AVɱÊÖľÂíTrojan.Win32.KillAV.acn£¨oqrxybz.sys£©

ʱ¼ä:2008-08-14 08:17:28  À´Ô´:  ×÷Õß:

 

¸ÃÑù±¾ÊÇʹÓÓDelphi”±àдµÄ“ľÂí³ÌÐò”£¬ÓÉ΢µãÖ÷¶¯·ÀÓùÈí¼þ×Ô¶¯²¶»ñ£¬²ÉÓÓUpack”¼Ó¿Ç·½Ê½ÊÔͼ¶ã±ÜÌØÕ÷ÂëɨÃè,¼Ó¿Çºó³¤¶ÈΪ“6,616 ×Ö½Ú”£¬Í¼±êΪ£¬Ê¹ÓÓexe”À©Õ¹Ãû£¬Í¨¹ý“ÍøÒ³Ä¾Â픡¢“ÎļþÀ¦°ó”µÈ·½Ê½Ö²ÈëÓû§¼ÆËã»ú£¬¶¯×÷ºó½«Ôì³ÉϵͳÖжàÊý°²È«Èí¼þ¼°ÏµÍ³¹¤¾ßÎÞ·¨Æô¶¯£¬ºóÏÂÔØÆäËûľÂí³ÌÐò¡£


²¡¶¾·ÖÎö

¸ÃÑù±¾³ÌÐò±»Ö´Ðкó£¬ÔÚ%SystemRoot%\system32\driversĿ¼ÏÂÊÍ·ÅÎļþ“oqrxybz.sys”£¬Ð´×¢²á±í½«Îļþ“oqrxybz.sys”×¢²á³ÉÃûΪ“oqrxybz”µÄ·þÎñ£¬Ê¹ÓÃÏà¹ØAPIº¯ÊýÆô¶¯±»×¢²áµÄ·þÎñ£»Çý¶¯¼ÓÔØºó´´½¨É豸“RESSDTDOS”£¬·ÃÎÊÉ豸»Ö¸´SSDTʹ¶àÊý°²È«Èí¼þ¼à¿ØÊ§Ð§¡£

  Quote:
ÏHKLM\SYSTEM\CurrentControlSet\Services\oqrxybz\
¼üÖµ£ºDisplayName
Ö¸ÏòÊý¾Ý£ºoqrxybz
ÏHKLM\SYSTEM\CurrentControlSet\Services\oqrxybz\
¼üÖµ£ºImagePath
Ö¸ÏòÎļþ£ºC:\windows\system32\drivers\oqrxybz.sys
ÏHKLM\SYSTEM\CurrentControlSet\Services\oqrxybz\
¼üÖµ£ºStart
Ö¸ÏòÊý¾Ý£º03


±éÀúϵͳµ±Ç°½ø³Ì²éÕÒÏÂÁнø³Ì²¢½«Æä½áÊø£¬Í¨¹ýÓ³Ïñ½Ù³ÖʹÆäÏ´ÎÎÞ·¨Æô¶¯£º

  Quote:
360rpt.exe
360safe.exe
autorunkiller
avp.exe
ccenter.exe
Icesword.exe
rav.exe
nod32krn.exe
HijackThis.exe
Nod32.exe
Nod32krn.exe
Nod32kui.exe
Ollydbg.exe
Ollyice.exe
Regdit.exe

Tags£º


ÉÏһƪ£ºÃ»ÓÐÁË   ÏÂһƪ£ºÃ»ÓÐÁË

ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0ÈË·¢±íÁËÆÀÂÛ ²é¿´ÍêÕûÄÚÈÝ