貌似不是病毒,MD默认规则,只提示联网。沙盘下运行有如下行为:
Files modified: 4
--------------------
[Content] C:\Documents and Settings\Admin\Cookies\index.dat
[Content] C:\Documents and Settings\Admin\Local Settings\History\History.IE5\index.dat
[Content] C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat
[Content] C:\windows\Debug\UserMode\userenv.log
Values changed: 2
--------------------
HKEY_LOCAL_MACHINE\software\microsoft\ole
Old: (SZ) EnableDCOM = Y
New: (SZ) EnableDCOM = N
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Old: (BINARY) SavedLegacySettings = 3C,00,00,00,06,0B,00,00,01,00,00,00,00,00,00,00,05,00,00,00,6C,6F,63,61,6C,00,00,00,00,00,00,00,00,00,00,00,00,90,0E,05,45,AE,D3,CA,01,01,00,00,00,C0,A8,01,64,00,00,00,00,00,00,00,00
New: (BINARY) SavedLegacySettings = 3C,00,00,00,07,0B,00,00,01,00,00,00,00,00,00,00,05,00,00,00,6C,6F,63,61,6C,00,00,00,00,00,00,00,00,00,00,00,00,90,0E,05,45,AE,D3,CA,01,01,00,00,00,C0,A8,01,64,00,00,00,00,00,00,00,00
貌似很正常的说。
不是什么强毒。 |