楼主: ghj89100062
收起左侧

[病毒样本] 华丽的全过

[复制链接]
xiaojinglf
发表于 2009-2-15 13:29:35 | 显示全部楼层
小红伞杀了
----------------------------------
增加键:
----------------------------------
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Enum

----------------------------------
增加值:
----------------------------------
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\Control\*NewlyCreated*: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\Control\ActiveService: "6to4"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\Service: "6to4"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\Legacy: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\ConfigFlags: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\Class: "LegacyDriver"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\0000\DeviceDesc: "windosme"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_6TO4\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Enum\0: "Root\LEGACY_6TO4\0000"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Enum\Count: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Enum\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Parameters\ServiceDll: "C:\WINDOWS\system32\nt6to4.dll"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Parameters\ServiceMain: "Antivirus"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Type: 0x00000020
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Start: 0x00000002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\ErrorControl: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\ImagePath: "%SystemRoot%\System32\svchost.exe -k netsvcs"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\DisplayName: "windosme"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\ObjectName: "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6to4\Description: "监测新硬件设备并自动更新设备驱动程序"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\Control\*NewlyCreated*: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\Control\ActiveService: "6to4"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\Service: "6to4"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\Legacy: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\ConfigFlags: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\Class: "LegacyDriver"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\0000\DeviceDesc: "windosme"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_6TO4\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Enum\0: "Root\LEGACY_6TO4\0000"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Enum\Count: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Enum\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Parameters\ServiceDll: "C:\WINDOWS\system32\nt6to4.dll"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Parameters\ServiceMain: "Antivirus"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Type: 0x00000020
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Start: 0x00000002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\ErrorControl: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\ImagePath: "%SystemRoot%\System32\svchost.exe -k netsvcs"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\DisplayName: "windosme"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\ObjectName: "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Description: "监测新硬件设备并自动更新设备驱动程序"

----------------------------------
修改值:
----------------------------------
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch: 0x00000016
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch: 0x00000017
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseObtainedTime: 0x49979A55
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseObtainedTime: 0x49979DE1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T1: 0x49979DD9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T1: 0x4997A165
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T2: 0x4997A07C
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T2: 0x4997A408
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseTerminatesTime: 0x4997A15D
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseTerminatesTime: 0x4997A4E9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\DhcpRetryTime: 0x00000381
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\DhcpRetryTime: 0x00000384
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseObtainedTime: 0x49979A55
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseObtainedTime: 0x49979DE1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T1: 0x49979DD9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T1: 0x4997A165
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T2: 0x4997A07C
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T2: 0x4997A408
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseTerminatesTime: 0x4997A15D
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseTerminatesTime: 0x4997A4E9
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\{38A7E5A1-78ED-46F6-95A5-37297860EED0}: 2C 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 5D A1 97 49 C0 A8 CB 02 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 5D A1 97 49 C0 A8 CB 02 03 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 5D A1 97 49 C0 A8 CB 02 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 5D A1 97 49 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 5D A1 97 49 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 5D A1 97 49 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 5D A1 97 49 C0 A8 CB FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 5D A1 97 49 05 00 00 00
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\{38A7E5A1-78ED-46F6-95A5-37297860EED0}: 2C 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 E9 A4 97 49 C0 A8 CB 02 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 E9 A4 97 49 C0 A8 CB 02 03 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 E9 A4 97 49 C0 A8 CB 02 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 E9 A4 97 49 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 E9 A4 97 49 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 E9 A4 97 49 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 E9 A4 97 49 C0 A8 CB FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 E9 A4 97 49 05 00 00 00
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch: 0x00000016
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch: 0x00000017
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseObtainedTime: 0x49979A55
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseObtainedTime: 0x49979DE1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T1: 0x49979DD9
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T1: 0x4997A165
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T2: 0x4997A07C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\T2: 0x4997A408
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseTerminatesTime: 0x4997A15D
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\LeaseTerminatesTime: 0x4997A4E9
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\DhcpRetryTime: 0x00000381
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\DhcpRetryTime: 0x00000384
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseObtainedTime: 0x49979A55
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseObtainedTime: 0x49979DE1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T1: 0x49979DD9
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T1: 0x4997A165
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T2: 0x4997A07C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\T2: 0x4997A408
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseTerminatesTime: 0x4997A15D
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{38A7E5A1-78ED-46F6-95A5-37297860EED0}\Parameters\Tcpip\LeaseTerminatesTime: 0x4997A4E9


----------------------------------
文件增加:1
----------------------------------
C:\WINDOWS\system32\nt6to4.dll
Elcondorposa
发表于 2009-2-15 14:51:12 | 显示全部楼层

回复 31楼 xiaojinglf 的帖子

为何我的红伞Premium不杀
easports1200
发表于 2009-2-15 15:07:38 | 显示全部楼层
KV2009,规则模式干掉病毒

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
weihuavip
发表于 2009-2-15 21:20:20 | 显示全部楼层
卡巴过不了吧,我下载的时候卡巴就直接报了,不关闭卡巴下载回来的包直接就废的!
makelovelc
发表于 2009-2-15 21:38:42 | 显示全部楼层
为什么我的卡巴 和 红伞都没反应
左手
发表于 2009-2-15 23:03:15 | 显示全部楼层
2009-02-15 23:02:41    修改文件      操作:阻止并结束进程
进程路径:E:\virus\大三许婷.exe
文件路径:C:\WINDOWS\system32
触发规则:所有程序规则->禁止创建文件的目录(黑名单)->%windir%\*

===========

实在不想改为阻止了,因为发现毒太BT,阻止,还死命的创建,搞的EQ那边一直在叫~~~~~~~~

[ 本帖最后由 左手 于 2009-2-15 23:04 编辑 ]
littlecho
发表于 2009-2-15 23:13:19 | 显示全部楼层
趨勢OfficeScan8沒有偵測到


已經上報給趨勢!
fzz8848
头像被屏蔽
发表于 2009-2-16 00:00:10 | 显示全部楼层

回复 35楼 makelovelc 的帖子

已入库
Begin scan in 'E:\Download\Virus\11.rar'
E:\Download\Virus\11.rar
    [0] Archive type: RAR
    --> ᄡ￳￈
zhanyuchenbobo
发表于 2009-2-16 08:38:03 | 显示全部楼层
Name :         Win32.Trojan.Agent
Alias:        Trojan.Agent
Type:        Trojan
Category:        Spyware
qihuakai
头像被屏蔽
发表于 2009-2-16 09:04:28 | 显示全部楼层
微点干掉,
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-23 00:40 , Processed in 0.085893 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表