额 一下这些是我在沙箱里运行这个病毒的一个日志 希望对LZ有所帮助
2011-05-14 19:54:38 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\sechost.dll C:\Windows\System32\sechost.dll
2011-05-14 19:54:38 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\imm32.dll C:\Windows\System32\imm32.dll
2011-05-14 19:54:38 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\imm32.dll C:\Windows\System32\imm32.dll
2011-05-14 19:54:38 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\security\ksde\kisdcom.dll C:\Program Files\Common Files\Kingsoft\kiscommon\security\ksde\kisdcom.dll
2011-05-14 19:54:39 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\uxtheme.dll C:\Windows\System32\uxtheme.dll
2011-05-14 19:54:39 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\kwsui.dll C:\Program Files\Common Files\Kingsoft\kiscommon\kwsui.dll
2011-05-14 19:54:39 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\version.dll C:\Windows\System32\version.dll
2011-05-14 19:54:39 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\winmm.dll C:\Windows\System32\winmm.dll
2011-05-14 19:54:40 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\kswebshield.dll C:\Program Files\Common Files\Kingsoft\kiscommon\kswebshield.dll
2011-05-14 19:54:40 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件D:\Program Files\KSafe\ksfmon.dll D:\Program Files\KSafe\ksfmon.dll
2011-05-14 19:54:40 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\dwmapi.dll C:\Windows\System32\dwmapi.dll
2011-05-14 19:54:40 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\cryptbase.dll C:\Windows\System32\cryptbase.dll
2011-05-14 19:54:41 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager
2011-05-14 19:54:41 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\secur32.dll C:\Windows\System32\secur32.dll
2011-05-14 19:54:41 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\sspicli.dll C:\Windows\System32\sspicli.dll
2011-05-14 19:54:41 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
2011-05-14 19:54:41 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\profapi.dll C:\Windows\System32\profapi.dll
2011-05-14 19:54:42 C:\Users\Jimmy\Desktop\baobei1.exe写文件C:\KSafeBox\9FFAD8C2\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\KSafeBox\9FFAD8C2\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2011-05-14 19:54:42 C:\Users\Jimmy\Desktop\baobei1.exe写文件C:\KSafeBox\9FFAD8C2\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\KSafeBox\9FFAD8C2\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写文件C:\KSafeBox\9FFAD8C2\Users\Jimmy\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\KSafeBox\9FFAD8C2\Users\Jimmy\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\dnsapi.dll C:\Windows\System32\dnsapi.dll
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\IPHLPAPI.DLL C:\Windows\System32\IPHLPAPI.DLL
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\winnsi.dll C:\Windows\System32\winnsi.dll
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\rasapi32.dll C:\Windows\System32\rasapi32.dll
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\rasman.dll C:\Windows\System32\rasman.dll
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\rtutils.dll C:\Windows\System32\rtutils.dll
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32 HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASAPI32
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe打开服务RASMAN RASMAN
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\KSBReg\9FFAD8C2\HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\baobei1_RASMANCS
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe打开服务Sens Sens
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe打开服务RASMAN RASMAN
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe写注册表HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\mswsock.dll C:\Windows\System32\mswsock.dll
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe加载库文件C:\Windows\System32\WSHTCPIP.DLL C:\Windows\System32\WSHTCPIP.DLL
2011-05-14 19:54:44 C:\Users\Jimmy\Desktop\baobei1.exe创建注册表键值HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_USERS\S-1-5-21-4220385740-4025949234-3541773174-1001\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections