瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了backdoor.delf.vyf,瑞星杀不死,现有样本,哪位大侠想研究找我

12   2  /  2  页   跳转

中了backdoor.delf.vyf,瑞星杀不死,现有样本,哪位大侠想研究找我

[C:\Program Files\Tencent\QQ\QQCustomFace.dll]  <N/A><N/A>
    [C:\WINNT\System32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [C:\Program Files\Tencent\QQ\GroupConnection.dll]  <Tencent><0, 3, 3, 5>
    [C:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 6, 60>
    [C:\Program Files\Tencent\QQ\QQZip.dll]  <tencent><0, 3, 2, 4>
    [C:\Program Files\Tencent\QQ\QQMagicFace.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [C:\WINNT\System32\AcSignIcon.dll]  <Autodesk><16.1.63.0>
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  <Autodesk><16.1.63.0>
    [C:\Program Files\Tencent\QQ\QQFileTransfer.dll]  <Tencent><0, 3, 3, 5>
[PID: 1172][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 248][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINNT\System32\AcSignIcon.dll]  <Autodesk><16.1.63.0>
    [C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll]  <Xiang Feng Technology><2, 2, 0, 1612>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINNT\System32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1812][C:\Program Files\Tencent\QQGame\QQGame.exe]  <深圳市腾讯计算机系统有限公司><0, 10, 108, 45>
    [C:\Program Files\Tencent\QQGame\VHelp.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQGame\ResEx.dll]  <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
    [C:\Program Files\Tencent\QQGame\HelpDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQGame\GameLogCore.dll]  <><0, 10, 106, 13>
    [C:\Program Files\Tencent\QQGame\Core.dll]  <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
    [C:\Program Files\Tencent\QQGame\NetCenter.dll]  <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
    [C:\Program Files\Tencent\QQGame\CmdCenter.dll]  <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
    [C:\Program Files\Tencent\QQGame\GameLogAidMgr.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQGame\COMToolKit.dll]  <><1, 0, 0, 3>
    [C:\Program Files\Tencent\QQGame\QQGameAvatar.dll]  <深圳市腾讯计算机系统有限公司                                    Tencent Computer System Ltd.><0, 10, 0, 0>
    [C:\Program Files\Tencent\QQGame\QQGameAvatarShow.dll]  <深圳市腾讯计算机系统有限公司                                    Tencent Computer System Ltd.><0, 10, 0, 0>
    [C:\Program Files\Tencent\QQGame\QQGameItemMgr.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQGame\ItemShowHelper.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQGame\WorkModule.dll]  <><0, 0, 0, 13>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Tencent\QQGame\Room.dll]  <><1, 0, 0, 28>
    [C:\Program Files\Tencent\QQGame\CUQG.ocx]  <深圳市腾讯计算机系统有限公司                                    Tencent Computer System Ltd.><0, 10, 0, 14>
    [C:\Program Files\Tencent\QQGame\GameProxy.dll]  <N/A><N/A>
[PID: 1848][D:\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

各位大侠,有结果了没
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT