望微点能做得更好~作者: david1126103 时间: 2006-10-8 15:12 昨天朋友中了一木马...装的是KIS搞不定...病毒开启无数IE进程直到资源耗尽,
我帮这位朋友远程装了微点...马上搞定,我朋友彻底与卡巴SAY 88
具体情况与病毒样本我发在剑盟样本区.....
以下是此病毒样本分析情况
VPCRM.exe
FileSize: 22,538 Bytes
SHA-160 : 8FCF1931E05F2DAC842E80F5FCE26FB4B272BA2F
MD5 : B85599108A6E39054A59E1A99DE2E2DE
CRC-32 : A05D767F
加壳方式:NsPacK V3.7 -> LiuXingPing *
文件信息如下:
Version Information
====================
Operating System : 32-bit Windows
File Type : Application
File Sub-Type : Unknown
File Version : 5,1,2600,0
Product Version : 5,1,2600,0
============================================================
Product Name : Microsoft(R) Windows(R) Operating System
File Description : Microsoft VPC Control
File Version : 5.1.2600.0
Product Version : 5.1.2600.0
Company Name : Microsoft Corporation
Internal Name : vpc
Legal Copyright : Microsoft Corporation. All rights reserved.
Original FileName : vpc.exe
行为:
SOFTWARE\wSkysoft
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
9=vpcrm.exe
KernelFaultCheck=vpcrm.exe
盗取如下文件数据
mir.dat
mir1.dat
mir2.dat
mir3.dat
ftp.ini
Server
server %dcaption
Server Count
User.ini
main
LastGroup
文件信息如下:
Version Information
====================
Operating System : 32-bit Windows
File Type : Application
File Sub-Type : Unknown
File Version : 5,1,2600,0
Product Version : 5,1,2600,0
============================================================
Product Name : Microsoft? Windows? Operating System
File Description : Microsoft Rendezvous Control
File Version : 5.1.2600.0
Product Version : 5.1.2600.0
Company Name : Microsoft Corporation
Internal Name : wscnty
Legal Copyright : ? Microsoft Corporation. All rights reserved.
Original FileName: wscnty.exe
[ Last edited by david1126103 on 2006-10-8 at 15:24 ]作者: 玛鲁 时间: 2006-10-10 15:51 楼上的兄弟,剑盟哪个帖子有?告一声,我试试!作者: philynet 时间: 2006-10-13 09:28
Quote:
Originally posted by david1126103 at 2006-10-8 15:12:
昨天朋友中了一木马...装的是KIS搞不定...病毒开启无数IE进程直到资源耗尽,
我帮这位朋友远程装了微点...马上搞定,我朋友彻底与卡巴SAY 88
具体情况与病毒样本我发在剑盟样本区.....
以下是此病毒样本分析情况 ...