本帖最后由 ssama 于 2010.7.31 09:21 编辑
to avast!
Executing: e:\testvirus\cctv8\cctv8.exe
SetWindowsHookEx()
CreateEvent(OleDfRootBD464642EDF82FB7)
CreateProcess((null),libeay32.dll,(null))
CreateProcess((null),msvcr80.dll,(null))
CreateToolhelp32Snapshot()
CreateFile(C:\2010\7\31.txt)
[ceDirectory(C:\WINDOWS\Winsows Publsnx)
CreateFile(E:\TestVirus\CCTV8\CCTV8.exe)
Creolor=#FF0000]CreateProcess((null),E:\TestVirus\CCTV8\CCTV8.exe,(null))
CreateFile(C:\Windows\system32\2.txt)
CreateDirectory(C:\Program Files\Winsows Publsnx)
CreatateFile(C:\Program Files\Winsows Publsnx\services.exe.txt) Move(C:\Program Files\Winsows Publsnx\services.exe.txt->C:\Program Files\Winsows Publsnx\services.exe)
CreateFile(C:\WINDOWS\Winsows Publsnx\services.exe.txt)
Move(C:\WINDOWS\Winsows Publsnx\services.exe.txt->C:\WINDOWS\Winsows Publsnx\services.exe)
RegSetValue(HKLM\SOFTWARE\ws NT\CurrentVersion\LanguagePack\SurrogateFallback\.inl,fileinl)
RegSetValueEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\(null), REG_SZ: fileinl)
RegSetValue(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\fileinl\DefaultIcon,%SystemRoot%\System32\shell32.dll,-151)
RegSetValueEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\(null), REG_SZ: %SystemRoot%\System32\shell32.dll,-151)
RegSetValue(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\fileinl\Shell\read,打开)
RegSetValueEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\(null), REG_SZ: 打开)
RegSetValue(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\fileinl\Shell\read\Command,C:\WINDOWS\Winsows Publsnx\services.exe "%1")
RegSetValueEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\(null), REG_SZ: C:\WINDOWS\Winsows Publsnx\services.exe "%1")
CreateFile(C:\Users\Shamrock\「开始」菜单\程序\启动\win.inl)
CreateFile(C:\Users\Shamrock\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\win.inl)
CreateFile(C:\Users\Shamrock\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat)
CreateFile(C:\Users\Shamrock\AppData\Roaming\Microsoft\Windows\Cookies\index.dat)
CreateFile(C:\Users\Shamrock\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat)
RegDeleteValue(HKCU\Software\Microsoft\Internet Explorer\LowRegistry\AddToFavoritesInitialSelection)
RegDeleteValue(HKCU\Software\Microsoft\Internet Explorer\LowRegistry\AddToFeedsInitialSelection)
DeleteFile(C:\Users\Shamrock\AppData\Local\Temp\~DFECE1.tmp)
|