查看: 4619|回复: 12
收起左侧

[病毒样本] soft.yingzheng.com赢政网页被挂马

[复制链接]
绅博周幸
发表于 2007-2-10 16:10:47 | 显示全部楼层 |阅读模式
AntiVir Found TR/Hijack.Explor.2047
ArcaVir Found Heur.Win32
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found BehavesLike:Win32.ExplorerHijack (probable variant)
ClamAV Found nothing
Dr.Web Found Trojan.DownLoader.16639
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Agent.bgm
NOD32 Found nothing
Norman Virus Control Found nothing
VirusBuster Found novirus:Packed/Upack
VBA32 Found nothing

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
七少
发表于 2007-2-10 16:14:17 | 显示全部楼层
费尔报

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
紫外线
发表于 2007-2-10 16:16:39 | 显示全部楼层
版主给的网页进8去了,自动转到首页
马力
发表于 2007-2-10 16:18:08 | 显示全部楼层
驱逐舰报杀

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
ALEXBLAIR
发表于 2007-2-10 16:23:15 | 显示全部楼层
恶心的东西
会修改系统的启动和关机脚本
当你开机和关机的时候运行和启动维护。
抢在非服务级别的杀毒软件之前启动(不过现在基本都是服务级别了

下面是调试日志(使用SSM)
Parent process:
   Path: C:\WINDOWS\explorer.exe
   PID: 1704
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
   Information: Windows Explorer (Microsoft Corporation)
Child process:
   Path: Z:\123\123.exe
   Command line:"Z:\123\123.exe"
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: Asynchronous
      Type: REG_DWORD
      Value: 00000001
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: Impersonate
      Type: REG_DWORD
      Value: 00000001
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: DllName
      Type: REG_SZ
      Value: msgcom.dll
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: Logoff
      Type: REG_SZ
      Value: StopProcessAtWinLogoff
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: Logon
      Type: REG_SZ
      Value: StartProcessAtWinLogon
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: Startup
      Type: REG_SZ
      Value: StartProcessAtStartup
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: iniurl
      Type: REG_SZ
      Value: iuuq;00xxx/274dw/dpn0wjq0274dw/uyu
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: upurl
      Type: REG_SZ
      Value: iuuq;00xxx/274dw/dpn0wjq0274dw/emm
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: lineurl
      Type: REG_SZ
      Value: iuuq;00tjbobbb/dpnbb/dnb
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Registry Group: Winlogon
Object:
   Registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cmdmant
   Registry value: timer
      Type: REG_SZ
      Value: 3
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Object:
   Path: C:\WINDOWS\explorer.exe
   Information: Windows Explorer (Microsoft Corporation)
This function is used to modify the virtual memory of another program, potentially changing its behaviour.
Process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Object:
   Path: C:\WINDOWS\explorer.exe
   Information: Windows Explorer (Microsoft Corporation)
This function is used to modify the virtual memory of another program, potentially changing its behaviour.
Parent process:
   Path: Z:\123\123.exe
   PID: 1828
   User name: [email=MINI@Administrator]MINI@Administrator[/email]
Child process:
   Path: C:\WINDOWS\system32\cmd.exe
   Information: Windows Command Processor (Microsoft Corporation)
   Command line:cmd /c C:\WINDOWS\system32\del.bat
不要怕
发表于 2007-2-10 16:43:30 | 显示全部楼层
东方微点:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\123.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\MSGCOM.DLL
删除木马程序及其衍生物!
处理结果:成功清除!
九尾野狐
头像被屏蔽
发表于 2007-2-10 16:50:10 | 显示全部楼层
NOD32  没报  

已经上报了
九尾野狐
头像被屏蔽
发表于 2007-2-10 17:03:47 | 显示全部楼层
用今天早上的病毒库没查出

升级了下病毒库后立马在下载前报警

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
鼻耳盖子
发表于 2007-2-11 12:01:44 | 显示全部楼层

微点杀

有生成物
\WINNT\SYSTEM32\MSGCOM.DLL I:\TEST\070210\12\123\123.EXE

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
pamier2001
发表于 2007-2-11 12:17:49 | 显示全部楼层
周版。。。
赢政现在的域名是winzheng,不是yingzheng
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-3 08:57 , Processed in 0.134989 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表