查看: 3448|回复: 3
收起左侧

[病毒样本] 软件里发现的可疑程序

[复制链接]
红心王子
发表于 2009-10-6 16:49:51 | 显示全部楼层 |阅读模式
md5:7c620a8c857cd2e5

安装hips或虚拟机的朋友们,可以帮忙分析下行为,

在xp变脸王里面找到的东西










[ 本帖最后由 红心王子 于 2009-10-6 16:52 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
z2665
发表于 2009-10-6 17:53:16 | 显示全部楼层
沙盘中hips。
CIMA:http://camas.comodo.com/cgi-bin/ ... 0373231a0b462cc6df5
(Drive)   \Device\CdRom0
(Drive)   \Device\CdRom1
(Drive)   \Device\HarddiskVolume1
(Drive)   \Device\HarddiskVolume2
(Drive)   \Device\HarddiskVolume3
(Drive)   \Device\HarddiskVolume4
(Unk)      00000004 \Device\Ide\IdePort0
(Unk)      00000022 \Device\SandboxieDriverApi
(Unk)      00000039 \Device\KsecDD
(Unk)      00000040 \FileSystem\Filters\FltMgrMsg
Clsid     -------------------------------
Ipc       -------------------------------
Ipc       \Sessions\1\BaseNamedObjects\!IETld!Mutex
Ipc       \Sessions\1\BaseNamedObjects\_!MSFTHISTORY!_
Ipc       \Sessions\1\BaseNamedObjects\__ComCatalogCache__
Ipc       \Sessions\1\BaseNamedObjects\17C8::DAF5B3CE49
Ipc       \Sessions\1\BaseNamedObjects\4A79EFD5::WK
Ipc       \Sessions\1\BaseNamedObjects\7CEC0261::SharedIndexInfo
Ipc       \Sessions\1\BaseNamedObjects\c:!users!z2665!appdata!local!microsoft!windows!history!history.ie5!
Ipc       \Sessions\1\BaseNamedObjects\c:!users!z2665!appdata!local!microsoft!windows!temporary internet files!content.ie5!
Ipc       \Sessions\1\BaseNamedObjects\c:!users!z2665!appdata!roaming!microsoft!windows!cookies!
Ipc       \Sessions\1\BaseNamedObjects\C:_Users_z2665_AppData_Local_Microsoft_Windows_History_History.IE5_index.dat_491520
Ipc       \Sessions\1\BaseNamedObjects\C:_Users_z2665_AppData_Local_Microsoft_Windows_Temporary Internet Files_Content.IE5_index.dat_2113536
Ipc       \Sessions\1\BaseNamedObjects\C:_Users_z2665_AppData_Roaming_Microsoft_Windows_Cookies_index.dat_81920
Ipc       \Sessions\1\BaseNamedObjects\DILLOCREATE
Ipc       \Sessions\1\BaseNamedObjects\DILLOOEP
Ipc       \Sessions\1\BaseNamedObjects\LSI-4A79EFD5
Ipc       \Sessions\1\BaseNamedObjects\oleacc-msaa-loaded
Ipc       \Sessions\1\BaseNamedObjects\RAL4A79EFD5
Ipc       \Sessions\1\BaseNamedObjects\SbieDllDummyEvent_6088
Ipc       \Sessions\1\BaseNamedObjects\SbieDllDummyEvent_724
Ipc       \Sessions\1\BaseNamedObjects\SbieServiceInitComplete_RpcSs
Ipc       \Sessions\1\BaseNamedObjects\windows_shell_global_counters
Ipc    O  \...\WerTargetListTable
Ipc    O  \BaseNamedObjects\msctf.serverDefault1
Ipc    O  \BaseNamedObjects\Sandboxie_DeviceIdList
Ipc    O  \BaseNamedObjects\Sandboxie_DeviceSetupClasses
Ipc    O  \KnownDlls\advapi32.dll
Ipc    O  \KnownDlls\clbcatq.dll
Ipc    O  \KnownDlls\COMDLG32.dll
Ipc    O  \KnownDlls\gdi32.dll
Ipc    O  \KnownDlls\IERTUTIL.dll
Ipc    O  \KnownDlls\kernel32.dll
Ipc    O  \KnownDlls\LPK.dll
Ipc    O  \KnownDlls\MSCTF.dll
Ipc    O  \KnownDlls\MSVCRT.dll
Ipc    O  \KnownDlls\NORMALIZ.dll
Ipc    O  \KnownDlls\NSI.dll
Ipc    O  \KnownDlls\ole32.dll
Ipc    O  \KnownDlls\OLEAUT32.dll
Ipc    O  \KnownDlls\PSAPI.DLL
Ipc    O  \KnownDlls\rpcrt4.dll
Ipc    O  \KnownDlls\Setupapi.dll
Ipc    O  \KnownDlls\SHELL32.dll
Ipc    O  \KnownDlls\SHLWAPI.dll
Ipc    O  \KnownDlls\URLMON.dll
Ipc    O  \KnownDlls\user32.dll
Ipc    O  \KnownDlls\USP10.dll
Ipc    O  \KnownDlls\WININET.dll
Ipc    O  \KnownDlls\WLDAP32.dll
Ipc    O  \KnownDlls\WS2_32.dll
Ipc    O  \LsaAuthenticationPort
Ipc    O  \NLS\NlsSectionSortkey0000080450100
Ipc    O  \RPC Control\RasmanRpc
Ipc    O  \RPC Control\SbieSvcPort
Ipc    O  \RPC Control\senssvc
Ipc    O  \Security\LSA_AUTHENTICATION_INITIALIZED
Ipc    O  \Sessions\1\BaseNamedObjects\CicLoadWinStaWinSta0
Ipc    O  \Sessions\1\BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-2556411077-3557072073-1268221902-1000
Ipc    O  \Sessions\1\BaseNamedObjects\DBWinMutex
Ipc    O  \Sessions\1\BaseNamedObjects\Dwm-1953-ApiPort-53FB
Ipc    O  \Sessions\1\BaseNamedObjects\MSCTF.Asm.MutexDefaultS-1-5-21-2556411077-3557072073-1268221902-1000
Ipc    O  \Sessions\1\BaseNamedObjects\MSCTF.CtfMonitorInstMutexDefault1
Ipc    O  \Sessions\1\BaseNamedObjects\RasPbFile
Ipc    O  \Sessions\1\BaseNamedObjects\WininetConnectionMutex
Ipc    O  \Sessions\1\BaseNamedObjects\WininetProxyRegistryMutex
Ipc    O  \Sessions\1\BaseNamedObjects\WininetStartupMutex
Ipc    O  \Sessions\1\Windows\ApiPort
Ipc    O  \Sessions\1\Windows\SharedSection
Ipc    O  \ThemeApiPort
Ipc    O  \UxSmsApiPort
Ipc    X  \BaseNamedObjects\{4AD5C1B1-C922-46dc-87EB-EEEEA805350C}
Ipc    X  \Sessions\1\BaseNamedObjects\!IETld!Mutex
Ipc    X  \Sessions\1\BaseNamedObjects\_!MSFTHISTORY!_
Ipc    X  \Sessions\1\BaseNamedObjects\c:!users!z2665!appdata!local!microsoft!windows!history!history.ie5!
Ipc    X  \Sessions\1\BaseNamedObjects\c:!users!z2665!appdata!local!microsoft!windows!temporary internet files!content.ie5!
Ipc    X  \Sessions\1\BaseNamedObjects\c:!users!z2665!appdata!roaming!microsoft!windows!cookies!
Ipc    X  \Sessions\1\BaseNamedObjects\C:_Users_z2665_AppData_Local_Microsoft_Windows_History_History.IE5_index.dat_491520
Ipc    X  \Sessions\1\BaseNamedObjects\C:_Users_z2665_AppData_Local_Microsoft_Windows_Temporary Internet Files_Content.IE5_index.dat_2113536
Ipc    X  \Sessions\1\BaseNamedObjects\C:_Users_z2665_AppData_Roaming_Microsoft_Windows_Cookies_index.dat_81920
Ipc    X  \Sessions\1\BaseNamedObjects\windows_shell_global_counters
Pipe      -------------------------------
Pipe      \Device\Mailslot\server\001D0656
Pipe      \Device\Mailslot\server\002C05CC
Pipe   X  \Device\Mailslot\server
Pipe   X  \Device\Mailslot\server\001D0656
Pipe   X  \Device\Mailslot\server\002C05CC
Pipe   X  \Device\NamedPipe\lsarpc
WinCls    -------------------------------
WinCls O  *:Dd24.exe
WinCls O  CicLoaderWndClass
WinCls O  MS_WebcheckMonitor
WinCls O  Shell_TrayWnd
WinCls O  SystemTray_Main
WinCls X  Button
WinCls X  CiceroUIWndFrame
WinCls X  ComboLBox
WinCls X  DDEMLEvent
WinCls X  Edit
WinCls X  FileMonClass
WinCls X  IME
WinCls X  MSCTFIME UI
WinCls X  PROCMON_WINDOW_CLASS
WinCls X  Progman
WinCls X  RegMonClass
WinCls X  ThunderRT6FormDC
WinCls X  tooltips_class32
WinCls X  WorkerW

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
尤金卡巴斯基
发表于 2009-10-6 18:44:13 | 显示全部楼层
2009/10/6 18:43:26        已删除        木马程序 Trojan.Win32.Genome.ehq        G:\Temp\Virus\Dd24\Dd24.exe
IllusionWing
发表于 2009-10-7 12:09:59 | 显示全部楼层
FP吧
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-17 14:18 , Processed in 0.151674 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表