1.一不小心中了Trojan.PSW.Win32.OnlineGames。还没弄清什么变种,ring已经被干掉,下面是中毒时的日志。
1。1 木马下载临时文件
C:\Documents and Settings\Administrator\Local Settings\Temp\M2.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\smss.exe
1。2 explorer被加载C:\Program Files\Common Files\fjOs0r.dll
1。3 IE被加载C:\Program Files\Internet Explorer\Onloor.dll
上面这几个东西被木马克星给做了,没法做样本了
1.4 Explorer加载一推游戏后门:
C:\WINDOWS\system32\mhdoor0.dll>
C:\WINDOWS\system32\wodoor0.dll>
C:\WINDOWS\system32\qhdoor0.dll>
C:\WINDOWS\system32\tldoor0.dll>
C:\WINDOWS\system32\55550.dll>
C:\WINDOWS\system32\dh3oor0.dll>
C:\WINDOWS\system32\mydoor0.dll>
C:\WINDOWS\system32\wgdoor0.dll>
C:\WINDOWS\system32\wddoor0.dll>
C:\WINDOWS\system32\qjdoor0.dll>
C:\WINDOWS\system32\cqdoor0.dll>
C:\WINDOWS\system32\wldoor0.dll>
C:\WINDOWS\system32\dadoor0.dll>
C:\WINDOWS\system32\rxdoor0.dll>
C:\WINDOWS\system32\csdoor0.dll>
C:\WINDOWS\system32\zxdoor0.dll>
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)附件:
48055620071012103653.txt