12
返回列表 发新帖
楼主: Nblock
收起左侧

[病毒样本] 据称过了微点

[复制链接]
蓝色牛仔裤
发表于 2007-5-30 12:45:27 | 显示全部楼层

回复 #10 solcroft 的帖子

我的实机操作也是这样。。。
zzh161
发表于 2007-5-30 12:47:32 | 显示全部楼层
pcc

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jlennon
头像被屏蔽
发表于 2007-5-30 12:53:54 | 显示全部楼层
原帖由 solcroft 于 2007-5-30 12:29 发表
运行后自行退出?
等jlennon来看看


我来也
jlennon
头像被屏蔽
发表于 2007-5-30 12:58:35 | 显示全部楼层
Processes:
PID ParentPID User Path
--------------------------------------------------
1448 228 MSEOSJD88JED:Administrator C:\Documents and Settings\Administrator\桌面\avp\avp.exe
Ports:
Port PID Type Path
--------------------------------------------------
Explorer Dlls:
DLL Path Company Name File Description
--------------------------------------------------
No changes Found   
IE Dlls:
DLL Path Company Name File Description
--------------------------------------------------
No changes Found   
Loaded Drivers:
Driver File Company Name Description
--------------------------------------------------
Monitored RegKeys
Registry Key Value
--------------------------------------------------
Kernel31 Api Log

--------------------------------------------------
***** Installing Hooks *****
71a270df     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\WinSock2\Parameters)
71a27cc4     RegOpenKeyExA (Protocol_Catalog9)
71a2737e     RegOpenKeyExA (0000010C)
71a2724d     RegOpenKeyExA (Catalog_Entries)
71a278ea     RegOpenKeyExA (000000000001)
71a278ea     RegOpenKeyExA (000000000002)
71a278ea     RegOpenKeyExA (000000000003)
71a278ea     RegOpenKeyExA (000000000004)
71a278ea     RegOpenKeyExA (000000000005)
71a278ea     RegOpenKeyExA (000000000006)
71a278ea     RegOpenKeyExA (000000000007)
71a278ea     RegOpenKeyExA (000000000008)
71a278ea     RegOpenKeyExA (000000000009)
71a278ea     RegOpenKeyExA (000000000010)
71a278ea     RegOpenKeyExA (000000000011)
71a278ea     RegOpenKeyExA (000000000012)
71a278ea     RegOpenKeyExA (000000000013)
71a22623     WaitForSingleObject(7a0,0)
71a283c6     RegOpenKeyExA (NameSpace_Catalog5)
71a2737e     RegOpenKeyExA (00000004)
71a27f5b     RegOpenKeyExA (Catalog_Entries)
71a280ef     RegOpenKeyExA (000000000001)
71a280ef     RegOpenKeyExA (000000000002)
71a280ef     RegOpenKeyExA (000000000003)
71a22623     WaitForSingleObject(798,0)
71a11afa     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\Winsock2\Parameters)
71a11996     GlobalAlloc()
7c80b689     ExitThread()
411f21     LoadLibraryA(KERNEL32.DLL)=7c800000
411f21     LoadLibraryA(ADVAPI32.dll)=77da0000
411f21     LoadLibraryA(USER32.dll)=77d10000
157ff0     LoadLibraryA(KERNEL32.DLL)=7c800000
157ff0     LoadLibraryA(ADVAPI32.dll)=77da0000
157ff0     LoadLibraryA(USER32.dll)=77d10000
15194e     CreateFileA(C:\windows\explorer.exe)
1518e6     GetVersionExA()
77db5f5e     WaitForSingleObject(7e8,2bf20)
77e7fb8e     RegOpenKeyExA (HKLM\Software\Microsoft\Rpc)
4105a4     LoadLibraryA(kernel32.dll)=7c800000
4105a4     LoadLibraryA(user32.dll)=77d10000
4105a4     LoadLibraryA(advapi32.dll)=77da0000
4105a4     LoadLibraryA(oleaut32.dll)=770f0000
71a4108d     GetCurrentProcessId()=1448
4105a4     LoadLibraryA(wsock32.dll)=71a40000
4105a4     LoadLibraryA(ws2_32.dll)=71a20000
4044fc     GetCommandLineA()
77dbbd59     RegOpenKeyExA (HKLM\System\CurrentControlSet\Control\ServiceCurrent)
403693     ExitProcess()
***** Injected Process Terminated *****
DirwatchData

--------------------------------------------------
WatchDir Initilized OK
Watching C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
Watching C:\windows
Watching C:\Program Files
Created: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JET8FBF.tmp
Created: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JET8.tmp
Deteled: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JET8.tmp
Modifed: C:\windows\Debug\UserMode\userenv.log
Deteled: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JET8FBF.tmp
Modifed: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFC199.tmp
Deteled: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFC199.tmp
Created: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFD08C.tmp
Modifed: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFD08C.tmp
Deteled: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFD08C.tmp
Modifed: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF8207.tmp
Deteled: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF8207.tmp
jlennon
头像被屏蔽
发表于 2007-5-30 12:59:25 | 显示全部楼层

啥也没干

野马
发表于 2007-5-30 13:17:50 | 显示全部楼层
谁有旧版的微点试一下?
solcroft
发表于 2007-5-30 13:21:23 | 显示全部楼层

回复 #14 jlennon 的帖子

加载一大把dll,创建一批tmp便没举动了
野马
发表于 2007-5-30 15:05:53 | 显示全部楼层
用了个3月份的微点,运行了一下,确实如楼上所言!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-12 16:18 , Processed in 0.094156 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表