回复:警惕NSDownLoader木马下载器(U盘病毒system.dll,替换appmgmts.dll等...
我经历过这个毒了
在我朋友家截获的
把瑞星改成1.exe能运行
上瑞星网站上不去显示
无法显示该页
下载的有:
WOWAR木马
QQPASS木马
AUTO木马
通过U盘传播
害的我差点。。。。
他先把DC8。DLL注入explorer.exe
以下是病毒的一段:lege pccguide.exe ZONEALARM.exe zonealarm.exe XDelbox.exe wink.exe windows优化大师.exe WFINDV32.exe webtrap.exe WEBSCANX.exe WEBSCAN.exe vsstat.exe VSSCAN40 VSHWIN32.exe vshwin32.exe VSECOMR.exe VPC32.exe vir.exe VETTRAY.exe VET95.exe vavrunr.exe UlibCfg.exe TSC.exe tmupdito.exe tmproxy.exe TMOAgent.exe Tmntsrv.exe TDS2-NT.exe TDS2-98.exe TCA.exe TBSCAN.exe symproxysvc.exe SWEEP95.exe sreng.exe spy.exe SPHINX.exe smtpsvc.exe SMC.exe sirc32.exe SERV95.exe secu.exe SCRSCAN.exe scon.exe SCANPM.exe SCAN32.exe scan.exe scam32.exe safeweb.exe safeboxTray.exe rn.exe Rfw.exe rescue32.exe regedit.exe RavTask.exe RavStub.exe RavMonD.exe RavMon.exe rav7win.exe RAV7.exe Rav.exe ras.exe pview95.exe prot.exe program.exe PpPpWallRun.exe PERSFW.exe PCFWALLICON.exe pccwin98.exe pccmain.exe pcciomon.exe PCCClient.exe pcc.exe PAVCL.exe PADMIN.exe OUTPOST.exe NVC95.exe NUPGRADE.exe norton.exe NORMIST.exe NMAIN.exe nisum.exe nisserv.exe NAVWNT.exe navwnt.exe NAVW32.exe NAVW.exe NAVSCHED.exe navrunr.exe NAVNT.exe NAVLU32.exe navapw32.exe navapsvc.exe N32ACAN.exe ms.exe MPFTRAY.exe MOOLIVE.exe moniker.exe mon.exe microsoft.exe mcafee.exe LUCOMSERVER.exe luall.exe LOOKOUT.exe lockdown2000.exe lamapp.exe kwatch.exe KVPreScan.exe KVMonXP.exe KRF.exe KPPMain.exe kpfwsvc.exe kpfw32.exe KPFW32.exe kissvc.exe kavstart.exe kav32.exe Kasmain.exe Kabackreport.exe JED.exe iomon98.exe iom.exe ICSSUPPNT.exe ICMOON.exe ICLOADNT.exe ICLOAD95.exe IceSword.exe ice.exe IBMAVSP.exe IBMASN.exe IAMSERV.exe IAMAPP.exe F-STOPW.exe f-stopw.exe FRW.exe FP-WIN.exe fp-win.exe f-prot95.exe F-PROT.exe fir.exe FINDVIRU.exe F-AGNT95.exe explorewclass.exe ESPWATCH.exe ESAFE.exe EFINET32.exe ECENGINE.exe DVP95.exe DV95_O.exe DV95.exe debu.exe dbg.exe DAVPFW.exe CLEANER3.exe CLEANER.exe CLAW95CT.exe CLAW95.exe cfinet32.exe cfinet.exe CFIND.exe CFIAUDIT.exe CFIADMIN.exe CCenter.exe BLACKICE.exe BLACKD.exe avxonsol.exe AVWIN95.exe avsynmgr.exe AVSCHED32.exe AVPUPD.exe AVKSERV.exe avk.exe AVGCTRL.exe AVE32.exe AVCONSOL.exe AUTODOWN.exe ATRACK.exe atrack.exe antivir.exe ANTI-TROJAN.exe anti.exe ACKWIN32.exe 360tray.exe 360safebox.exe 360safe.exe Debugger avp.exe SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options LoadLibraryA VirtualAllocEx \svchost.exe NsDlRK250 [url=file://\\.\NsDlRK250]\\.\NsDlRK250[/url] RES \Nskhelper2.sys \ w i a s e r v c . d l l \ w 3 2 t i m e . d l l \ s r s v c . d l l \ a p p m g m t s . d l l \ s c h e d s v c . d l l I m a g e h l p . d l l CheckSumMappedFile NsPsDk%.2d N s P s D k % . 2 d %s\NsPass%d.sys \ ? ? \ \ \ . \ % s SYSTEM TEST_EVENT \ B a s e N a m e d O b j e c t s \ 6 9 5 3 E A 6 0 - 8 D 5 F - 4 5 2 9 - 8 7 1 0 - 4 2 F 8 E D 3 E 8 C D A NsDnldrKillProcess NtQuerySystemInformation n t d l l ? q? qm s v c r t . d l l atol KeServiceDescriptorTable ntdll.dll ? q? q w s 2 _ 3 2 . d l l inet_addr SendARP I p h l p a p i . d l l GetAdaptersInfo WinNT Win2K WinXP Win2003 UnKnow %s?mac=%s&os=%s&ver=2.6A.1207&temp=%d&key=%d %.2X-%.2X-%.2X-%.2X-%.2X-%.2X \appwinproc.dll 360.qihoo.com tool.ikaka.com
www.virustotal.com bbs.sucop.com
www.dswlab.com www.nod32club.com www.lanniao.org www.cnnod32.cn www.kaspersky.com virustotal.com kaspersky.com.cn
www.kaspersky.com.cn union.kingsoft.com shadu.duba.net
www.nod32.com www.eset.com.cn www.duba.net www.jiangmin.com jiangmin.com dl.jiangmin.com rising.com.cn
www.rising.com.cn www.chinakv.com www.360safe.com www.360safe.cn www.360.cn open . S h e l l 3 2 . d l l ShellExecuteA [%s]
%s\open\%s %s,%s
%s\%s\%s %s,%s shell command=rundll32 %s%s.inf autorun B:\ A:\ system.dll explore 127.0.0.1 %s