查看: 2847|回复: 16
收起左侧

[病毒样本] usow.exe (5/42)

[复制链接]
hx1997
发表于 2010-8-2 11:06:14 | 显示全部楼层 |阅读模式
usow.exe


jayavira
发表于 2010-8-2 11:08:18 | 显示全部楼层
ess kill

  Win32/Kryptik.CKD 特洛伊木马 的变种
llzy3575
发表于 2010-8-2 11:24:06 | 显示全部楼层
to avast
gbs0856
发表于 2010-8-2 11:25:45 | 显示全部楼层
Submit to MSE & Avira
willjjyu
发表于 2010-8-2 11:43:01 | 显示全部楼层
本帖最后由 willjjyu 于 2010.8.2 11:47 编辑

  • 全部过程 (25)
    • Process ID 0, File Name: (SystemIdle),
    • Process ID 4, File Name: (System),
    • Process ID 224, File Name: C:\WINDOWS\system32\cmd.exe, File Name Hash: 2751DD6A00570674F0080506F4B6C600B64FDB50.
    • Process ID 308, File Name: C:\WINDOWS\System32\smss.exe, File Name Hash: 33A0AB030064EFA6C69B00AD18ED030054CE3826.
    • Process ID 364, File Name: C:\WINDOWS\system32\cmd.exe /c C:\DOCUME~1\Dave\LOCALS~1\Temp\tmpb80dc665.bat, File Name Hash:2751DD6A00570674F0080506F4B6C600B64FDB50.
    • Process ID 428, File Name: C:\WINDOWS\system32\csrss.exe, File Name Hash: B4E7351200C6D8C218E800665DD0AE001975146F.
    • Process ID 452, File Name: C:\WINDOWS\system32\winlogon.exe, File Name Hash: 65AC26F6009EAAB8C01307D21BFA850005C731B9.
    • Process ID 504, File Name: C:\WINDOWS\system32\services.exe, File Name Hash: 2C560F210066FD4CA85C016C25DE39002D329A6C.
    • Process ID 516, File Name: C:\WINDOWS\system32\lsass.exe, File Name Hash: 09DB5EC900AF6D2D3445003B3C2E07008DAECC19.
    • Process ID 664, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
    • Process ID 744, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
    • Process ID 780, File Name: C:\WINDOWS\System32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
    • Process ID 852, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
    • Process ID 932, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
    • Process ID 1112, File Name: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe, File Name Hash: 33C29C7400B37D5834BB02990540530056CA390E.
    • Process ID 1136, File Name: C:\WINDOWS\Explorer.EXE, File Name Hash: 7BA51796002B8BEEC6F00FDC583A42008EE45077.
    • Process ID 1288, File Name: C:\WINDOWS\system32\spoolsv.exe, File Name Hash: 2C3E540B00AFB573E240000320EF83001114DA67.
    • Process ID 1416, File Name: C:\WINDOWS\system32\cmd.exe, File Name Hash: 2751DD6A00570674F0080506F4B6C600B64FDB50.
    • Process ID 1584, File Name: C:\WINDOWS\system32\wuauclt.exe, File Name Hash: 5D9EF4ECE0722577D09600DE168DCC00EF2F8802.
    • Process ID 1628, File Name: C:\69147381.exe, File Name Hash: hash_error.
    • Process ID 1840, File Name: C:\WINDOWS\system32\wbem\wmiprvse.exe, File Name Hash: B38ABA89005EF55F549603092FD48400AE03A0D3.
    • Process ID 1916, File Name: C:\WINDOWS\system32\wscntfy.exe, File Name Hash: 8FBFA6FA00E6E09B3694001AFC0EFA001CA5DA83.
    • Process ID 1956, File Name: C:\WINDOWS\System32\alg.exe, File Name Hash: B789899500A84BB2AEC2005EDE65FA004F6B7ADA.
    • Process ID 2032, File Name: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe, File Name Hash: D6ADD7F570B8CCAB8BE800659CBCA80027D54BA7.
    • Process ID 2044, File Name: C:\WINDOWS\system32\ctfmon.exe, File Name Hash: CB94C76000E5509F3C0D00C310E23300C6DC8A05.
    • 打开的文件

      • File: \\.\PIPE\lsarpc
      • File Type: namedpipe
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS
      • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
      • Flags: SECURITY_ANONYMOUS
      • Quantity: 4

      • File: C:\69147381.exe
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS
      • Share Access: FILE_SHARE_READ
      • Flags: SECURITY_ANONYMOUS
      • Quantity: 2

      • File: C:\Documents and Settings\Dave\Application Data
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS
      • Share Access: FILE_SHARE_DELETE FILE_SHARE_READ FILE_SHARE_WRITE
      • Flags: SECURITY_ANONYMOUS

      • File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
      • File Type: file
      • Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
      • Share Access: FILE_SHARE_READ
      • Flags: SECURITY_ANONYMOUS
      • Stored as: 4702b064ec87544b635e2df7c43910d8.exe

      • File: C:\Documents and Settings\Dave\Application Data\Woyqy
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
      • Share Access: FILE_SHARE_READ
      • Flags: SECURITY_ANONYMOUS

      • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
      • Share Access: FILE_SHARE_READ
      • Flags: SECURITY_ANONYMOUS

      • File: C:\Documents and Settings\Dave\Application Data\Miifny
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
      • Share Access: FILE_SHARE_READ
      • Flags: SECURITY_ANONYMOUS

      • File: C:\WINDOWS\AppPatch\sysmain.sdb
      • File Type: file
      • Source File Hash: 178984DA5623C3D05AF212C03BD2D300E4481614
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS FILE_READ_ATTRIBUTES
      • Share Access: FILE_SHARE_READ
      • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
      • Quantity: 2

      • File: C:\WINDOWS\AppPatch\systest.sdb
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS FILE_READ_ATTRIBUTES
      • Share Access: FILE_SHARE_READ
      • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
      • Quantity: 2

      • File: \Device\NamedPipe\ShimViewer
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE FILE_ADD_SUBDIRECTORY FILE_APPEND_DATA FILE_CREATE_PIPE_INSTANCE FILE_WRITE_EA FILE_WRITE_ATTRIBUTES
      • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
      • Quantity: 2

      • File: C:\Documents and Settings\Dave\Application Data\Woyqy\
      • File Type: file
      • Source File Hash: hash_error
      • Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY
      • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
      • Flags: SECURITY_ANONYMOUS

      • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
      • File Type: file
      • Source File Hash: hash_error
      • Creation/Distribution: OPEN_EXISTING
      • Desired Access: FILE_ANY_ACCESS
      • Share Access: FILE_SHARE_READ
      • Flags: SECURITY_ANONYMOUS

      • File: C:\WINDOWS\system32\
      • File Type: file
      • Source File Hash: hash_error
      • Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY
      • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
      • Flags: SECURITY_ANONYMOUS
      • 创建的文件

        • File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
        • File Type: file
        • Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
        • Creation/Distribution: CREATE_ALWAYS
        • Desired Access: FILE_ANY_ACCESS
        • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
        • Stored as: 4702b064ec87544b635e2df7c43910d8.exe

        • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
        • File Type: file
        • Source File Hash: hash_error
        • Creation/Distribution: CREATE_ALWAYS
        • Desired Access: FILE_ANY_ACCESS
        • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS

        • File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
        • File Type: file
        • Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
        • Creation/Distribution: CREATE_ALWAYS
        • Desired Access: FILE_ANY_ACCESS
        • Share Access: FILE_SHARE_READ
        • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
        • Stored as: 4702b064ec87544b635e2df7c43910d8.exe

        • File: C:\DOCUME~1\Dave\LOCALS~1\Temp\tmpb80dc665.bat
        • File Type: file
        • Source File Hash: hash_error
        • Creation/Distribution: CREATE_ALWAYS
        • Desired Access: FILE_ANY_ACCESS
        • Share Access: FILE_SHARE_READ
        • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
        • Quantity: 2
        • Stored as: c28e784cea35faeb9387cc516e43852b.bat
        • Process # 2, (ID: 1112).
          • 打开的文件
            • File: \\.\PIPE\lsarpc
            • File Type: namedpipe
            • Creation/Distribution: OPEN_EXISTING
            • Desired Access: FILE_ANY_ACCESS
            • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
            • Flags: SECURITY_ANONYMOUS

            • File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
            • File Type: file
            • Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
            • Creation/Distribution: OPEN_EXISTING
            • Desired Access: FILE_ANY_ACCESS
            • Share Access: FILE_SHARE_READ
            • Flags: SECURITY_ANONYMOUS





        创建/打开 的文件...
        • File Type: file
        • Desired Access: FILE_ANY_ACCESS
        • Flags: SECURITY_ANONYMOUS




      • Process # 3, (ID: 1136).
        • 打开的文件
          • File: \\.\PIPE\lsarpc
          • File Type: namedpipe
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
          • Flags: SECURITY_ANONYMOUS

          • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
          • File Type: file
          • Source File Hash: hash_error
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_READ
          • Flags: SECURITY_ANONYMOUS

          • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
          • File Type: file
          • Source File Hash: hash_error
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_DELETE FILE_SHARE_READ FILE_SHARE_WRITE
          • Flags: SECURITY_ANONYMOUS
          • Stored as: d4f2ce821b597e2e6f709671144ec64c.oxe

          • File: \\.\PIPE\ROUTER
          • File Type: namedpipe
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
          • Flags: SECURITY_ANONYMOUS
          • Quantity: 2

          • File: c:\autoexec.bat
          • File Type: file
          • Source File Hash: hash_error
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_READ
          • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
          • Quantity: 5

          • File: \\.\Ip6
          • File Type: file
          • Source File Hash: hash_error
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
          • Flags: SECURITY_ANONYMOUS
          • Quantity: 5

          • File: \\.\Ip6
          • File Type: file
          • Source File Hash: hash_error
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
          • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS

          • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.tmp
          • File Type: file
          • Source File Hash: hash_error
          • Creation/Distribution: OPEN_EXISTING
          • Desired Access: FILE_ANY_ACCESS
          • Share Access: FILE_SHARE_DELETE FILE_SHARE_READ FILE_SHARE_WRITE
          • Flags: SECURITY_ANONYMOUS
          • 创建、打开的文件
            • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS
            • Share Access: FILE_SHARE_READ
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
            • Stored as: d4f2ce821b597e2e6f709671144ec64c.oxe

            • File: \Device\RasAcd
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE
            • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
            • Quantity: 5

            • File: \Device\Tcp6
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS
            • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
            • Quantity: 2

            • File: \Device\Ip6
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS
            • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS

            • File: \Device\Ip6
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE
            • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS

            • File: \Device\Tcp
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS
            • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS

            • File: \Device\NetBT_Tcpip_{AC33AA7D-86BB-40D5-BEF6-51C33880EAF1}
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE
            • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
            • Quantity: 2

            • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.tmp
            • File Type: file
            • Source File Hash: hash_error
            • Creation/Distribution: OPEN_ALWAYS
            • Desired Access: FILE_ANY_ACCESS
            • Share Access: FILE_SHARE_READ
            • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
            • 创建的文件
              • File: C:\DOCUME~1\Dave\LOCALS~1\Temp\tmp6999c57b\d45hr.exe
              • File Type: file
              • Source File Hash: C303D0FC000F1FA7D099001234D9BC00F5896FA6
              • Creation/Distribution: CREATE_ALWAYS
              • Desired Access: FILE_ANY_ACCESS
              • Share Access: FILE_SHARE_READ
              • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
                • Process # 5, (ID: 1916).
                  • 打开的文件
                    • File: \\.\PIPE\lsarpc
                    • File Type: namedpipe
                    • Creation/Distribution: OPEN_EXISTING
                    • Desired Access: FILE_ANY_ACCESS
                    • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
                    • Flags: SECURITY_ANONYMOUS

                    • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
                    • File Type: file
                    • Source File Hash: hash_error
                    • Creation/Distribution: OPEN_EXISTING
                    • Desired Access: FILE_ANY_ACCESS
                    • Share Access: FILE_SHARE_READ
                    • Flags: SECURITY_ANONYMOUS
                      • Process # 6, (ID: 2032).
                        • 打开的文件
                          • File: \\.\PIPE\lsarpc
                          • File Type: namedpipe
                          • Creation/Distribution: OPEN_EXISTING
                          • Desired Access: FILE_ANY_ACCESS
                          • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
                          • Flags: SECURITY_ANONYMOUS

                          • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
                          • File Type: file
                          • Source File Hash: hash_error
                          • Creation/Distribution: OPEN_EXISTING
                          • Desired Access: FILE_ANY_ACCESS
                          • Share Access: FILE_SHARE_READ
                          • Flags: SECURITY_ANONYMOUS
                            • Process # 7, (ID: 2044).
                              • 打开的文件
                                • File: \\.\PIPE\lsarpc
                                • File Type: namedpipe
                                • Creation/Distribution: OPEN_EXISTING
                                • Desired Access: FILE_ANY_ACCESS
                                • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
                                • Flags: SECURITY_ANONYMOUS

                                • File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
                                • File Type: file
                                • Source File Hash: hash_error
                                • Creation/Distribution: OPEN_EXISTING
                                • Desired Access: FILE_ANY_ACCESS
                                • Share Access: FILE_SHARE_READ
                                • Flags: SECURITY_ANONYMOUS
                                  • Process # 8, (ID: 364).
                                    • 打开的文件
                                      • File: C:\DOCUME~1\Dave\LOCALS~1\Temp\tmpb80dc665.bat
                                      • File Type: file
                                      • Source File Hash: hash_error
                                      • Creation/Distribution: OPEN_EXISTING
                                      • Desired Access: FILE_ANY_ACCESS
                                      • Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
                                      • Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
                                      • Quantity: 6































rok827
发表于 2010-8-2 11:45:50 | 显示全部楼层
norton scan kill
fatezero
发表于 2010-8-2 11:50:25 | 显示全部楼层
TO KL
rasis
发表于 2010-8-2 12:32:52 | 显示全部楼层
KS
病毒        2010-08-02  12:33:19        d:\download\usow.rar<a:rar>usow.exe        Win32.Malware.Heur_Generic.A.(kcloud)        处理成功(操作:删除)       
KOI9009
发表于 2010-8-2 12:32:54 | 显示全部楼层
网盾 云启发
wck317
发表于 2010-8-2 13:00:32 | 显示全部楼层
NIS2011sonar赞一个

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-14 17:26 , Processed in 0.127161 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表