发表于 2008-8-9 08:32:59 | 显示全部楼层
2008-8-9 8:30:40        http://mtv3gp.com/PpDowN.exe//stream//data0002/p.exe        检测到: Heur.Downloader
Kitman
发表于 2008-8-9 09:30:08 | 显示全部楼层
The file 'PpDowN.exe' has been determined to be 'UNDER ANALYSIS'.
yeandwo
发表于 2008-8-9 10:36:23 | 显示全部楼层
avast   Win32:Lmir-RH [Trj]
BING126
头像被屏蔽
发表于 2008-8-9 11:06:12 | 显示全部楼层
McAfee miss
Palkia
发表于 2008-8-9 11:20:30 | 显示全部楼层
金山 0
sam.to
发表于 2008-8-9 15:28:13 | 显示全部楼层
上报卡巴,PCSL
sam.to
发表于 2008-8-9 16:47:40 | 显示全部楼层
Hello.
No malicious software was found in the attached file.

Please quote all when answering.


-----------------
Regards, Kirill Erakhtin
Virus Analyst, Kaspersky Lab.

Ph.: +7(095) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
http://www.kaspersky.com/trials - trial version
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-5 17:42 , Processed in 0.120117 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表