本页主题: P2P-Worm.Win32.Delf.ao简单分析及解决 打印 | 加为IE收藏 | 复制链接 | 收藏主题 | 上一主题 | 下一主题

admin
尽我所能帮助他人
级别: 管理员


精华: 5
发帖: 2218
威望: 16644 点
星星铁: 3172 块
贡献值: 0 点
在线时间:381(小时)
注册时间:2005-12-04
最后登录:2008-11-19

 P2P-Worm.Win32.Delf.ao简单分析及解决

管理提醒:
本帖被 admin 执行加亮操作(2008-10-26)
●文件运行后在其所在目录复制自身,并命名为useit.exe,同时在目录%windir%\ssl下疯狂建立ZIP包裹文件复制自身,压缩方式采用为“存储”,这是最低的压缩格式,目的是迅速占用硬盘资源。 B}}2YJ{  
生成的文件名可能为: 'uEU!!  
Visual_C++_Crack.zip n~ M5>u  
Kazaa_Plus.zip m40TG[Y  
Porn_Napster.zip N0*^6ag G  
Mp3_Finder.zip `Yo:x&=  
Msn_Crack.zip c[*cYd+`Z  
Yahoo_hacker.zip  @/}tY  
Msn_Hacker.zip n\3(ok^  
Delphi_7_Crack.zip  m12N  
Delphi_8_Crack.zip r}ledJwl  
HalfLife_keygen.zip 911-+&h  
CounterStrike_Keygen.zip !_vp{Z  
WinXp_Crack.zip M)OUj([  
WinXp_keygen.zip A+f s&&,  
mirc_6.2_Patch.zip {O@-mD}%b  
Email_Cracker.zip cr5Qr-  
Maria_Carey.zip iNJso9{  
Jeniifer_Lopez.zip fsQKY&?m?  
Fifa_2005_Demo.zip CB2%1Y2q|  
Mailbomber.zip OYo.  
Email_harvester.zip /CVk|#^m  
Spam_Blocker.zip ;?d;O4TX  
Mail_Spammer.zip $P_+YUY  
Half_Life_2_Keygen.zip 4]u[N7-/  
Mirc_Scripter.zip eaJk{  
Mp3_Search.zip 3588=   
Sex_Harvester.zip Qt|2)'{  
ZoneAlaram_Crack.zip ciJ X@E  
Sygate_Crack.zip * p:+ppVe\  
Kaspersky_Crack.zip LLiz*K.|*  
Mcafee_8_Crack.zip "&d-M\-  
Mcafee_7_Crack.zip IkDU^^(<  
Norton_Antivirus_Crack.zip cQsJYgW  
NAV_2004_Crack.zip _&,oIY8h0  
Pcillin_Crack.zip 4v/lo%|z1  
RPC_Patch.zip o@lY8/4l  
Hack_mail.zip u.7} :<b>  
Registry_Fixer.zip Yt>vIL<  
Adobe_Photoshop_Keygen.zip * "wwW]0  
Adobe_All_versions_keygen.zip %Gd8~sy`  
Windows_All_versions_keygen.zip NLM73  
Lesbian_Stars.zip = x:  Y<  
britney_Spears_Screen.zip `g;kc`_C  
Celebrities_Screensaver.zip >c HdRKgL`  
Pamela_Anderson_Screen.zip :JqfMRZ;8  
Mirc_Flooder.zip C*[ /N  
Hack_Networks.zip ? f PWet  
Webcam_Napster.zip `V\JXSvx  
Yahoo_Flooder.zip 0Jaqrf5;  
Msn_Crasher.zip N2H"X=  
Yahoo_crasher.zip :C5]rTO  
Call_of_duty_crack.zip NVgo_9h  
Red_Alert_3_Cheats.zip <Eq<ik  
AIM_Cracker.zip E ;u5Y  
Credit_Cards_Generator.zip P iCCD%  
Photo_Impact_Crack.zip XvYf?vpW."  
Acdsee_Crack.zip {^eO=K  
host_faker.zip DM86 I' h  
host_spoofer.zip <:gX4Hm,  
ip_spoofer.zip ) =^SC  
ip_faker.zip sp!_8F"b  
ident_spoofer.zip "jD'7BM2M  
ident_faker.zip !onQQCTd7  
tripod_hacker.zip '(24D|  
tripod_cracker.zip :L>.Z4=o  
hotmailhacker.zip x Q0bl}7  
hotmailcracker.zip ND]|k  
hotmail_account_sniffer.zip b1 + $57X  
aimhacker.zip 0n$@r   
aimcracker.zip tB~08 %*  
icqhacker.zip RMKQ-Ku$J  
icqcracker.zip qo$  
msnhacker.zip {@ 3}hk{  
msncracker.zip M)KaVW-9J  
winxp_hacker_.zip )*szsq)(  
winxp_cracker.zip Ah .jK  
winxphack.zip B u|Qy  
win2k_serial.zip LZJM)x}psz  
yahoo_cracker.zip .&N| J  
divx_fix.zip W%/V0p=c  
divx_repair.zip 7}EKitR  
ftp_hacker.zip [`b46Aa  
ftp_cracker.zip B~\d \G}e  
porn_account_hacker.zip u $*4wY  
porn_account_cracker.zip 1v@G@mT   
catherine_zeta_jones_nude.zip *E3jP-Fh_  
catherine_zeta_jones_naked.zip ?J/>-X/A  
catherine_zeta_jones_anal.zip ~Q+t8PSV  
pamela_anderson_anal.zip 2vC]i~h[Vr  
pamela_anderson_nude.zip g(:a N/  
pamela_anderson_naked.zip b>Xasu=  
buttman.zip 5HuJ/{PN&  
sarah_michelle_gellar_nude.zip %S Ac/G  
sarah_michelle_gellar_naked.zip Jc4hB$)  
sandra_bullock_nude.zip Z;gGuVd  
sandra_bullock_naked.zip ?.`Rx99"  
anastasia_anal.zip i'B+ @x!r  
anastasia_naked.zip xqb76  
anastasia_nude.zip t1L!#h|CB  
shakira_anal_.zip mT3YOsuy  
shakira_assfucked.zip c $;re^jt  
shakira_naked.zip FWN%&k8B2  
shakira_nude.zip }_j?Tv=&  
shakira_paparazzi_collection.zip \E;iFs  
XP_keygen.zip m5G^2.2~>  
PS2_emulator_bleem.zip ^}Fg8fd  
xbox_emulator_beta.zip :Q:eG/5  
linux_root.zip ,0;H= |ZKM  
win2k_pass_decryptor.zip B&I=B%Af  
Win2k_reboot_exploit.zip T{|-df'  
IIS_shellbind_exploit.zip lG.ccEP$  
AdvZip_Recovery.zip / bi([r  
AIM_Pass_stealer.zip (-s13A-0b  
AMI_BIOS_Cracker.zip Z|qh?*Qj  
Counter_Strike_CD_Keygen.zip -Xb-UKE  
Delphi_5_Keygen.zip *Tp'$!q83  
Delphi_6_Keygen.zip P@nOm U`  
Half_life_Cd_keygen.zip PbvoX  
Hotmail_Hacker.zip =>}'`=dT  
ICQ_Hackingtools.zip w 1WU9.  
invisible_IP.zip (+gf ;Lh2#  
kazaa.zip n'iD:X!%  
edonkey_serverlist.zip ~i $;m7aqZ  
kmd151_en.zip CWb)`  
Linux_rootaccess.zip /'}.U`x  
msn_IP_finder.zip Yh+[>v(  
Office_key_Gen.zip }.Uk ##m7h  
Autocad_2002_Crack.zip S'TLPH  
HttpTunnel_Keygen.zip 2y 3W  
Winrar_Crack.zip bp]e.^s  
Winrar_Keygen.zip DH=:i)^  
Winzip_Keygen.zip CV\|VR7`9  
Winzip_Crack.zip &2b A:OhMk  
Mirc_Crack.zip ALTG v\;  
mydoom_Scanner.zip oEixlCL  
Netbios_Cracker.zip Le /;9qpi  
Irc_Flooder.zip auON`s7  
MSN_7.3.zip U"AR([f  
MSN_PLUS_3.zip V<z^m=w^  
filename.exe 3('f)k-k  
useit.exe   7Cu-[" L  
N(9@aB!3j  
●程序试图连接网络 Z:1vH!kC/  

@T(1P^ P  
K~)Va>u9}  
●更改注册表 ,=]`5  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ;za z-i  
"startup"="C:\\WINXP\\ssl\\filename.exe" >s}C_T9+l  
Pn0^d8GK  
清除方法: e^T%%I~<  
使用Ctrl+Alt+Del终止filename进程,清理注册表,删除SSL目录即可。 w4':dn <U  
#QV#|hcy  
相关链接: diQa-pc;  
http://avfbbs.80port.net/read.php?tid=1221&fpage=2&toread=1
顶端 Posted: 2006-02-06 19:42 | [楼 主]
帖子浏览记录 版块浏览记录
Anti-Virus Fans » 病毒分析解决报告区

Time now is:11-21 19:38, Gzip enabled
Powered by PHPWind v6.3.2 Certificate Code © 2003-08 PHPWind.com Corporation