12
返回列表 发新帖
楼主: The EQs
收起左侧

[病毒样本] 老外的autorun失效N久后又开始大规模爆发了

[复制链接]
328397663
发表于 2009-3-26 23:43:46 | 显示全部楼层
Hello,

DigitalHQ.exe - Trojan.Win32.TDSS.vgj

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

LS 耐心的等候..
fatezero
发表于 2009-3-26 23:51:24 | 显示全部楼层
检测到威胁        病毒 HEUR:Trojan.Win32.Generic        DigitalHQ.exe       
启发^_^
iorikyox
发表于 2009-3-26 23:52:54 | 显示全部楼层
奇怪了,既然是新品种,为啥你的能查杀呢?
ledled
发表于 2009-3-27 00:13:06 | 显示全部楼层
to VB
wrq
发表于 2009-3-27 01:16:53 | 显示全部楼层
Warning

--------------------------------------------------------------------------------

In order not to compromise your security, this page will not be accessed


A virus or unwanted program has been detected
in the HTTP data on the requested page.

--------------------------------------------------------------------------------

Requested URL: http://bbs.kafan.cn/attachment.p ... 91&t=1238087796
Information Is the TR/Crypt.ZPACK.Gen Trojan


--------------------------------------------------------------------------------

Generated by AntiVir WebGuard 9.0.3.0, AVE 8.2.0.129, VDF 7.1.2.222
upside
发表于 2009-3-27 07:14:42 | 显示全部楼层
生成文件:
c:\autorun.inf
%Temp%\tmp1.tmp
%Temp%\tmp2.tmp
c:\RECYCLER\S-4-6-53-100021982-100010000-100024378-4092.com
%Windir%\Temp\310203.tmp
%Windir%\pchealth\ERRORREP\UserDumps\spoolsv.exe.20090327-175745-00.hdmp
%Windir%\pchealth\ERRORREP\UserDumps\spoolsv.exe.20090327-175745-00.mdmp

進程調用:
IEXPLORE.EXE %ProgramFiles%\internet explorer\iexplore.exe

建立註冊表:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\videoshow
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\videoshow\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\UserFaults
The newly created Registry Values are:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\videoshow\CLSID]
(Default) = "{6BF52A52-394A-11D3-B153-00C04F79FAA6}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\UserFaults]
%Windir%\PCHealth\ErrorRep\UserDumps\spoolsv.exe.20090327-175745-00.mdmp = DA 00 00 00 60 00 00 00 60 00 00 00 A0 00 00 00 F4 1D 00 00 00 00 00 00 05 00 01 00 28 0A 84 08 00 00 00 00 00 00 00 00 00 00 00 00 D9 07 03 00 05 00 1B 00 11 00 39 00 2D 00 22 02 30 00 30 00 05 00 00 C0 31 00 38 00 00 00 00 00 00 00 00 00 B4 7E 10 4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
UserFaultCheck = "%System%\dumprep 0 -u"
The following Registry Values were modified:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent]
(Default) = 0x0000000D
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
(Default) = 0x0000000D

試圖建立與遠程主機。連接
94.247.2.107 80
iorikyox
发表于 2009-3-27 07:48:53 | 显示全部楼层
kis8.0终于报杀了,真是羡慕2楼,不知道你的规则是如何设置的。我现在心里很怕怕
kingsheet
发表于 2009-3-27 08:34:37 | 显示全部楼层
卡巴  The requested URL http://bbs.kafan.cn/attachment.p ... e1&t=1238113885 is infected with Trojan.Win32.TDSS.vgj virus
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-7 02:33 , Processed in 0.198128 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表