楼主: xiayang1221
收起左侧

[病毒样本] 无壳过世界杀毒网下载者~~(已更新)

  [复制链接]
hx1997
发表于 2011-3-7 21:39:42 | 显示全部楼层
本帖最后由 hx1997 于 2011-3-7 21:44 编辑

扫描设置
启发式分析(Ditectiv): 打开
云扫描(Cloud): 云 1、云 2 启用

扫描目标: G:\Documents and Settings\Administrator.HX-C0987054243B\桌面\antiVm1.0.exe

扫描于 2011-3-7 21:37:31 开始。

共计0个威胁。
扫描于 4 秒内完成。
扫描于 2011-3-7 21:37:35 结束。

最早的版本扫出来了

扫描设置
启发式分析(Ditectiv): 打开
云扫描(Cloud): 云 1、云 2 启用

扫描目标: G:\Documents and Settings\Administrator.HX-C0987054243B\桌面\antiVm

扫描于 2011-3-7 21:41:26 开始。

G:\Documents and Settings\Administrator.HX-C0987054243B\桌面\antiVm\antiVm.exe - Cloud.Suspicious (Probably Downloader) (检出方: Cloud 1)

共计1个威胁。
扫描于 5 秒内完成。
扫描于 2011-3-7 21:42:12 结束。



viruskiller123
发表于 2011-3-8 06:29:28 | 显示全部楼层
QVMKilled
古神魔塔
发表于 2011-3-8 10:11:18 | 显示全部楼层
hzk456 发表于 2011-3-7 12:40
360不知道11!

提示未知文件时,打开就要小心了
qianyuqx
头像被屏蔽
发表于 2011-3-8 10:21:22 | 显示全部楼层
360 miss
fzq198776
发表于 2011-3-8 13:21:36 | 显示全部楼层
本帖最后由 fzq198776 于 2011-3-8 13:35 编辑
xiayang1221 发表于 2011-3-7 10:16
回复 16楼 byxxdrls 的帖子

是的


首先增加文件体积到20 M,并在虚拟机中运行,运行后 NIS2011 的 sonar报警并删除
注:关闭NIS2011的实时监控后,程序会提示是在虚拟机中运行,可开启NIS 的实时监控,运行后就直接被sonar删除了,啥提示也没有,NIS2011的行为防御好强大。。。KIS2011只提示说程序没有数字签名,问是否运行运行,相比之下NIS2011的行为防御能力更强悍更智能!
尤金卡巴斯基
发表于 2011-3-9 22:48:29 | 显示全部楼层
antiVm.exe - Trojan-Downloader.Win32.Agent.fysx
antiVm0.5.exe - Trojan-Downloader.Win32.Agent.fyrk
antiVm0.7.exe - Trojan-Downloader.Win32.Agent.fyrl
antiVm0.8.exe - Trojan-Downloader.Win32.Agent.fyrm
antiVm1.0.exe - Trojan-Downloader.Win32.Agent.fyts

XMonster
发表于 2011-3-12 12:45:54 | 显示全部楼层
2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[1].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[2].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[3].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[4].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[5].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[6].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[7].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[8].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[9].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[10].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\inst[11].exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264Q.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VG.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMB.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8Z.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUE.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHO.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411Z.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0K.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPK.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHU.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ET.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QI.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\instCAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAZG264QCA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CA0X96S4CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CASWOQO5CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMK.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CALS42VGCAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAN9R536CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3O.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAKFSKMBCA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KP.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CA34DI24CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CA00BF8ZCASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRL.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CASE2KG6CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WU.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAG6BVUECA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6S.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CA5PBVHOCAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICY.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAR7411ZCA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2B.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CA3IVC0KCAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9I.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAH3MLPKCA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9ICAJ7DOOY.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CA9YDSHUCAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9ICAJ7DOOYCALP0J7G.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAF212ETCAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9ICAJ7DOOYCALP0J7GCACKMB4W.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAI60ZI4CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9ICAJ7DOOYCALP0J7GCACKMB4WCA94NKD0.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CAHGM2QICADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9ICAJ7DOOYCALP0J7GCACKMB4WCA94NKD0CAFIW9AO.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CADAUMP1CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9ICAJ7DOOYCALP0J7GCACKMB4WCA94NKD0CAFIW9AOCAJDZWHG.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:32    创建文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Users\dxm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBP5VLEG\CA9DE179CAD51LF9CA1QPPMKCAVH3HA0CA95IG3OCA63H7KPCAIB2BV0CA8D6HRLCALY23WUCAJ21X6SCA6YNICYCAWI0V2BCA2BSE9ICAJ7DOOYCALP0J7GCACKMB4WCA94NKD0CAFIW9AOCAJDZWHGCADFPNGI.exe
规则: [文件组]IE Cache -> [文件]*\temporary internet files\*; *.exe

2011/3/12 12:43:39    修改文件    阻止
进程: d:\下载\antivm1.0\antivm1.0.exe
目标: C:\Windows\System32\drivers\etc\hosts
规则: [文件组]受保护文件 -> [文件]c:\windows\system32\drivers\etc\*
522586971
头像被屏蔽
发表于 2011-3-12 12:57:52 | 显示全部楼层
回复 76楼 尤金卡巴斯基 的帖子

这也上报?这几个文件明显没有恶意啊。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-13 17:00 , Processed in 0.088265 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表