瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了流行木马137.ini,望赐教!谢谢!

12   2  /  2  页   跳转

中了流行木马137.ini,望赐教!谢谢!

请帮我分析一下,谢谢!
gototop
 

等猫叔分析,学习下
LotusHlp.exe这个有流行趋势了...看了几个了
gototop
 

有眉目没有呀?谢谢了~~~
gototop
 

该用户帖子内容已被屏蔽
gototop
 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<GenProtect><C:\WINDOWS\bmolqa.exe> []
<AVPSrv><C:\WINDOWS\AVPSrv.exE> [N/A]
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<WinSysM><C:\WINDOWS\235780M.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDCG32 ><LYLeador.exe> [N/A]

[A6560D5E / A6560D5E][Stopped/Auto Start]
<C:\WINDOWS\system32\7C9EC208.EXE -k><Microsoft Corporation>

C:\WINDOWS\system32\198EB394.DLL

[C:\WINDOWS\235780MM.DLL] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\198EB394.DLL] [Microsoft Corporation, ]

Autorun.inf
[C:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[D:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[E:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT