瑞星卡卡安全论坛技术交流区系统软件 中文上网CNNIC厉害啊,装了会自动打系统补丁,此恶意软件也许是变种了

1   1  /  1  页   跳转

中文上网CNNIC厉害啊,装了会自动打系统补丁,此恶意软件也许是变种了

中文上网CNNIC厉害啊,装了会自动打系统补丁,此恶意软件也许是变种了

不知不觉就会在后台运行打补丁,幸好被我发现,立即取消掉,要不然就惨了,补丁的名字是KB918899,,我上网查了这个微软是有这个补丁。。但是我在服务里和系统属性都已经把自动更新都禁用了,不可以能系统会自动打补丁的,然后我查看WINDOWS下的LOG,里面的内容就是CNNIC的垃圾。。。呵呵,还在WINDOWS下生成~tmp9714.exe垃圾文件

附件附件:

下载次数:191
文件类型:image/pjpeg
文件大小:
上传时间:2006-10-23 0:10:42
描述:
预览信息:EXIF信息



最后编辑2006-10-23 00:15:26.077000000
分享到:
gototop
 

以下是LOG的部分内容,因为内容众多不能全部都贴上来,所以只能发一点
[KB918899.log]
2.974: ================================================================================
2.974: 2006/10/22 23:48:53.026 (local)
2.974: d:\50471d6a3cf57c4ed5\update\update.exe (version 6.2.29.0)
3.014: Hotfix started with following command line:
3.455: FileVersion of C:\Program Files\internet explorer\iexplore.exe is Less Than 7.0.0.0
3.455: Condition succeeded for section Test.IE7InstallBlock.Section in Line 1 of PreRequisite
7.441: In Function TestVolatileFlag, line 11873, RegOpenKeyEx failed with error 0x2
7.441: In Function TestVolatileFlag, line 11905, RegOpenKeyEx failed with error 0x2
7.551: ---- Old Information In The Registry ------
7.571: Source:C:\Program Files\CNNIC\Cdn\cdnup.exe (2.4.0.6)
7.571: Destination:
7.581: Source:C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (2.0.0.2)
7.581: Destination:
7.641: Source:C:\PROGRA~1\CNNIC\Cdn\idnconvs.dll (2.0.0.0)
7.641: Destination:
7.661: Source:C:\PROGRA~1\CNNIC\Cdn\cdnvers.dat
7.661: Destination:
7.711: Source:C:\PROGRA~1\CNNIC\Cdn\cdnunins.exe (2.4.0.1)
7.711: Destination:
7.731: Source:C:\PROGRA~1\CNNIC\Cdn\cdnaux.dll (2.1.0.0)
7.731: Destination:
7.731: Source:C:\PROGRA~1\CNNIC\Cdn\cdnup.exe (2.4.0.6)
7.731: Destination:
7.731: Source:C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (2.0.0.2)
7.731: Destination:
7.761: Source:C:\PROGRA~1\CNNIC\Cdn\cdnprh.dll (2.4.0.3)
7.761: Destination:
7.781: Source:C:\PROGRA~1\CNNIC\Cdn\idnconv.dll (2.0.0.0)
7.781: Destination:
7.871: Source:C:\PROGRA~1\CNNIC\Cdn\cdnrenew.exe (2.3.0.7)
7.871: Destination:
7.891: Source:C:\PROGRA~1\CNNIC\Cdn\cdndet.dll (2.4.0.3)
7.891: Destination:
7.901: Source:C:\PROGRA~1\CNNIC\Cdn\cdndisp.dat
7.901: Destination:
7.901: Source:C:\PROGRA~1\CNNIC\Cdn\imaoe.dll (2.2.0.1)
7.901: Destination:
7.921: Source:C:\PROGRA~1\CNNIC\Cdn\cdnprev.dat
7.921: Destination:
7.961: Source:C:\PROGRA~1\CNNIC\Cdn\cdnuc.exe (1.1.0.1)
7.961: Destination:
7.992: Source:C:\PROGRA~1\CNNIC\Cdn\cdnacs.dat
7.992: Destination:
7.992: Source:C:\Program Files\CNNIC\Cdn\cdnup.exe (2.4.0.6)
7.992: Destination:
8.032: Source:C:\windows\system32\drivers\cdnprot.sys (2.4.0.10)
8.032: Destination:
8.062: Source:C:\windows\system32\CDnprot.dat
8.062: Destination:
8.062: Source:C:\windows\system32\drivers\cdnprot.sys (2.4.0.10)
8.062: Destination:
8.062: Source:C:\Program Files\CNNIC\Cdn\idnconvs.dll (2.0.0.0)
8.062: Destination:c:\1
8.062: Deleting File: \??\C:\Program Files\CNNIC\Cdn\idnconvs.dll ( incoming is a newer file )
8.062: Source:C:\Program Files\CNNIC\Cdn\idnconvs.dll.tmp
8.062: Destination:c:\1
8.062: Deleting File: \??\C:\Program Files\CNNIC\Cdn\idnconvs.dll.tmp ( incoming is a newer file )
8.062: Source:C:\Program Files\CNNIC\Cdn\cdnunins.exe (2.4.0.1)
8.062: Destination:c:\1
8.062: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnunins.exe ( incoming is a newer file )
8.062: Source:C:\Program Files\CNNIC\Cdn\cdnunins.exe.tmp
8.062: Destination:c:\1
8.062: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnunins.exe.tmp ( incoming is a newer file )
8.062: Source:C:\Program Files\CNNIC\Cdn\cdnaux.dll (2.1.0.0)
8.062: Destination:c:\1
8.062: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnaux.dll ( incoming is a newer file )
8.062: Source:C:\Program Files\CNNIC\Cdn\cdnaux.dll.tmp
8.062: Destination:c:\1
8.062: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnaux.dll.tmp ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnup.exe (2.4.0.6)
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnup.exe ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnup.exe.tmp
gototop
 

8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnup.exe.tmp ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnforie.dll (2.0.0.2)
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnforie.dll ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnforie.dll.tmp
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnforie.dll.tmp ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnprh.dll (2.4.0.3)
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnprh.dll ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnprh.dll.tmp
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnprh.dll.tmp ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\idnconv.dll (2.0.0.0)
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\idnconv.dll ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\idnconv.dll.tmp
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\idnconv.dll.tmp ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnrenew.exe (2.3.0.7)
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnrenew.exe ( incoming is a newer file )
8.072: Source:C:\Program Files\CNNIC\Cdn\cdnrenew.exe.tmp
8.072: Destination:c:\1
8.072: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnrenew.exe.tmp ( incoming is a newer file )
8.082: Source:C:\Program Files\CNNIC\Cdn\cdndet.dll (2.4.0.3)
8.082: Destination:c:\1
8.082: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdndet.dll ( incoming is a newer file )
8.082: Source:C:\Program Files\CNNIC\Cdn\cdndet.dll.tmp
8.082: Destination:c:\1
8.082: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdndet.dll.tmp ( incoming is a newer file )
8.082: Source:C:\Program Files\CNNIC\Cdn\imaoe.dll (2.2.0.1)
8.082: Destination:c:\1
8.082: Deleting File: \??\C:\Program Files\CNNIC\Cdn\imaoe.dll ( incoming is a newer file )
8.082: Source:C:\Program Files\CNNIC\Cdn\imaoe.dll.tmp
8.082: Destination:c:\1
8.082: Deleting File: \??\C:\Program Files\CNNIC\Cdn\imaoe.dll.tmp ( incoming is a newer file )
8.082: Source:C:\Program Files\CNNIC\Cdn\cdnuc.exe (1.1.0.1)
8.082: Destination:c:\1
8.082: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnuc.exe ( incoming is a newer file )
8.082: Source:C:\Program Files\CNNIC\Cdn\cdnuc.exe.tmp
8.082: Destination:c:\1
8.082: Deleting File: \??\C:\Program Files\CNNIC\Cdn\cdnuc.exe.tmp ( incoming is a newer file )
8.082: Source:C:\windows\system32\capp.exe
8.082: Destination:C:\1
8.082: Deleting File: \??\C:\windows\system32\capp.exe ( incoming is a newer file )
8.082: Source:C:\windows\system32\capp.exe.tmp
8.082: Destination:C:\1
8.082: Deleting File: \??\C:\windows\system32\capp.exe.tmp ( incoming is a newer file )
8.092: Source:C:\windows\system32\capp.exe
8.092: Destination:C:\1
8.092: Deleting File: \??\C:\windows\system32\capp.exe ( incoming is a newer file )
8.092: Source:C:\windows\system32\capp.exe.tmp
8.092: Destination:C:\1
8.092: Deleting File: \??\C:\windows\system32\capp.exe.tmp ( incoming is a newer file )
8.092: Source:C:\windows\system32\cdn.dll
8.092: Destination:C:\1
8.092: Deleting File: \??\C:\windows\system32\cdn.dll ( incoming is a newer file )
8.092: Source:C:\windows\system32\cdn.dll.tmp
8.092: Destination:C:\1
8.092: Deleting File: \??\C:\windows\system32\cdn.dll.tmp ( incoming is a newer file )
8.102: Source:C:\windows\system32\cdn.dll
8.102: Destination:C:\1
8.102: Deleting File: \??\C:\windows\system32\cdn.dll ( incoming is a newer file )
8.102: Source:C:\windows\system32\cdn.dll.tmp
8.102: Destination:C:\1
8.102: Deleting File: \??\C:\windows\system32\cdn.dll.tmp ( incoming is a newer file )
8.102: Source:C:\windows\system32\CdnAux.dll
8.102: Destination:C:\1
8.102: Deleting File: \??\C:\windows\system32\CdnAux.dll ( incoming is a newer file )
8.102: Source:C:\windows\system32\CdnAux.dll.tmp
8.102: Destination:C:\1
8.102: Deleting File: \??\C:\windows\system32\CdnAux.dll.tmp ( incoming is a newer file )
8.102: Source:C:\windows\system32\CdnAux.dll
8.102: Destination:C:\1
8.102: Deleting File: \??\C:\windows\system32\CdnAux.dll ( incoming is a newer file )
8.102: Source:C:\windows\system32\CdnAux.dll.tmp
8.102: Destination:C:\1
8.102: Deleting File: \??\C:\windows\system32\CdnAux.dll.tmp ( incoming is a newer file )
8.112: Source:C:\windows\system32\Cdnficfg.dat
8.112: Destination:C:\1
8.112: Deleting File: \??\C:\windows\system32\Cdnficfg.dat ( incoming is a newer file )
8.112: Source:C:\windows\system32\Cdnficfg.dat.tmp
8.112: Destination:C:\1
8.112: Deleting File: \??\C:\windows\system32\Cdnficfg.dat.tmp ( incoming is a newer file )
8.112: Source:C:\windows\system32\Cdnficfg.dat
8.112: Destination:C:\1
8.112: Deleting File: \??\C:\windows\system32\Cdnficfg.dat ( incoming is a newer file )
8.112: Source:C:\windows\system32\Cdnficfg.dat.tmp
8.112: Destination:C:\1
8.112: Deleting File: \??\C:\windows\system32\Cdnficfg.dat.tmp ( incoming is a newer file )
8.112: Source:C:\windows\system32\CdnHint.dat
gototop
 

??\C:\windows\system32\CdnHint.dat ( incoming is a newer file )
8.112: Source:C:\windows\system32\CdnHint.dat.tmp
8.112: Destination:C:\1
8.112: Deleting File: \??\C:\windows\system32\CdnHint.dat.tmp ( incoming is a newer file )
8.122: Source:C:\windows\system32\CdnHint.dat
8.122: Destination:C:\1
8.122: Deleting File: \??\C:\windows\system32\CdnHint.dat ( incoming is a newer file )
8.122: Source:C:\windows\system32\CdnHint.dat.tmp
8.122: Destination:C:\1
8.122: Deleting File: \??\C:\windows\system32\CdnHint.dat.tmp ( incoming is a newer file )
8.122: Source:C:\windows\system32\cdnhook.dat
8.122: Destination:C:\1
8.122: Deleting File: \??\C:\windows\system32\cdnhook.dat ( incoming is a newer file )
8.122: Source:C:\windows\system32\cdnhook.dat.tmp
8.122: Destination:C:\1
8.122: Deleting File: \??\C:\windows\system32\cdnhook.dat.tmp ( incoming is a newer file )
8.122: Source:C:\windows\system32\cdnhook.dat
8.122: Destination:C:\1
8.122: Deleting File: \??\C:\windows\system32\cdnhook.dat ( incoming is a newer file )
8.122: Source:C:\windows\system32\cdnhook.dat.tmp
8.122: Destination:C:\1
8.122: Deleting File: \??\C:\windows\system32\cdnhook.dat.tmp ( incoming is a newer file )
8.132: Source:C:\windows\system32\CdnIEHlp.dll
8.132: Destination:C:\1
8.132: Deleting File: \??\C:\windows\system32\CdnIEHlp.dll ( incoming is a newer file )
8.132: Source:C:\windows\system32\CdnIEHlp.dll.tmp
8.132: Destination:C:\1
8.132: Deleting File: \??\C:\windows\system32\CdnIEHlp.dll.tmp ( incoming is a newer file )
8.132: Source:C:\windows\system32\CdnIEHlp.dll
8.132: Destination:C:\1
8.132: Deleting File: \??\C:\windows\system32\CdnIEHlp.dll ( incoming is a newer file )
8.132: Source:C:\windows\system32\CdnIEHlp.dll.tmp
8.132: Destination:C:\1
8.132: Deleting File: \??\C:\windows\system32\CdnIEHlp.dll.tmp ( incoming is a newer file )
8.132: Source:C:\windows\system32\CdnProt.dll
8.132: Destination:C:\1
8.132: Deleting File: \??\C:\windows\system32\CdnProt.dll ( incoming is a newer file )
8.132: Source:C:\windows\system32\CdnProt.dll.tmp
8.132: Destination:C:\1
8.142: Deleting File: \??\C:\windows\system32\CdnProt.dll.tmp ( incoming is a newer file )
8.142: Source:C:\windows\system32\CdnProt.dll
8.142: Destination:C:\1
8.142: Deleting File: \??\C:\windows\system32\CdnProt.dll ( incoming is a newer file )
8.142: Source:C:\windows\system32\CdnProt.dll.tmp
8.142: Destination:C:\1
8.142: Deleting File: \??\C:\windows\system32\CdnProt.dll.tmp ( incoming is a newer file )
8.142: Source:C:\windows\system32\CdnTdns.dll
8.142: Destination:C:\1
8.142: Deleting File: \??\C:\windows\system32\CdnTdns.dll ( incoming is a newer file )
8.142: Source:C:\windows\system32\CdnTdns.dll.tmp
8.142: Destination:C:\1
8.142: Deleting File: \??\C:\windows\system32\CdnTdns.dll.tmp ( incoming is a newer file )
8.152: Source:C:\windows\system32\CdnTdns.dll
8.152: Destination:C:\1
8.152: Deleting File: \??\C:\windows\system32\CdnTdns.dll ( incoming is a newer file )
8.152: Source:C:\windows\system32\CdnTdns.dll.tmp
8.152: Destination:C:\1
8.152: Deleting File: \??\C:\windows\system32\CdnTdns.dll.tmp ( incoming is a newer file )
8.152: Source:C:\windows\system32\CdnUnkw.dll
8.152: Destination:C:\1
8.152: Deleting File: \??\C:\windows\system32\CdnUnkw.dll ( incoming is a newer file )
8.152: Source:C:\windows\system32\CdnUnkw.dll.tmp
8.152: Destination:C:\1
8.152: Deleting File: \??\C:\windows\system32\CdnUnkw.dll.tmp ( incoming is a newer file )
8.152: Source:C:\windows\system32\CdnUnkw.dll
8.152: Destination:C:\1
8.162: Deleting File: \??\C:\windows\system32\CdnUnkw.dll ( incoming is a newer file )
8.162: Source:C:\windows\system32\CdnUnkw.dll.tmp
8.162: Destination:C:\1
8.162: Deleting File: \??\C:\windows\system32\CdnUnkw.dll.tmp ( incoming is a newer file )
8.162: Source:C:\windows\system32\character.dat
8.162: Destination:C:\1
8.162: Deleting File: \??\C:\windows\system32\character.dat ( incoming is a newer file )
8.162: Source:C:\windows\system32\character.dat.tmp
8.162: Destination:C:\1
8.162: Deleting File: \??\C:\windows\system32\character.dat.tmp ( incoming is a newer file )
8.162: Source:C:\windows\system32\character.dat
8.162: Destination:C:\1
8.162: Deleting File: \??\C:\windows\system32\character.dat ( incoming is a newer file )
8.162: Source:C:\windows\system32\character.dat.tmp
8.162: Destination:C:\1
8.162: Deleting File: \??\C:\windows\system32\character.dat.tmp ( incoming is a newer file )
8.162: Source:C:\windows\system32\CodeLib.dll
8.162: Destination:C:\1
8.172: Deleting File: \??\C:\windows\system32\CodeLib.dll ( incoming is a newer file )
8.172: Source:C:\windows\system32\CodeLib.dll.tmp
8.172: Destination:C:\1
8.172: Deleting File: \??\C:\windows\system32\CodeLib.dll.tmp ( incoming is a newer file )
8.172: Source:C:\windows\system32\CodeLib.dll
8.172: Destination:C:\1
8.172: Deleting File: \??\C:\windows\system32\CodeLib.dll ( incoming is a newer file )
8.172: Source:C:\windows\system32\CodeLib.dll.tmp
8.172: Destination:C:\1
8.172: Deleting File: \??\C:\windows\system32\CodeLib.dll.tmp ( incoming is a newer file )
8.172: Source:C:\windows\system32\hookdll.dll
8.172: Destination:C:\1
8.172: Deleting File: \??\C:\windows\system32\hookdll.dll ( incoming is a newer file )
8.172: Source:C:\windows\system32\hookdll.dll.tmp
8.172: Destination:C:\1
8.172: Deleting File: \??\C:\windows\system32\hookdll.dll.tmp ( incoming is a newer file )
8.172: Source:C:\windows\system32\hookdll.dll
8.182: Destination:C:\1
8.182: Deleting File: \??\C:\windows\system32\hookdll.dll ( incoming is a newer file )
8.182: Source:C:\windows\system32\hookdll.dll.tmp
8.182: Destination:C:\1
8.182: Deleting File: \??\C:\windows\system32\hookdll.dll.tmp ( incoming is a newer file )
8.182: Source:C:\windows\system32\IdnAcc.dll
8.182: Destination:C:\1
8.182: Deleting File: \??\C:\windows\system32\IdnAcc.dll ( incoming is a newer file )
8.182: Source:C:\windows\system32\IdnAcc.dll.tmp
8.182: Destination:C:\1
8.182: Deleting File: \??\C:\windows\system32\IdnAcc.dll.tmp ( incoming is a newer file )
8.182: Source:C:\windows\system32\IdnAcc.dll
8.182: Destination:C:\1
8.182: Deleting File: \??\C:\windows\system32\IdnAcc.dll ( incoming is a newer file )
8.182: Source:C:\windows\system32\IdnAcc.dll.tmp
8.182: Destination:C:\1
8.182: Deleting File: \??\C:\windows\system32\IdnAcc.dll.tmp ( incoming is a newer file )
8.182: Source:C:\windows\system32\IdnMail.exe
8.192: Destination:C:\1
8.192: Deleting File: \??\C:\windows\system32\IdnMail.exe ( incoming is a newer file )
8.192: Source:C:\windows\system32\IdnMail.exe.tmp
8.192: Destination:C:\1
8.192: Deleting File: \??\C:\windows\system32\IdnMail.exe.tmp ( incoming is a newer file )
8.202: Source:C:\windows\system32\IdnMail.exe
8.202: Destination:C:\1
8.202: Deleting File: \??\C:\windows\system32\IdnMail.exe ( incoming is a newer file )
8.202: Source:C:\windows\system32\IdnMail.exe.tmp
8.202: Destination:C:\1
8.202: Deleting File: \??\C:\windows\system32\IdnMail.exe.tmp ( incoming is a newer file )
8.202: Source:C:\windows\system32\Idnmail.ini
8.202: Destination:C:\1
8.202: Deleting File: \??\C:\windows\system32\Idnmail.ini ( incoming is a newer file )
8.202: Source:C:\windows\system32\Idnmail.ini.tmp
8.202: Destination:C:\1
8.202: Deleting File: \??\C:\windows\system32\Idnmail.ini.tmp ( incoming is a newer file )
8.202: Source:C:\windows\system32\Idnmail.ini
8.202: Destination:C:\1
8.202: Deleting File: \??\C:\windows\system32\Idnmail.ini ( incoming is a newer file )
8.202: Source:C:\windows\system32\Idnmail.ini.tmp
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT