[2006

编程入门 行业动态 更新时间:2024-10-10 06:13:26

[2006

[2006

endurer 原创

2006-04-15 第3版 补充瑞星的回复:manageBackdoor.Gpigeon.ynjG_Server.exeBackdoor.Gpigeon.ykh
2006-04-12 第2版 补充Kaspersky的回复:manage 、G_Server.exe均为Backdoor.Win32.GrayBird.id
2006-04-12 第1

昨晚帮同事弄使用Win XP SP1的电脑,瑞星开机自动扫描报告:

IEXPLORE.EXE>>c:/Program Files/Internet Explorer/IEXPLORE.EXE感染BackDoor.Gpigeon.5.dq,清除成功。


用HijackThis扫描log,发现可疑服务启动项:

 


 

O23 - Service: Media Server - Unknown owner - C:/Program.exe (file missing)

 


 

重启到安全模式,设置系统显示所有文件和文件夹,不隐藏已知类型文件扩展名

没有发现文件C:/Program.exe。

到控制面板--》系统工具--》服务中,检查服务Media Server,发现该服务实际对应的文件是:C:/Program Files/Common Files/manage

文件manage的创建时间是:2006-04-11 18:07,文件大小是242 KB (247,808 字节)。

发现文件C:/Program Files/Common Files/1.22.exe,创建时间是:2006-04-11 18:08,经比较,此文件与manage完全相同。

发现文件c:/windows/G_Server.exe,创建时间为:2006-03-22 14:54,文件大小是594 KB (608,335 字节),使用JPG格式的图标,相当有迷惑性。

Server response


Results of a file scan

This is a report processed by VirusTotal on 04/11/2006 at 17:10:19 (CET) after scanning the file "unknown---G_Server.exe.rar" file.

AntivirusVersionUpdateResult
AntiVir6.34.0.2404.11.2006Heuristic/Crypted.Layered
Avast4.6.695.004.03.2006no virus found
AVG38604.11.2006no virus found
Avira6.34.0.5604.11.2006no virus found
BitDefender7.204.11.2006no virus found
CAT-QuickHeal8.0004.11.2006no virus found
ClamAVdevel-2006020204.11.2006no virus found
DrWeb4.3304.11.2006no virus found
eTrust-InoculateIT23.71.12604.11.2006no virus found
eTrust-Vet12.4.215804.11.2006no virus found
Ewido3.504.11.2006no virus found
Fortinet2.71.0.004.11.2006no virus found
F-Prot3.16c04.11.2006no virus found
Ikarus0.2.59.004.11.2006no virus found
Kaspersky4.0.2.2404.11.2006no virus found
McAfee473704.10.2006no virus found
NOD32v21.148204.11.2006no virus found
Norman5.90.1504.11.2006no virus found
Panda9.0.0.404.11.2006Suspicious file
Sophos4.04.004.11.2006no virus found
Symantec8.004.11.2006no virus found
TheHacker5.9.7.12804.11.2006no virus found
UNA1.8304.07.2006no virus found
VBA323.10.504.11.2006no virus found

 

VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Do not reply to this message. It has been generated by an automatic address that will not handle any reply. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

更多推荐

[2006

本文发布于:2024-02-06 05:31:28,感谢您对本站的认可!
本文链接:https://www.elefans.com/category/jswz/34/1746503.html
版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系,我们将在24小时内删除。
本文标签:

发布评论

评论列表 (有 0 条评论)
草根站长

>www.elefans.com

编程频道|电子爱好者 - 技术资讯及电子产品介绍!