电脑之家
您的位置:首页 >>电脑安全 >>电脑病毒大全 >> Trojan.PSW.Misc.di病毒日志分析
飞信手机客户端软件,免费发手机短信

Trojan.PSW.Misc.di病毒日志分析

PCPXP.COM     来源:新浪-ufo不幸外人     时间:2007-04-05

病毒名称:Trojan.PSW.Misc.di
病毒类型:
病毒标准大小:47,081B
病毒启动方式:注册表HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\项启动

Trojan.PSW.Misc.di病毒在电脑添加文件:
  C:\Windows\EXERT.exe
  C:\Windows\LSASS.exe
  C:\Windows\system32\regedit.com
  C:\Windows\system32\MSconfig.com
  C:\Windows\system32\dxdiag.com
  C:\Windows\Debug\DebugProgram.exe
  C:\Program Files\Common Files\INTEXPLORE.pif
  C:\Program Files\Internet Explorer\INTEXPLORE.com
  D:\Atuorun.inf
  D:\command.com
文件PEID信息:
系统进程:LSASS.exe
进程用户:当前用户
测试时进程ID:1780

Trojan.PSW.Misc.di病毒在注册表添加:
  添加主键
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\DefaultIcon
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\Shell
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\Shell\Open
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\Shell\Open\Command
  HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif
  HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif\shell
  HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif\shell\open
  HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif\shell\open\command
  添加EXE文件关联:
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\Shell\Open\Command\: 43 3A 5C 57 49 4E 44 4F 57 53 5C 45 58 45 52 54 2E 65 78 65 20 22 25 31 22 20 25 2A 00 00 00 00 2E 00
  添加系统注册表启动:
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ToP: "C:\WINDOWS\LSASS.exe"
  其他添加:
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\DefaultIcon\: "%1"
  HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif\LocalizedString: 49 4E 54 45 58 50 4C 4F 52 45 00 D1 DB
  HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif\shell\open\command\: "C:\Program Files\common~1\INTEXPLORE.pif"
注册表修改: www.pcpxp.com 供稿
  修改EXE文件关联指向:
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\: "exefile"
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\: "WindowFiles"
  修改桌面IE连接:
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iexplore.exe\shell\open\command\: ""C:\Program Files\Internet Explorer\iexplore.exe" %1"
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iexplore.exe\shell\open\command\: ""C:\Program Files\Internet Explorer\INTEXPLORE.com" %1"
  其他修改:
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\shell\open\command\: ""C:\Program Files\Internet Explorer\iexplore.exe" %1"
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\shell\open\command\: ""C:\Program Files\Internet Explorer\INTEXPLORE.com" %1"

共2页: 上一页 1 [2] 下一页
奥运直播,PPS网络电视播放器软件