楼主: nazisoft
收起左侧

[病毒样本] 新型机器狗,过驱动防火墙

  [复制链接]
lf968
发表于 2011-5-3 21:58:09 | 显示全部楼层
Program Guard: dwawdw.exe -> cmd.exe        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\dwawdw.exe(4872) wants to start C:\Windows\SysWOW64\cmd.exe(4148)
Program Guard: dwawdw.exe -> a.bat        2011/5/3 21:53        Allowed        C:\Users\xxxxxx\AppData\Local\Temp\dwawdw.exe wants to create executable file C:\Users\xxxxxx\AppData\Local\Temp\a.bat
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming TCP access blocked to: 0.0.0.0:6197
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming TCP access blocked to: 0.0.0.0:7828
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming TCP access blocked to: 0.0.0.0:7858
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming TCP access blocked to: 0.0.0.0:6294
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming TCP access blocked to: 0.0.0.0:6836
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming TCP access blocked to: 0.0.0.0:8090
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Outgoing UDP access blocked to: 0.0.0.0:1900
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming UDP access blocked to: 0.0.0.0:5199
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming UDP access blocked to: 0.0.0.0:5198
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming UDP access blocked to: 0.0.0.0:5136
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Incoming UDP access blocked to: 0.0.0.0:5135
Firewall: Automatic decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\dwawdw.exe, Outgoing TCP access blocked to: 222.211.91.39:87
Firewall: User decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\dwawdw.exe, Outgoing UDP access blocked to: (xfstat.qq.com) 127.0.0.1:51512
Firewall: User decision        2011/5/3 21:53        Blocked        C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe, Outgoing TCP access blocked to: (update.qvod.com) 119.184.126.124:80
Program Guard: QvodSetupPlus3.exe -> QvodSetupPlus3.exe        2011/5/3 21:53        Allowed        C:\Users\xxxxxx\Desktop\QvodSetupPlus3\QvodSetupPlus3.exe(3236) wants to start C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe
Program Guard: QvodSetupPlus3.exe -> QvodSetupPlus3.exe        2011/5/3 21:53        Allowed        C:\Users\xxxxxx\Desktop\QvodSetupPlus3\QvodSetupPlus3.exe wants to create executable file C:\Users\xxxxxx\AppData\Local\Temp\QvodSetupPlus3.exe
Program Guard: QvodSetupPlus3.exe        2011/5/3 21:52        Allowed        C:\Windows\explorer.exe -> C:\Users\xxxxxx\Desktop\QvodSetupPlus3\QvodSetupPlus3.exe
ioton
头像被屏蔽
发表于 2011-5-4 01:01:28 | 显示全部楼层
在网吧试了,没穿网吧的还原和驱动防火墙。。
sadfish5
发表于 2011-5-4 13:12:23 | 显示全部楼层
连QQ管家都提示在加载驱动- -!

感染后再运行微点2.0,清理得一干二净。像没发生过啥事
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-9 02:13 , Processed in 0.078197 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表