电脑之家
您的位置:首页 >>电脑安全 >>电脑病毒大全 >> Trojan.PSW.WoWar.ib 病毒的分析和日志
飞信手机客户端软件,免费发手机短信

Trojan.PSW.WoWar.ib 病毒的分析和日志

PCPXP.COM     来源:新浪-ufo不幸外人     时间:2007-04-05

病毒名称:Trojan.PSW.WoWar.ib
病毒类型:
病毒标准大小:
病毒启动方式:服务启动

添加文件:

  C:\WINDOWS\Help\ZThook.dll(释放的Trojan.PSW.ZhengTu.bn病毒)
  C:\WINDOWS\Help\ZTpass.exe(60,029B)
  C:\WINDOWS\Help\ZTYX.CHI(60,029B)

文件PEID信息:
系统进程:ZTpass.exe www.pcpxp.com
进程用户:system
测试时进程ID:200

Trojan.PSW.WoWar.ib注册表添加:

添加主键
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\Control
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZTmassacre
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZTmassacre\Security
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZTmassacre\Enum
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZTMASSACRE
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZTMASSACRE\0000
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZTMASSACRE\0000\Control
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTmassacre
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTmassacre\Security
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTmassacre\Enum

其他添加
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\Control\*NewlyCreated*: 0x00000000
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\Control\ActiveService: "ZTmassacre"
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\Service: "ZTmassacre"
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\Legacy: 0x00000001
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\ConfigFlags: 0x00000000
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\Class: "LegacyDriver"
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\0000\DeviceDesc: "ZT Massacre"
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZTMASSACRE\NextInstance: 0x00000001
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZTmassacre\Enum\0: "Root\LEGACY_ZTMASSACRE\0000"
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZTmassacre\Enum\Count: 0x00000001
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZTmassacre\Enum\NextInstance: 0x00000001
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZTmassacre\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00

共3页: 上一页 1 [2] [3] 下一页
奥运直播,PPS网络电视播放器软件