木马清除大师1110个病毒样本分析报告(Updated at 2008-05-10).
2008-05-10日我们的蜜罐网络一共捕获1110个病毒样本,木马病毒以aitlasys.exe,azzxaime.exe,jbhxabyt.exe,Nt_Sys32.Sys,oohxcbyt.dll, ypcqchlp.dll,yxcsbhlp.dll,zptlbsys.dll,zyzxeime.dll,变种数量最大,详细报告如下:
注:以下病毒均可以通过木马清除大师强力查杀,下载地址:http://www.lofocus.com/download
| 文件名 |
大小 |
CRC |
是否加壳 |
变种数量 |
病毒类型 |
| zzz.sys |
10880bytes |
0X33E2F002 |
否 |
1 |
Password |
| zyzxeime.dll |
172544bytes |
0X1F9D1342 |
否 |
5 |
BackDoor |
| zywmdime.dll |
537096bytes |
0XA8543F94 |
否 |
2 |
Password |
| zycbbime.dll |
489472bytes |
0XA5FFD69C |
否 |
1 |
BackDoor |
| zxpmmt.dll |
222208bytes |
0X7ECD0FFD |
否 |
2 |
KeyLogger |
| zxmsbwin.dll |
536584bytes |
0XDEF07270 |
否 |
1 |
BackDoor |
| zxmsawin.dll |
535812bytes |
0XCA74F87C |
否 |
2 |
Trojan |
| zxcsahlp.exe |
14212bytes |
0X8283B6D4 |
是 |
1 |
Password |
| ztiudy.dll |
211456bytes |
0X0058AA19 |
否 |
1 |
KeyLogger |
| zsvn0.exe |
31343bytes |
0X02DEB62E |
是 |
1 |
BackDoor |
| zscqahlp.exe |
14418bytes |
0X7D7CF9A7 |
是 |
1 |
Password |
| zrquiy.dll |
211456bytes |
0XC976200A |
否 |
2 |
KeyLogger |
| zqeqqt.dll |
222208bytes |
0XED94A18E |
否 |
2 |
BackDoor |
| zptlbsys.dll |
535300bytes |
0X11FA25C4 |
否 |
6 |
Password |
| zjydcx.dll |
215040bytes |
0X26D78FEB |
否 |
2 |
Trojan |
| zgfdet.dll |
225792bytes |
0X5B1146E6 |
否 |
1 |
KeyLogger |
| yxcschlp.dll |
533512bytes |
0X4AC1CFC3 |
否 |
2 |
BackDoor |
| yxcsbhlp.dll |
532740bytes |
0X0B68F968 |
否 |
3 |
Password |
| ypdjebmp.dll |
535812bytes |
0X4ACA1C1E |
否 |
2 |
Trojan |
| ypcqdhlp.dll |
534536bytes |
0X125D9124 |
否 |
1 |
Trojan |
| ypcqchlp.dll |
533252bytes |
0X9263AFC4 |
否 |
4 |
Trojan |
| ydgn.dll |
44176bytes |
0X165CCF18 |
否 |
1 |
Password |
| yawj27.exe |
12840bytes |
0X02E7FAB6 |
是 |
1 |
KeyLogger |
| xpst28.exe |
17176bytes |
0XA4B15714 |
否 |
1 |
KeyLogger |
| xkqn19.exe |
17176bytes |
0XBF919E6D |
否 |
1 |
Trojan |
| xia9.exe |
15360bytes |
0X7A33F6D3 |
否 |
2 |
KeyLogger |
| xia8.exe |
19255bytes |
0X1BFFAA90 |
是 |
2 |
BackDoor |
| xia7.exe |
14418bytes |
0XA5849721 |
是 |
2 |
Trojan |
| xia6.exe |
15872bytes |
0X3798FBA0 |
否 |
2 |
BackDoor |
| xia5.exe |
19667bytes |
0X8A0C8F8D |
是 |
2 |
Trojan |
| xia30.exe |
17552bytes |
0XC04CD502 |
否 |
2 |
Password |
| xia3.exe |
30837bytes |
0X32E8AF38 |
否 |
2 |
Trojan |
| xia29.exe |
19259bytes |
0X4C77342B |
是 |
2 |
Trojan |
| xia28.exe |
23184bytes |
0XD8E6681C |
否 |
2 |
Password |
| xia27.exe |
18178bytes |
0XD489AEE1 |
是 |
2 |
KeyLogger |
| xia26.exe |
18507bytes |
0X5C03EA84 |
是 |
2 |
Password |
| xia24.exe |
18623bytes |
0X5092EE01 |
是 |
2 |
Password |
| xia23.exe |
18891bytes |
0X4AADAE9F |
是 |
2 |
Password |
| xia22.exe |
18695bytes |
0X39D8D549 |
是 |
2 |
Trojan |
| xia21.exe |
19351bytes |
0XD577BD04 |
是 |
2 |
Trojan |
| xia20.exe |
18679bytes |
0XB7DD2175 |
是 |
2 |
KeyLogger |
| xia2.exe |
21287bytes |
0XDD94CC09 |
是 |
2 |
KeyLogger |
| xia19.exe |
16528bytes |
0X41762B5B |
否 |
2 |
Trojan |
| xia16.exe |
14887bytes |
0XE0F5AECD |
是 |
2 |
KeyLogger |
| xia15.exe |
19383bytes |
0XF1DCBD4A |
是 |
2 |
KeyLogger |
| xia13.exe |
15705bytes |
0X189DF299 |
是 |
2 |
Password |
| xia12.exe |
19347bytes |
0X0DC92E15 |
是 |
2 |
KeyLogger |
| xia11.exe |
19631bytes |
0XCB55A094 |
是 |
1 |
Trojan |
| xia10.exe |
24720bytes |
0X292DCBA8 |
否 |
2 |
KeyLogger |
| xgnfn.dll |
25744bytes |
0XCC3D08C1 |
否 |
1 |
BackDoor |
| wyrsdj.dll |
222208bytes |
0X7A553C15 |
否 |
2 |
Trojan |
| wyhesm.dll |
222208bytes |
0X76F03730 |
否 |
2 |
Password |
| wvde7.exe |
20329bytes |
0XD95AFF83 |
是 |
1 |
Password |
| WinSys16.Sys |
48253bytes |
0X4A950EF5 |
否 |
1 |
KeyLogger |
| whsasw.dll |
250880bytes |
0XCFA11136 |
否 |
2 |
KeyLogger |
| wgtpwl.dll |
222208bytes |
0XE19F5121 |
否 |
2 |
BackDoor |
| waxrfl.dll |
222208bytes |
0X06DD30BF |
否 |
1 |
Trojan |
| wamw26.exe |
15048bytes |
0X4DA019C1 |
是 |
1 |
Password |
| vtmc2.exe |
24684bytes |
0X470F50F2 |
是 |
1 |
KeyLogger |
| usbhdd.sys |
2944bytes |
0X40BFDD2C |
否 |
2 |
Trojan |
| update.exe |
11916bytes |
0XC1314585 |
是 |
3 |
KeyLogger |
| up.exe |
42405bytes |
0XB3A6B856 |
是 |
1 |
Trojan |
| ujqm9.exe |
20405bytes |
0X675862A3 |
是 |
1 |
BackDoor |
| tyfw10.exe |
20013bytes |
0X46100C05 |
是 |
1 |
Trojan |
| tqzg8.exe |
20645bytes |
0X9F3F1752 |
是 |
1 |
Trojan |
| toayvl.dll |
218624bytes |
0X9D0F18A1 |
否 |
2 |
Trojan |
| tmp140.tmp |
8192bytes |
0X119F171E |
否 |
1 |
Trojan |
| tmp13F.tmp |
7368bytes |
0X007E017E |
是 |
1 |
Trojan |
| tmp13E.tmp |
159708bytes |
0XA014297A |
是 |
1 |
Password |
| tmp13D.tmp |
5689bytes |
0X65F56606 |
是 |
1 |
Password |
| tmp13B.tmp |
107352bytes |
0X5767A773 |
否 |
1 |
BackDoor |
| tmp13A.tmp |
19784bytes |
0XAD6EB34B |
是 |
1 |
Password |
| tjfyabyt.exe |
14286bytes |
0X281BA434 |
是 |
2 |
Password |
| tdse12.exe |
14616bytes |
0X33EAD058 |
是 |
1 |
Trojan |
| s[1].exe |
1408bytes |
0X5652F15B |
是 |
2 |
Trojan |
| SysWoWa8.dll |
20251bytes |
0X4B6E67D5 |
是 |
1 |
BackDoor |
| SysWmWaV.dll |
19185bytes |
0X71B3BA2C |
否 |
1 |
Password |
| SysWdPp.dll |
18581bytes |
0X4AD31A13 |
是 |
1 |
Password |
| syscheck.exe |
1968bytes |
0X55918990 |
是 |
1 |
KeyLogger |
| sqomvx.dll |
207872bytes |
0XEC499E20 |
否 |
2 |
BackDoor |
| sperls.dll |
7168bytes |
0X3EAB2DE5 |
否 |
3 |
BackDoor |
| soft21[1].exe |
8196bytes |
0X1C6C001D |
否 |
1 |
KeyLogger |
| smpdtg.dll |
215040bytes |
0XCDE4BC8F |
否 |
2 |
BackDoor |
| sgrefg.dll |
215040bytes |
0X56168E32 |
否 |
3 |
BackDoor |
| SETUP.EXE |
1536bytes |
0X6CEE38FC |
否 |
1 |
Trojan |
| sehhter.dll |
26392bytes |
0X528A2563 |
否 |
1 |
KeyLogger |
| sefawe.dll |
8192bytes |
0XDB4A4E5B |
否 |
1 |
BackDoor |
| secdrv.sys |
5120bytes |
0XB9844096 |
否 |
2 |
Password |
| rgfjj.dll |
25880bytes |
0X659FAFFA |
否 |
1 |
BackDoor |
| rdthr.dll |
36120bytes |
0X48F3D62C |
否 |
1 |
Password |
| qjkd15.exe |
18677bytes |
0XF2434C37 |
是 |
1 |
BackDoor |
| ptjhchlp.dll |
533764bytes |
0X05C007F1 |
否 |
1 |
KeyLogger |
| ppix16.exe |
18481bytes |
0XB052260C |
是 |
1 |
Password |
| pop.sys |
1792bytes |
0XA1625B05 |
否 |
1 |
KeyLogger |
| pluw6.exe |
22296bytes |
0XD1BA3C15 |
否 |
1 |
KeyLogger |
| phih4.exe |
16664bytes |
0X3E2329A8 |
否 |
1 |
KeyLogger |
| pbnr24.exe |
16757bytes |
0X7D10BD64 |
是 |
1 |
Password |
| ozfycbyt.dll |
533252bytes |
0X0596A5B2 |
否 |
2 |
Trojan |
| oqrthc.dll |
28952bytes |
0XDDEF2C58 |
否 |
1 |
Password |
| opshbbty.dll |
533512bytes |
0XA4958E11 |
否 |
2 |
Trojan |
| oohxcbyt.dll |
536584bytes |
0X6A46F393 |
否 |
4 |
BackDoor |
| oohxbbyt.dll |
536324bytes |
0X246A8DEE |
否 |
2 |
Password |
| onjzalit.exe |
15318bytes |
0X9493B4D4 |
是 |
1 |
KeyLogger |
| Nt_Sys32.Sys |
44661bytes |
0X9090494E |
否 |
3 |
Trojan |
| ntuser.com |
13732bytes |
0X4E5CCA82 |
是 |
3 |
Password |
| NTDUBECT.EXE |
48132bytes |
0X00C4BC81 |
是 |
1 |
BackDoor |
| npdv29.exe |
15128bytes |
0X78E8462C |
否 |
1 |
Trojan |
| nodd.exe |
34996bytes |
0XC7CFAE49 |
是 |
1 |
Trojan |
| msosmsp2p32.sys |
3072bytes |
0X472CB8CC |
否 |
2 |
Password |
| msosmsfpfis64.sys |
2560bytes |
0X8D38EB04 |
否 |
1 |
Password |
| msosmhfp00.dll |
14346bytes |
0X7506CF98 |
是 |
2 |
Trojan |
| msosdohs00.dll |
13713bytes |
0XB84165F3 |
是 |
1 |
Trojan |
| msepbe.dll |
3464bytes |
0X9CC48826 |
是 |
1 |
Password |
| MSDOS.bat |
14984bytes |
0X48E2E8B0 |
是 |
1 |
BackDoor |
| mpmycapi.dll |
534276bytes |
0X6A717D5E |
否 |
1 |
KeyLogger |
| mnmhcsrv.dll |
537608bytes |
0X35F34C79 |
否 |
2 |
BackDoor |
| mndscsrv.dll |
532740bytes |
0X5D1B6EC2 |
否 |
2 |
Password |
| mm[1].exe |
13816bytes |
0XD976C989 |
是 |
1 |
Trojan |
| MicroSoft.pif |
56320bytes |
0X2E0229BA |
否 |
1 |
Password |
| mgmgmm.dll |
26392bytes |
0XA18ABF7F |
否 |
1 |
KeyLogger |
| mfdesy.dll |
225792bytes |
0X7073CCED |
否 |
2 |
Trojan |
| lsxe25.exe |
20357bytes |
0XC668EE93 |
是 |
1 |
BackDoor |
| lijzalit.dll |
534536bytes |
0X6B6C23EA |
否 |
1 |
BackDoor |
| kenecb.dll |
3951bytes |
0X85A0FBE9 |
是 |
1 |
BackDoor |
| k.k1 |
24846bytes |
0X4F0F304B |
是 |
1 |
Trojan |
| k.k |
24846bytes |
0X4F0F304B |
是 |
1 |
BackDoor |
| jzzn1.exe |
23168bytes |
0X15F60474 |
是 |
1 |
Password |
| jzijj.dll |
29976bytes |
0X5A145919 |
否 |
1 |
KeyLogger |
| jyjlt.dll |
38680bytes |
0XD0D9DD67 |
否 |
1 |
KeyLogger |
| jxzh3.exe |
23696bytes |
0X04CAA79B |
否 |
1 |
KeyLogger |
| jwnf17.exe |
19077bytes |
0XD9A02128 |
是 |
1 |
KeyLogger |
| jtwfbx.dll |
211456bytes |
0X6F17A960 |
否 |
2 |
Password |
| jckp18.exe |
16152bytes |
0X9885E0E9 |
否 |
1 |
Password |
| jbhxabyt.exe |
15697bytes |
0X5B280E7F |
是 |
3 |
Password |
| ismhasrv.exe |
17223bytes |
0XEA64BA58 |
是 |
2 |
BackDoor |
| isdsasrv.exe |
14180bytes |
0X78D17658 |
是 |
1 |
Trojan |
| hfrdzx.dll |
215040bytes |
0X1FFAEF41 |
否 |
2 |
Trojan |
| hfjg.dll |
28440bytes |
0XCC2BB576 |
否 |
1 |
Trojan |
| HBKrnl.dll |
20480bytes |
0X7FC139AD |
否 |
1 |
Password |
| HBKernel.sys |
13920bytes |
0XBE73D421 |
否 |
1 |
Trojan |
| go[1].exe |
13824bytes |
0XD01F5BAB |
否 |
1 |
BackDoor |
| gmjgty.dll |
9728bytes |
0XE5EE9FAE |
否 |
1 |
Trojan |
| gjpn14.exe |
23184bytes |
0XB260F6A4 |
否 |
1 |
BackDoor |
| gfhynrth.dll |
36632bytes |
0XF5F6E937 |
否 |
2 |
Trojan |
| fsrgeb.dll |
211456bytes |
0XA3F98FEB |
否 |
2 |
Trojan |
| fjyjy.dll |
29976bytes |
0X703F213B |
否 |
1 |
KeyLogger |
| fjnbv.dll |
26392bytes |
0X613F6DB8 |
否 |
2 |
BackDoor |
| fdght.dll |
8192bytes |
0X1D15DB03 |
否 |
1 |
BackDoor |
| euqu20.exe |
32893bytes |
0XC471A002 |
否 |
1 |
BackDoor |
| etshabty.exe |
14843bytes |
0X6E7EC651 |
是 |
2 |
Trojan |
| ektvm.dll |
16285bytes |
0X0C0FEDED |
是 |
2 |
Password |
| dscef.dll |
24856bytes |
0XBDFAE3D4 |
否 |
1 |
KeyLogger |
| drcj31.exe |
15640bytes |
0X1A3D03B7 |
否 |
1 |
Password |
| down[1].exe |
14384bytes |
0X0136C821 |
是 |
2 |
Trojan |
| ctfmon.exe |
5856bytes |
0X72242BA7 |
是 |
6 |
Trojan |
| csavpw0.dll |
19456bytes |
0XA208437B |
否 |
1 |
KeyLogger |
| crugd.dll |
42640bytes |
0X022A6815 |
否 |
3 |
BackDoor |
| cpry13.exe |
16016bytes |
0X6DF4CAC4 |
否 |
1 |
Password |
| cftmon.exe |
5052bytes |
0X592E809B |
是 |
1 |
Password |
| cedafb.dll |
222208bytes |
0X0C598A3E |
否 |
2 |
KeyLogger |
| bhis5.exe |
18712bytes |
0X980AC0AE |
否 |
1 |
Password |
| beup22.exe |
16977bytes |
0XCA7A628D |
是 |
1 |
KeyLogger |
| bak[1].css |
13732bytes |
0X4E5CCA82 |
是 |
3 |
Password |
| azzxaime.exe |
15656bytes |
0X30AD2F36 |
是 |
3 |
BackDoor |
| azwmaime.exe |
16318bytes |
0X3BA70607 |
是 |
1 |
KeyLogger |
| axmsawin.exe |
15741bytes |
0X584F4681 |
是 |
1 |
BackDoor |
| anistio.exE |
16109bytes |
0XE2F62F00 |
是 |
1 |
BackDoor |
| anistio.dll |
24860bytes |
0X6E6F9C05 |
否 |
1 |
Trojan |
| aitlasys.exe |
15353bytes |
0X1DF90060 |
是 |
4 |
BackDoor |
| agwu23.exe |
15640bytes |
0X12F569B9 |
否 |
1 |
KeyLogger |
| a014[1].exe |
1968bytes |
0X55918990 |
是 |
1 |
BackDoor |
| 9.exe |
18474bytes |
0X66289FA8 |
是 |
3 |
Trojan |
| 8.exe |
18678bytes |
0X98A434E5 |
是 |
3 |
Password |
| 7[1].exe |
23696bytes |
0X1DB22390 |
否 |
1 |
BackDoor |
| 7.exe |
16318bytes |
0X653D01F3 |
是 |
3 |
KeyLogger |
| 6[1].exe |
18712bytes |
0X85397E2A |
否 |
1 |
Trojan |
| 6.exe |
19311bytes |
0XF2FCB751 |
是 |
3 |
Password |
| 5[1].exe |
18712bytes |
0X180AB88F |
否 |
1 |
Trojan |
| 555888 |
46897bytes |
0X9E6D5CBA |
否 |
1 |
Trojan |
| 525181M.exe |
28733bytes |
0XBD8F9E9B |
是 |
1 |
Password |
| 5.exe |
19505bytes |
0X4D672E24 |
是 |
3 |
Password |
| 4.exe |
15353bytes |
0X8A9006A1 |
是 |
3 |
BackDoor |
| 3[1].exe |
20405bytes |
0X51E33209 |
是 |
1 |
Trojan |
| 3.exe |
15405bytes |
0X365459C7 |
是 |
3 |
KeyLogger |
| 2[1].exe |
16664bytes |
0X25C2997C |
否 |
1 |
Trojan |
| 21.exe |
30841bytes |
0X3A84DF20 |
否 |
1 |
Password |
| 20.exe |
15853bytes |
0XAE15ABEF |
是 |
1 |
KeyLogger |
| 2.exe |
16164bytes |
0XB7A2C57B |
是 |
3 |
BackDoor |
| 1[1].exe |
1167bytes |
0X61C80DB0 |
是 |
1 |
Trojan |
| 19.exe |
20405bytes |
0X155E2AFD |
是 |
2 |
Trojan |
| 18.exe |
20405bytes |
0X23B9156F |
是 |
2 |
KeyLogger |
| 17.exe |
15656bytes |
0X79443A18 |
是 |
3 |
Password |
| 16[1].exe |
16152bytes |
0XA1EAE6FC |
否 |
1 |
KeyLogger |
| 16186MM.DLL |
46897bytes |
0XAE8E7CA8 |
否 |
1 |
BackDoor |
| 16186M.exe |
28789bytes |
0XD22E6FB2 |
是 |
1 |
BackDoor |
| 16.exe |
19154bytes |
0XAE8CBE76 |
是 |
3 |
Trojan |
| 15[1].exe |
18834bytes |
0X341D336C |
是 |
1 |
Password |
| 15.exe |
14212bytes |
0X4379D423 |
是 |
3 |
Password |
| 14[1].exe |
18654bytes |
0X0BABD71F |
是 |
1 |
Password |
| 14.exe |
15612bytes |
0XF989965A |
是 |
3 |
Trojan |
| 13[1].exe |
19291bytes |
0X58847F7B |
是 |
1 |
Trojan |
| 13.exe |
23744bytes |
0XF80F9CE9 |
是 |
2 |
BackDoor |
| 12.exe |
19291bytes |
0X58847F7B |
是 |
2 |
BackDoor |
| 11.exe |
14311bytes |
0XAFB203B7 |
是 |
3 |
BackDoor |
| 10[1].exe |
18498bytes |
0X392D0ED6 |
是 |
1 |
KeyLogger |
| 10.exe |
16152bytes |
0X35D2A5FC |
否 |
3 |
Trojan |
| 1.exe |
14972bytes |
0X3E60E95D |
是 |
3 |
BackDoor |
| 1.11 |
7424bytes |
0X05858C09 |
否 |
1 |
KeyLogger |
| 1.1 |
7424bytes |
0X05858C09 |
否 |
1 |
Trojan |
| 0[1].exe |
24948bytes |
0X01FF4440 |
是 |
2 |
BackDoor |
| 014[1].exe |
11912bytes |
0XA500F874 |
是 |
2 |
Password |
| 0014[1].exe |
13772bytes |
0X4D41129E |
是 |
2 |
Password |
| 0.exe |
20405bytes |
0X228B1245 |
是 |
3 |
BackDoor | |