大小: 24576 字节
4r5O! 4y 文件版本: 5.2600.2180
VEXsL$lmO 修改时间: 2006年9月24日, 22:18:38
n+29tQ MD5: CBDCF0AB0561540891A3E466147A4CE4
*V ){<;h SHA1: C3AC9EDF18A70304DEDE80AEABC0CA86AE9FED64
{+GLt!.60 CRC32: CD11CF59
FKWj$lT RDJY@ 测试系统WINDOWS2000
!+Lmfy"0q 病毒发作过程:
'\O5uOD3 写入文件项
]DB%lCZ C:\Documents and Settings\XXX\Local Settings\Temp\~DF1244.tmp
;1e C:\Documents and Settings\XXX\Local Settings\Temp\~DF6AE.tmp
#za?Jrh C:\WINNT\system32\EXPLORER.EXE
?jL-?<~; C:\WINNT\system32\wsctf.exe
kqNU D{ ^7$]W, 病毒开启进程:
/pS*D]E C:\WINNT\system32\EXPLORER.EXE
BnrOE<(I0 C:\WINNT\system32\wsctf.exe
15zPL}0F 0ctvEmjf 注册表动作
q%B*2f.Q~g HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Run
>f9eROXxCm HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\Winlogon
c?H<Wew \IM?=g\ 简单清除方法:
@n^,5w( 首先用组合键CTRL+ALT+DEL调出WINDOWS任务栏管理器
z<KlyEF3~ 结束病毒进程EXPLORER.EXE,wsctf.exe
&8s0k) 然后删除病毒创建的文件EXPLORER.EXE,wsctf.exe
*C] kL_ 清空C:\Documents and Settings\XXX\Local Settings\Temp目录临时文件。
0,B[H*EuKh 最后清除病毒注册信息。
.zf^Copv 完成。
@g^_y,ZJ ~K-=oK?R File: wsctf.exe
:'e`DK)|" Status: INFECTED/MALWARE
daA
tD3z MD5: cbdcf0ab0561540891a3e466147a4ce4
jQ*<87- Packers detected: -
="J.M Bit9 reports: Not analyzed yet (more info)
&*UCE{cH <`J]?B-(q Scanner results
;&YM029m Scan taken on 10 Oct 2007 12:42:47 (GMT)
'2BI [) A-Squared Found nothing
.V9z=w4 AntiVir Found TR/VB.HM
8aj8f*M ArcaVir Found nothing
(N.WaV Avast Found Win32:Looked-B
oM<hc8)v AVG Antivirus Found Worm/VB.AEM
N8TQa7m BitDefender Found Win32.Worm.WTC
9*_Mv lU ClamAV Found nothing
RYH7L_qB CPsecure Found nothing
OZ vB Dr.Web Found Win32.HLLW.Wtc
nQ@M>=9z+Q F-Prot Antivirus Found W32/Legendmir.CTS
P~3JtY<* F-Secure Anti-Virus Found Virus.Win32.VB.bu
m<iAf~rK Fortinet Found W32/LegendMir.CTS!tr.pws
*%A
rm(%` Kaspersky Anti-Virus Found Virus.Win32.VB.bu
( sKJzW NOD32 Found Win32/VB.NIH
%>=2vk2qA Norman Virus Control Found W32/VBTroj.DVI
QE1!9y4 Panda Antivirus Found Trj/VB.SG
3eEm7-5=|s Rising Antivirus Found Trojan.PSW.SBoy.b
Pex5aZ7QU Sophos Antivirus Found Troj/VB-DBU
bqWj*,.A[ VirusBuster Found nothing
\n9YKBd VBA32 Found Virus.Win32.VB.bu
?KGp TCB 5,,Js[ACce 病毒样本位置:
9Z\LK'< http://avfbbs.80port.net/read.php?tid=18399