Trojan-Dropper.Win32.Agent.aye (NTDETECT.exe )分析 病毒文件名 %3bYV3[8_ NTDETECT.exe GP5
~NV 测试系统 Qm.eZck WIN2000 e7U1lDW! 测试人员 $*mFa(P. happyboys_xp 2,oZ&2UX ipCj?Vh 发作过程 0nc{OU4o 病毒文件运行后有如下文件动作 "pId 在所有分区创建anuorun.inf与NTDETECT.EXE文件 R=HI7Wp' C:\autorun.inf ?@+2j$aj C:\NTDETECT.exe ][jO,Qvw> C:\WINNT\system32\ntsvr.dll ;FWd*~z* D:\NTDETECT.exe z?;~(KHE D:\autorun.inf Vd"W~# )^J\"U* 注册表动作 Up2'-n054 HKCR\CLSID\{79B8A2B5-CCAB-40CD-B939-A18B916FAD95}\InProcServer32 *vv&`qU HKCR\CLSID\{79B8A2B5-CCAB-40CD-B939-A18B916FAD95}\Progid =5 Uh& HKCR\CLSID\{79B8A2B5-CCAB-40CD-B939-A18B916FAD95}\Programmable 0NZa&o HKCR\CLSID\{79B8A2B5-CCAB-40CD-B939-A18B916FAD95}\TypeLib /kaOa_ HKCR\CLSID\{79B8A2B5-CCAB-40CD-B939-A18B916FAD95}\VersionIndependentProgID )Yc{ftLyXI HKCR\Drive\shell\open\command Dhb@xvH HKCR\mssconime.ntsvr #+]\BA' HKCR\mssconime.ntsvr.1 E~#43]zlV HKCR\mssconime.ntsvr.1\CLSID +MM9<cJ HKCR\mssconime.ntsvr\CLSID aA$( HKCR\mssconime.ntsvr\CurVer P}D@@y1 uPX?*=`u]' {~$<B)B File: NTDETECT.exe LS^V3-] Status: INFECTED/MALWARE ~!j41GS] MD5: ebb252dbbcb3ad20952f265405467914 #,Kge#]? Packers detected: - Qzw5^Xa Yvu'U%&\~- AntiVir Found TR/Agent.ZP.4.B )O(3h1J% ArcaVir Found nothing \=A8)ne Avast Found Win32:Agent-DJE S`5MVX6o AVG Antivirus Found Dropper.Agent.CBZ y=|!j4 t BitDefender Found Trojan.Dropper.Agent.N 3C3d#"kC ClamAV Found nothing ]:NSKe CPsecure Found Troj.Dropper.W32.Agent.aye `Lo=QgC Dr.Web Found Trojan.MulDrop.4417 ve{z" F-Prot Antivirus Found W32/Agent f;m"XUu2 F-Secure Anti-Virus Found Trojan-Dropper.Win32.Agent.aye }S<m:eh&C Fortinet Found nothing R_8,<c*R Ikarus Found Trojan-Dropper.Win32.Agent.aye 3<kEKk{ Kaspersky Anti-Virus Found Trojan-Dropper.Win32.Agent.aye b\Ph+fQG NOD32 Found nothing 0{%.Tn Norman Virus Control Found nothing %S I' z Panda Antivirus Found nothing =g0Bvp [ Sophos Antivirus Found nothing _ oV$`Q VirusBuster Found nothing VzxM)(,8D VBA32 Found Trojan-Dropper.Win32.Agent.aye |