°Ù¶È¿Õ¼ä | °Ù¶ÈÊ×Ò³ 
 
ÎÄÕÂÁбí
 
ÄúÕýÔڲ鿴 "²¡¶¾·À»¤" ·ÖÀàϵÄÎÄÕÂ

2007-09-23 14:49

ÕâÊÇÎÒΪ·¢¾òÍøÐ´µÄµÚһƪÎÄÕ£¬ÒòΪ°æÈ¨µÄ¹ØÏµ£¬Ö»ÄܰÑÁ¬½Ó·ÅÔÚÕâ¡£ÎÒÊDzËÄñ£¬Ò²·ÇרҵÈËÊ¿£¬ÎÄÕ»áÓдíÎóºÍÒÅ©µÄµØ·½£¬ÎÒÒ²Ò»Ö±ÔÚ²»¶Ïѧϰ£¬²»¶ÏÌá¸ß×Ô¼º£¬Ð»Ð»¡£

Ô­ÎÄÁ¬½Ó£º"ÎÒµÄÕÕÆ¬.Exe"£¨QQPass.ban£©×¨É±·½°¸

¡¾

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(8) | ä¯ÀÀ()
 
2007-09-14 00:55

ÎÒÏÈ˵Á½¾ä£º½ñÌìÇ×°®µÄ°²ÌìÅã¾ÆÍÅÍų¤¸øÁËÎÒÒ»¸ö²¡¶¾£¬¸½¼ÓÁËÒ»¾ä£ºÐ¡ÐÄŶ£¬¸ÐȾÐ͵ÄŶ~¶÷£¬ºÜºÃ£¬ºÜºÍг~Ö±½Ó´ÓÍų¤ÄÇתÀ´·ÖÎö¡£²»¹ýÂ¿ÉÄÜÊÇÒòΪÊǼòµ¥´ÖÂÔ·ÖÎö£¬Â©ÁËһЩ£º±ÈÈç´´½¨ÁË·þÎñ£¬±ÈÈçÕë¶Ôavp×öÁËijЩ¶¯×÷~Íų¤Ëµ²»ÊÇËûдµÄ¡£Ö§³Ö°²Ìì~Íų¤Ê²Ã´Ê±ºòÓлú»áºÈÒ»±­£¿¶ò£¬»¹ÓУ¬ÍµÍµµØÎÊÒ»¾ä£ºWSWHACKERÄãÊÇÂüÁªÇòÃÔô£¿

Ô­ÎĵØÖ·£º×îв¡¶¾¡°¶ñħ¡±¡¡Virus.Win32.Devil.a ·ÖÎö

¾¯Ìè×îв¡

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(0) | ä¯ÀÀ()
 
2007-08-27 03:32

²¡¶¾Ãû³Æ£ºN/A£¨Kaspersky£©
²¡¶¾±ðÃû£ºWorm.Diskgen.GEN£¨ÈðÐÇ£©
                   Win32.VcingT.a.793096£¨½ðɽ£©
²¡¶¾´óС£º86016 byte
¼Ó¿Ç·½Ê½£ºN/A
Ñù±¾MD5£º067e6aebe2df4c90299287e897a021a4
Ñù±¾SHA1£º231651cb97df9ebfd39ee3ee6d3d2bcd397827d5
±àдÓïÑÔ£ºMicrosoft Visual C++ 6.0

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐкó£¬Éú³ÉµÄÎļþ£º
%System32%\com\lsass.exe
%System32%\co

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(5) | ä¯ÀÀ()
 
2007-08-25 00:46

¼òµ¥ËµËµ°É£º£©

²¡¶¾Ãû³Æ£ºVirus.Win32.AutoRun.hx£¨Kaspersky£©
²¡¶¾±ðÃû£ºTrojan.Spy.Win32.Agent.dew £¨ÈðÐÇ£©
²¡¶¾´óС£º180224 byte
¼Ó¿Ç·½Ê½£ºN/A
Ñù±¾MD5£º0e736adecf8a3cdad09c87c61e998a4f
Ñù±¾SHA1£º852e0929dea01eccb08faeabf412d4404801161d
±àдÓïÑÔ£ºMicrosoft Visual C++ 6.0

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐк󣬸´ÖÆ×ÔÉíµ½£º
%System32%\Exp1orer.exe
ÊÍ·ÅÎļþ£º
%Windir%\logo.ini

²¡¶¾´´½¨½ø³Ì£ºExp1orer.exe

²¡¶¾Ìí¼Ó×¢²á±íÏî£¬Ëæ»úÆô¶¯£º

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(2) | ä¯ÀÀ()
 
2007-08-21 12:51

²¡¶¾Ãû³Æ£ºTrojan-Spy.Win32.KeyLogger.ns
²¡¶¾´óС£º40960 bytes
¼Ó¿Ç·½Ê½£ºN/A
Ñù±¾MD5£º5fa6d779855ec725c94538c528bc9f14
Ñù±¾SHA1£º9a719423b0731c43ecb9e17029a090f3765ae412

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐкó£¬Éú³ÉÎļþ£º
c:\NTDETECT.EXE£¨×ÔÉí£©
c:\48a0948cf852a96f590a\mrt.exe£¨×ÔÉí£©
c:\check.dll
c:\bootstat.sys

²¡¶¾´´½¨½ø³Ì£º
MSSetup.exe
mrt.exe
NTDETECT.EXE

²¡¶¾Ìí¼ÓµÄ×¢²á±íÏ
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Cur

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(2) | ä¯ÀÀ()
 
2007-08-16 16:15

²¡¶¾Ãû³Æ£ºTrojan-Downloader.Win32.Delf.bnc £¨Kaspersky£©
²¡¶¾´óС£º24387 bytes
¼Ó¿Ç·½Ê½£ºUpack
Ñù±¾MD5£ºea449fb9fa0912cc96aede1ec5842cad
Ñù±¾SHA1£º051c98415dd3d04eff3cb16f2415e4f7b25ad74f
±àдÓïÑÔ£ºBorland Delphi 6.0-7.0

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐк󣬴´½¨¸±±¾µ½£º
%System32%\wnipsvr.exe
²¢ÊÍ·Å£º
%System32%\perefic.ini
¼Ç¼²¡¶¾µÄ°æ±¾ÐÅÏ¢ £¬Õâ¸öÑù±¾ÊÇ11212

´´½¨·þÎñ£º
[HKLM\System\CurrentControlSet\Services\11111]
ÏÔʾÃû£º11111

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(5) | ä¯ÀÀ()
 
2007-08-15 22:48

²¡¶¾Ãû³Æ£ºTrojan-PSW.Win32.OnLineGames.tn(Kaspersky)
²¡¶¾´óС£º29221 bytes
¼Ó¿Ç·½Ê½£ºUpack
Ñù±¾MD5£º582d0de7bd83d91c3b4d862323768695  
Ñù±¾SHA1£ºf063def08ecaec14170f73022e4ae1b72e14f91f

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐк󣬸´ÖÆ×ÔÉíµ½£º
%System32%\gfdax.bbr

²¢ÊÍ·Ådll:
%System32%\wintyu.dll
%System32%\winkoyq.dll
%System32%\winlpyfa.dll
%System32%\fhfdy.dll
%System32%\wjhgl.dll
%System32%\wgfsm.dll
%System32%\wkjhj.dll

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(0) | ä¯ÀÀ()
 
2007-08-13 17:38

²¡¶¾Ãû³Æ£ºTrojan-PSW.Win32.Nilage.blg(Kaspersky)
²¡¶¾´óС£º15671 bytes
¼Ó¿Ç·½Ê½£ºNsPack
Ñù±¾MD5£º4e6b49a4bdb1caecc0fa2b69ec81f998
Ñù±¾SHA1£ºc4881275f29fd403009855afdad05a6163010a2c

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐк󣬸´ÖÆ×ÔÉíµ½£º
%ProgramFiles%\Internet Explorer\PLUGINS\NewTemp.bak

²¢ÊÍ·Ådll:
%ProgramFiles%\Internet Explorer\PLUGINS\NewTemp.dll
×¢Èëexplorer.exe½ø³Ì,¼àÊÓ·¢Ë͵½ÏûÏ¢¶ÓÁеÄÏûÏ¢£¬µÁÈ¡Óû§ÃÜÂ룬ÕʺŵÈÃô¸ÐÐÅÏ¢

´´½¨ShellExecuteHooks£¬

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(0) | ä¯ÀÀ()
 
2007-08-06 21:07

²¡¶¾Ãû³Æ£ºTojan-PWS.Win32.OnLineGames.uo£¨Kaspersky£©
²¡¶¾±ðÃû£ºTrojan.PSW.Win32.SunOnline.ab£¨ÈðÐÇ£©
²¡¶¾´óС£º10994 bytes  
¼Ó¿Ç·½Ê½£ºUPACK, BINARYRES
Ñù±¾MD5£º7f84234d88df5a4ce372b465b4fb825a
Ñù±¾SHA1£º828a7ef284319d145c82003b9935634212c5268b
±àдÓïÑÔ£ºBorland Delphi 6.0-7.0  

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐкó£¬ÊÍ·ÅÅú´¦ÀíC:\DeleteFileDos.bat£¬É¾³ýÕý³£verclsid.exeϵͳÎļþ
Åú´¦ÀíÄÚÈÝ£º
@echo off
:Loop
attrib "C:\WINDOWS\S

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(5) | ä¯ÀÀ()
 
2007-08-05 15:06

²¡¶¾Ãû³Æ£ºTrojan-Downloader.Win32.Small.ege £¨Kaspersky£©
²¡¶¾´óС£º14888 bytes
¼Ó¿Ç·½Ê½£ºNsPack
Ñù±¾MD5£ºc22272c7dbb194cacfc5242730cfbd78
Ñù±¾SHA1£ºf8f890586955ccc25244d684e98f0a74631d4176
±àдÓïÑÔ£ºBorland Delphi 6.0-7.0

ÐÐΪ·ÖÎö£º

²¡¶¾ÔËÐк󣬸´ÖÆ×ÔÉíµ½²¡¶¾´´½¨µÄWeb PublishÎļþ¼ÐÏ£º
C:\Program Files\Web Publish\IDrivers.pif   

Ìí¼Ó×¢²á±íÏ
[HKLM\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2bf41073-b2b1-

Àà±ð£º²¡¶¾·À»¤ | ÆÀÂÛ(2) | ä¯ÀÀ()
 
     
 
 
ÎÄÕ·ÖÀà
 
     
 
ÎÄÕ´浵
 
 
 
 
 
 
 
 
 
 
 
 
 
     
 
×îÐÂÎÄÕÂÆÀÂÛ
   

[񡀂]
 
 
 

½ñÌìºÜ¿ªÐÄ£¬¶®µÃÓò©¿ÍÁË£¡
 

45
 
     


©2009 Baidu