mssave.exe Backdoor/Agobot.chy
"Microsoft System Saver"="flcnfm.exe"
holdon.dyndns.org
casi.blogdns.com
comevisit.mentalstate.info
itsthat.mentalstate.info
whore.3xperienced.info
urknot.3xperienced.info
todayis.w33d420.be
digital.w33d420.be
hittin.w33d420.be
billysmells.micr0s0cks.info
buysome.micr0s0cks.info
yes.micr0s0cks.info
udontknow.makaveli7.be
philosophe.makaveli7.be
amalive.makaveli7.be
tupac.makaveli7.beextrmous.exe Backdoor/Agobot.chv
%SystemDir%\extrmous.exe, 262656字节
2、在注册表中添加下列启动项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mouse Adaptor" = extrmous.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Mouse Adaptor" = extrmous.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mouse Adaptor" = extrmous.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Mouse Adaptor" = extrmous.exe
这样,在Windows启动时,病毒就可以自动执行。explore.exe Backdoor/Agobot.chw
%SystemDir%\explore.exe, 111616字节
2、在注册表中添加下列启动项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"1337 virus" = explore.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"1337 virus" = explore.exe
这样,在Windows启动时,病毒就可以自动执行。
4、通过多种系统漏洞传播,可造成中毒计算机运行速度下降,局域网拥堵。guest.exe Trojan/Delf.kp
%SystemDir%\intasks.exe, 25671字节
%SystemDir%\msinetes.inf, 309字节
%SystemDir%\msinetes.pnf, 3304字节
%SystemDir%\svchest.exe, 15872字节
%SystemDir%\winpub.reg, 540字节
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSService" = svchest.exe
这样,在Windows启动时,svchest.exe就可以自动执行。phost.exe TrojanProxy.Ranky.dn
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"syshost.exe" = phost.exe
这样,在Windows启动时,病毒就可以自动执行。
2、开启后门代理端口,可供黑客远程使用,成为黑客进行黑客活动的跳板。lup.exe Backdoor.Agobot mssvcc.exe Backdoor.Agobot newname8.exe TrojanDownloader.VB.jr mousepad8.exe TrojanClicker.Small.gdh keyboard8.exe TrojanDownloader.VB.jq
运行后,首先向一个网络asp脚本提交新增感染报告,提交形式如下:
http://www.nonameforthisdomain.com/teller2.asp?rnd=[随机数]
然后获得一个要下载程序的列表:
http://www.nonameforthisdomain.com/data.asp?rnd=[随机数]&antisp=1
当前下载列表的内容如下:
http://content.dollarrevenue.com/keyboard8.exe,就是keyboard2.exe本身
http://content.dollarrevenue.com/mousepad8.exe,一个广告点击程序,可能弹出广告窗口
http://content.dollarrevenue.com/newname8.exe,木马下载器winsystems.exe Backdoor/Agobot.chx
%SystemDir%\winsystems.exe, 80842字节
2、在注册表中添加下列启动项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"winsystems25" = winsystems.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"winsystems25" = winsystems.exe
这样,在Windows启动时,病毒就可以自动执行。
3、连接IRC服务器boughtem.nowslate1703.info,接收并执行黑客命令
你可以使用这个链接引用该篇文章 http://publishblog.blogchina.com/blog/tb.b?diaryID=4811029
|
- 评论人:泡泡糖
2006-04-16 14:31:26
|
|||
lup.exe,晕,杀不死的。越生越多。 |
||||
|
- 评论人:冻结
2006-04-09 23:17:14
|
|||
我的sohu帐号被盗了,
|
||||
|
- 评论人:lzp1109
2006-04-08 11:30:33
|
|||
太谢谢你了,大哥 |
||||
|
- 评论人:w999888
2006-04-07 18:21:06
|
|||
专业反病毒工程师?不会是斑竹小白吧? |
||||
|
- 评论人:Awing
2006-04-06 19:44:39
|
|||
我从google连接到您的blog。
|
||||