本帖最后由 ssama 于 2010.8.4 09:09 编辑
avast! Win32:Trojan-gen
Executing: e:\testvirus\qq\qq.exe
SetWindowsHookEx
CreateFileMapping
CreateFile(C:\windows\war\war.exe)
CreateFile(E:\TestVirus\QQ\kill.bat)
RegDeleteValue(HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProxyBypass)
RegDeleteValue(HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProxyBypass) ]
RegDeleteValue(HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\IntranetName)
RegSetValueEx(HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\UNCAsIntranet, REG_DWORD: 0)
RegSetValueEx(HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\UNCAsIntranet, REG_DWORD: 0)
RegSetValueEx(HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\AutoDetect, REG_DWORD: 1)
CreateProcess(C:\windows\war\war.exe,"C:\windows\war\war.exe" ,E:\TestVirus\QQ)
CreateProcess((null),"kill.bat",(null))
Executing: d:\sandbox\shamrock\test\drive\c\windows\war\war.exe
RegSetValueEx(HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1441131b-985d-11df-a501-806e6f6e6963}\\BaseClass, REG_SZ: Drive)
RegSetValueEx(HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1441131d-985d-11df-a501-806e6f6e6963}\\BaseClass, REG_SZ: Drive)
RegSetValueEx(HKLM\SOFTWARE\Microsoft\CTF\Compatibility\QQ.EXE\BaseClass, REG_SZ: Drive)
Executing: c:\windows\system32\cmd.exe
DeleteFile(E:\TestVirus\QQ\QQ.EXE)
SetWindowsHookEx()
CreateProcess(C:\Windows\System32\regsvr32.exe,regsvr32 /s c:\windows\war\key.dll,E:\TestVirus\QQ)
CreateFileMapping
CreateEvent(OleDfRootE8BB6F774314A273)
Executing: c:\windows\system32\regsvr32.exe
RegSetValueEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\zhanzhengfanzi, REG_SZ: c:\windows\war\QO.exe)
CreateProcess((null),net stop sharedaccess,(null))
Executing: c:\windows\system32\net.exe
RegCreateKeyEx(HKLM\System\CurrentControlSet\Services\Tcpip\Parameters,Class)
CreateProcess((null),C:\Windows\system32\net1 stop sharedaccess,(null))
Executing: c:\windows\system32\net1.exe
DeleteFile(E:\TestVirus\QQ\kill.bat)
OpenService(SHAREDACCESS)
...(War.exe没反应了)
|