木马清除大师1205个病毒样本分析报告(Updated at 2008-05-07).
2008-05-07日我们的蜜罐网络一共捕获1205个病毒样本,木马病毒以acpidisk.sys,dionpis.dll,dionpis.exe,DoSSSetup.dll,eachnet.exe, fiosectc.dll,fiosectc.exe,fmsjhif.dll,fmsjhif.exe,huifitc.dll, 变种数量最大,详细报告如下:
注:以下病毒均可以通过木马清除大师强力查杀,下载地址:http://www.lofocus.com/download
| 文件名 |
大小 |
CRC |
是否加壳 |
变种数量 |
病毒类型 |
| ~Temp2479.tmp |
1408bytes |
0X5652F15B |
是 |
2 |
BackDoor |
| ~Temp2319.tmp |
1408bytes |
0X5652F15B |
是 |
1 |
BackDoor |
| ~de9F.tmp |
757760bytes |
0X21FC4605 |
否 |
2 |
BackDoor |
| zzz.sys |
10880bytes |
0X33E2F002 |
否 |
2 |
KeyLogger |
| zyzxeime.dll |
536324bytes |
0XE3E188B5 |
否 |
4 |
BackDoor |
| zywmdime.dll |
537096bytes |
0XA36AADFE |
否 |
2 |
KeyLogger |
| zywmcime.dll |
536836bytes |
0X5D24EE40 |
否 |
1 |
KeyLogger |
| zywlaime.dll |
535812bytes |
0X240B2282 |
否 |
2 |
Trojan |
| zxmsawin.dll |
535812bytes |
0X5D671D09 |
否 |
4 |
KeyLogger |
| zxcsahlp.exe |
14212bytes |
0X8283B6D4 |
是 |
1 |
KeyLogger |
| zscqahlp.exe |
14418bytes |
0X7D7CF9A7 |
是 |
1 |
BackDoor |
| zptlbsys.dll |
535300bytes |
0X11FA25C4 |
否 |
1 |
Password |
| zhishiku.exe |
24576bytes |
0X9439A1DD |
否 |
2 |
BackDoor |
| zaztamsn.exe |
15282bytes |
0XC311711A |
是 |
1 |
KeyLogger |
| z19.ext |
18029bytes |
0X5CA3B597 |
是 |
1 |
BackDoor |
| z17.ext |
14208bytes |
0X2C2E5251 |
是 |
1 |
BackDoor |
| yzztemsn.dll |
534276bytes |
0XCBC1E76E |
否 |
1 |
KeyLogger |
| yxcsbhlp.dll |
532740bytes |
0XA929F9CA |
否 |
2 |
Trojan |
| ypcqchlp.dll |
532228bytes |
0XD2A8672E |
否 |
2 |
BackDoor |
| XNGAnti.sys |
2816bytes |
0X20A2D8DF |
否 |
1 |
Password |
| wzpeatsd.dll |
31000bytes |
0X7F2EAFD8 |
否 |
3 |
BackDoor |
| WSockDrv32.exe |
19236bytes |
0X4BE9AD4C |
是 |
3 |
Password |
| WSockDrv32.dll |
33036bytes |
0X01B5046C |
否 |
3 |
Trojan |
| WinSys16.Sys |
48245bytes |
0XB650DA0B |
否 |
4 |
BackDoor |
| WinPact.exe |
35913bytes |
0X62BB6FE6 |
是 |
2 |
Trojan |
| wijham.dll |
222208bytes |
0X046232B8 |
否 |
1 |
BackDoor |
| usbhdd.sys |
2944bytes |
0X40BFDD2C |
否 |
1 |
KeyLogger |
| update.exe |
76309bytes |
0XD04ACF57 |
是 |
3 |
Trojan |
| UPDA4.tmp |
180224bytes |
0XB284E5DD |
否 |
2 |
Trojan |
| ufp8jaxgzj.sys |
45440bytes |
0X9D696EBA |
否 |
2 |
BackDoor |
| ttVUFVUF1011.dll |
6796bytes |
0XEBE4DBA1 |
是 |
3 |
BackDoor |
| ttQACQAC1038.dll |
7296bytes |
0X15D4E559 |
是 |
3 |
KeyLogger |
| ttNNBNNB1047.dll |
7023bytes |
0X3CD621CF |
是 |
3 |
BackDoor |
| toayvl.dll |
218624bytes |
0X9D0F18A1 |
否 |
1 |
KeyLogger |
| tmpE.tmp |
8192bytes |
0X4EEB6CCD |
否 |
1 |
Trojan |
| tmpC7.tmp |
14346bytes |
0X7506CF98 |
是 |
2 |
BackDoor |
| tmpC2.tmp |
46700bytes |
0X7EBC45A6 |
是 |
2 |
BackDoor |
| tmpBF.tmp |
8192bytes |
0X4CE173C2 |
否 |
2 |
KeyLogger |
| tjfyabyt.exe |
14286bytes |
0XD90A3ECE |
是 |
3 |
Password |
| ticisms.exe |
20541bytes |
0X38E5CC87 |
是 |
3 |
BackDoor |
| ticisms.dll |
31512bytes |
0X3428CEAB |
否 |
3 |
KeyLogger |
| tempaq1 |
147968bytes |
0X10FC733D |
否 |
1 |
KeyLogger |
| tempaq |
147968bytes |
0X10FC733D |
否 |
1 |
Trojan |
| tcpip.exe |
43008bytes |
0X4D32DFE5 |
否 |
2 |
BackDoor |
| s[1].exe |
1408bytes |
0X5652F15B |
是 |
1 |
Trojan |
| System76.Ins |
29268bytes |
0X599C2E32 |
否 |
1 |
Password |
| syscheck.exe |
1968bytes |
0X55918990 |
是 |
1 |
Password |
| sperls.dll |
7168bytes |
0X316C7345 |
否 |
1 |
KeyLogger |
| soundma.exe |
51042bytes |
0XDC7E30F6 |
是 |
1 |
Trojan |
| smpdtg.dll |
215040bytes |
0XCDE4BC8F |
否 |
1 |
KeyLogger |
| Setup35.exe |
97749bytes |
0X7F0AE712 |
否 |
3 |
BackDoor |
| Setup13.exe |
55620bytes |
0X4091B7CE |
否 |
3 |
KeyLogger |
| sehhter.dll |
26392bytes |
0X528A2563 |
否 |
1 |
KeyLogger |
| sefawe.dll |
8192bytes |
0XB329A3B8 |
否 |
1 |
Password |
| rrqe.dll |
53248bytes |
0X6F129DD2 |
否 |
1 |
BackDoor |
| RESSDT.sys |
2304bytes |
0X445F076D |
否 |
1 |
KeyLogger |
| RESSDT.exe |
33280bytes |
0X641BA9BD |
否 |
1 |
BackDoor |
| release.tmp |
97280bytes |
0X785F1598 |
否 |
1 |
KeyLogger |
| rdthr.dll |
33048bytes |
0X8E405F81 |
否 |
1 |
BackDoor |
| qqxyd.dll |
17920bytes |
0X899D55CD |
否 |
3 |
KeyLogger |
| qq.exe |
32885bytes |
0XF55FEDC1 |
否 |
3 |
Trojan |
| q5w1s9mu.dll |
167936bytes |
0XF8486AF5 |
否 |
2 |
BackDoor |
| ptshell.exe |
20013bytes |
0X2728B96C |
是 |
1 |
BackDoor |
| ptshell.dll |
30488bytes |
0X6515EA87 |
否 |
1 |
KeyLogger |
| ppfilm[1].exe |
1166bytes |
0XE4B68D53 |
否 |
1 |
BackDoor |
| portablemsi.dll |
33792bytes |
0X44306AAD |
否 |
2 |
Trojan |
| pop.sys |
1792bytes |
0XA1625B05 |
否 |
3 |
KeyLogger |
| ozfycbyt.dll |
533252bytes |
0XB5F04448 |
否 |
3 |
KeyLogger |
| oonb.dll |
73728bytes |
0X848E9220 |
否 |
1 |
Password |
| oohxbbyt.dll |
536324bytes |
0X246A8DEE |
否 |
1 |
KeyLogger |
| ntuser.com |
13348bytes |
0XA938F0AF |
是 |
4 |
BackDoor |
| ntdfdisk.sys |
4160bytes |
0X0B391C16 |
否 |
1 |
Trojan |
| msosping00.dll |
9803bytes |
0X711DDDFF |
是 |
4 |
Trojan |
| msosmsp2p32.sys |
3072bytes |
0X5A4D2758 |
否 |
3 |
BackDoor |
| msosmsfpfis64.sys |
2560bytes |
0X8D38EB04 |
否 |
4 |
Trojan |
| msosmnsf00.dll |
13031bytes |
0XF036807B |
是 |
3 |
KeyLogger |
| msosmhfp00.dll |
14489bytes |
0XB2E61405 |
是 |
1 |
Password |
| msosjtio00.dll |
11876bytes |
0X21FAEBD1 |
是 |
2 |
KeyLogger |
| msosiocp.dll |
6784bytes |
0XB055C30C |
是 |
1 |
Password |
| msosfmsq00.dll |
10402bytes |
0X40353173 |
是 |
3 |
KeyLogger |
| msosdohs00.dll |
13804bytes |
0X74E9678A |
是 |
3 |
Trojan |
| msms001.vwp |
424960bytes |
0XCA07FC25 |
否 |
1 |
Password |
| msepbe.dll |
3464bytes |
0X9CC48826 |
是 |
1 |
BackDoor |
| MSDOS.bat |
15000bytes |
0X63F9DCB0 |
是 |
3 |
KeyLogger |
| msdmo.dll |
14336bytes |
0XA1367814 |
否 |
1 |
Trojan |
| mscomfix64.exe |
139264bytes |
0XC119E226 |
否 |
4 |
BackDoor |
| mndscsrv.dll |
532740bytes |
0X0A479DA7 |
否 |
5 |
Password |
| mm[1].exe |
11015bytes |
0XE78FE5F2 |
否 |
2 |
Password |
| MMWLVAHB1017.dll |
11192bytes |
0XA9817C96 |
是 |
2 |
Password |
| MMSADZFB1045.dll |
10581bytes |
0X7160916F |
是 |
3 |
KeyLogger |
| mmlz.dll |
73728bytes |
0X7AC83AF8 |
否 |
1 |
KeyLogger |
| MMFKKLJK1071.dll |
10063bytes |
0X6DE62EDA |
是 |
2 |
Trojan |
| MMDXYBQE1016.exe |
18140bytes |
0XE377F9B3 |
是 |
2 |
Trojan |
| MMDXYBQE1016.dll |
10084bytes |
0X870B1D7A |
是 |
2 |
Password |
| MicroSofts.pif |
11432bytes |
0XB030A83E |
是 |
1 |
KeyLogger |
| MicroSoft.pif |
19020bytes |
0XBAFBEC26 |
是 |
1 |
Trojan |
| meex.exe |
43885bytes |
0X0E8AA99A |
否 |
1 |
KeyLogger |
| mc2C3.tmp |
2560bytes |
0X192F5E43 |
否 |
2 |
KeyLogger |
| mc23B.tmp |
2560bytes |
0X192F5E43 |
否 |
1 |
Trojan |
| MayaBabyMain.exe |
30588bytes |
0X183498DB |
是 |
2 |
BackDoor |
| MayaBabyDll.dat |
17896bytes |
0X6E0FD93F |
是 |
2 |
Trojan |
| lofsajbo.dll |
533764bytes |
0XC88D70CC |
否 |
3 |
BackDoor |
| lmmh.exe |
13804bytes |
0X2267A8AC |
是 |
3 |
BackDoor |
| ljenkdzz.exe |
20597bytes |
0X66BCB12F |
是 |
3 |
KeyLogger |
| kenecb.dll |
3951bytes |
0X85A0FBE9 |
是 |
1 |
BackDoor |
| kcbxta.dll |
167936bytes |
0X989EAAED |
否 |
1 |
Trojan |
| jjiw.dll |
475136bytes |
0X8B868145 |
否 |
2 |
KeyLogger |
| jfgrdh.dll |
218624bytes |
0X1103759E |
否 |
2 |
BackDoor |
| jdfsdf.exe |
7368bytes |
0X5D0065A2 |
是 |
2 |
BackDoor |
| jbhxabyt.exe |
15697bytes |
0X5B280E7F |
是 |
1 |
Password |
| issms32.exe |
19229bytes |
0XC9601F70 |
是 |
3 |
Trojan |
| issms32.dll |
28956bytes |
0XAF5D27EE |
否 |
3 |
Password |
| isdsasrv.exe |
14180bytes |
0X231D54BF |
是 |
2 |
KeyLogger |
| inudhya.dll |
95744bytes |
0XF7E92E9E |
否 |
3 |
BackDoor |
| huifitc.exe |
16737bytes |
0X5FFC0420 |
是 |
3 |
Trojan |
| huifitc.dll |
41240bytes |
0XD868641C |
否 |
3 |
Trojan |
| host.exe |
5872bytes |
0XCEAB8B3F |
是 |
3 |
KeyLogger |
| hfjg.dll |
28440bytes |
0XCC2BB576 |
否 |
1 |
Trojan |
| hapdrv.sys |
2688bytes |
0X526FB239 |
否 |
3 |
Trojan |
| h83t.sys |
45440bytes |
0X6CD80B05 |
否 |
2 |
KeyLogger |
| go[1].exe |
13824bytes |
0XC9A5698B |
否 |
1 |
KeyLogger |
| game.exe |
30188bytes |
0XF7280E77 |
是 |
3 |
Trojan |
| g11ouupol.dll |
167936bytes |
0XF7ECF25C |
否 |
2 |
Trojan |
| g0ld.com |
23404bytes |
0XF2039784 |
是 |
3 |
Password |
| fmsjhif.exe |
19749bytes |
0X5798FBCA |
是 |
3 |
KeyLogger |
| fmsjhif.dll |
29976bytes |
0XD5C89E62 |
否 |
3 |
KeyLogger |
| fiosectc.exe |
20461bytes |
0XA97CD515 |
是 |
3 |
Trojan |
| fiosectc.dll |
31516bytes |
0X28F90016 |
否 |
3 |
Password |
| ffes.dll |
40960bytes |
0X48D267D2 |
否 |
2 |
Password |
| fdght.dll |
8192bytes |
0X57AE96E3 |
否 |
1 |
Trojan |
| ektvm.dll |
16285bytes |
0X0C0FEDED |
是 |
1 |
KeyLogger |
| eachnet.exe |
45056bytes |
0X66F13E7C |
否 |
7 |
Password |
| duba[1].exe |
103979bytes |
0X357B5B90 |
否 |
2 |
KeyLogger |
| dqWLVWLV1012.dll |
10991bytes |
0XD827A410 |
是 |
1 |
Password |
| dqFKKFKK1063.dll |
9842bytes |
0X99D78309 |
是 |
1 |
KeyLogger |
| down[1].exe |
23618bytes |
0XAA685AF0 |
否 |
1 |
Password |
| down8[1].Exe |
21555bytes |
0X5B931EDF |
否 |
1 |
BackDoor |
| DoSSSetup.dll |
73728bytes |
0XA25F5ACA |
否 |
6 |
Password |
| dll.tmp |
97792bytes |
0X78EA6F99 |
否 |
2 |
Trojan |
| dionpis.exe |
20101bytes |
0X8D19034A |
是 |
3 |
Trojan |
| dionpis.dll |
30492bytes |
0X2E378F7A |
否 |
3 |
BackDoor |
| dfhtrhy.dll |
31512bytes |
0X0D404401 |
否 |
1 |
Trojan |
| dev04.inf |
81920bytes |
0XF85A76FB |
否 |
2 |
Password |
| D2.tmp |
20480bytes |
0X8669BC3E |
否 |
2 |
Trojan |
| D1.tmp |
34064bytes |
0X7D6820E0 |
否 |
2 |
BackDoor |
| ctfmon.exe |
5048bytes |
0X7428B68B |
是 |
7 |
Password |
| crugd.dll |
42640bytes |
0X1B52EC1E |
否 |
1 |
Password |
| cpush.dll |
176128bytes |
0XA877B761 |
否 |
2 |
Trojan |
| clfmon.exe |
19020bytes |
0XC5A31F37 |
是 |
3 |
Trojan |
| cihfob.dll |
222208bytes |
0X26C19A7B |
否 |
2 |
Trojan |
| b[1].exe |
7936bytes |
0XDFC72E33 |
是 |
1 |
KeyLogger |
| bincdwsa.exe |
16693bytes |
0X229A61BA |
是 |
1 |
KeyLogger |
| bincdwsa.dll |
25872bytes |
0X75C4084A |
否 |
1 |
BackDoor |
| bak[1].css |
13348bytes |
0XA938F0AF |
是 |
3 |
BackDoor |
| azzxaime.exe |
15656bytes |
0X1FD5247F |
是 |
1 |
BackDoor |
| ayoa.sys |
48224bytes |
0XF91D05F7 |
否 |
2 |
Trojan |
| axmsawin.exe |
15741bytes |
0X4A44EC26 |
是 |
1 |
BackDoor |
| ArpHack.exe |
211793bytes |
0X9390AACF |
是 |
2 |
BackDoor |
| arp111.exe |
282624bytes |
0X81CB63E3 |
否 |
3 |
Trojan |
| are[1].exe |
14984bytes |
0X48E2E8B0 |
是 |
2 |
BackDoor |
| anditbcd.exe |
20992bytes |
0X9D4F07AE |
否 |
2 |
Trojan |
| an.exe |
180224bytes |
0X05EA1AFE |
否 |
4 |
BackDoor |
| aitlasys.exe |
15353bytes |
0X1DF90060 |
是 |
1 |
KeyLogger |
| acpidisk.sys |
172676bytes |
0X469C1260 |
否 |
6 |
Password |
| a014[1].exe |
1968bytes |
0X55918990 |
是 |
2 |
KeyLogger |
| 7[1].exe |
23696bytes |
0X1DB22390 |
否 |
1 |
BackDoor |
| 6[1].exe |
18712bytes |
0X85397E2A |
否 |
1 |
Trojan |
| 614[1].exe |
7368bytes |
0X1B96DE6D |
是 |
1 |
Password |
| 5[1].exe |
18200bytes |
0XCB44FF1F |
否 |
1 |
Password |
| 5Ehosts.exe |
107352bytes |
0X5767A773 |
否 |
1 |
Trojan |
| 4Dmicrosoft.exe |
7368bytes |
0X5F0A7AAD |
是 |
1 |
KeyLogger |
| 47.tmp |
20480bytes |
0X8669BC3E |
否 |
1 |
Password |
| 46.tmp |
34064bytes |
0X7D6820E0 |
否 |
1 |
Trojan |
| 44[1].exe |
154351bytes |
0XC11B6859 |
否 |
2 |
KeyLogger |
| 42[1].exe |
116266bytes |
0XE46E98F9 |
否 |
2 |
Trojan |
| 41[1].exe |
24576bytes |
0XE7E0E816 |
否 |
2 |
BackDoor |
| 40[1].exe |
226974bytes |
0X4B413704 |
否 |
2 |
KeyLogger |
| 3[1].exe |
20405bytes |
0X51E33209 |
是 |
1 |
Trojan |
| 3Ccb.exe |
5689bytes |
0X65F56606 |
是 |
1 |
KeyLogger |
| 39[1].exe |
164010bytes |
0XC94E97F3 |
否 |
2 |
Password |
| 38[1].exe |
24576bytes |
0X979076DA |
否 |
2 |
Password |
| 36[1].exe |
173010bytes |
0X11083DBB |
否 |
1 |
Password |
| 36124.exe |
107555bytes |
0X9246D651 |
否 |
2 |
KeyLogger |
| 35[1].exe |
185724bytes |
0X5010F987 |
否 |
2 |
Password |
| 33[1].exe |
32881bytes |
0X986E5527 |
否 |
2 |
Password |
| 31[1].exe |
17509bytes |
0X92A35B5C |
是 |
2 |
BackDoor |
| 30.ext |
24148bytes |
0XB4672DF8 |
否 |
1 |
KeyLogger |
| 2[1].exe |
16664bytes |
0X25C2997C |
否 |
1 |
BackDoor |
| 2Bwow.exe |
19784bytes |
0XAD6EB34B |
是 |
1 |
KeyLogger |
| 29.ext |
32899bytes |
0X298C0F0B |
否 |
1 |
BackDoor |
| 26[1].exe |
18806bytes |
0X74CF013B |
是 |
1 |
BackDoor |
| 25[1].exe |
19194bytes |
0X2D19D250 |
是 |
2 |
Trojan |
| 25.ext |
16016bytes |
0X7B61E2F4 |
否 |
1 |
KeyLogger |
| 24.ext |
16664bytes |
0X856288D6 |
否 |
1 |
Trojan |
| 23[1].exe |
19118bytes |
0X6F5D1007 |
是 |
2 |
Trojan |
| 23.ext |
15128bytes |
0X832B1E38 |
否 |
1 |
KeyLogger |
| 22.ext |
16152bytes |
0XA7B1B447 |
否 |
1 |
BackDoor |
| 1Acq.exe |
28789bytes |
0XD22E6FB2 |
是 |
1 |
BackDoor |
| 17[1].exe |
13016bytes |
0X9533E5C4 |
是 |
1 |
Trojan |
| 179g1q9fig.sys |
45440bytes |
0X217B7051 |
否 |
2 |
BackDoor |
| 16[1].exe |
16152bytes |
0XA1EAE6FC |
否 |
1 |
KeyLogger |
| 16186MM.DLL |
46897bytes |
0XAE8E7CA8 |
否 |
1 |
Password |
| 15[1].exe |
17176bytes |
0X9B8A8035 |
否 |
2 |
BackDoor |
| 14[1].exe |
18654bytes |
0X0BABD71F |
是 |
1 |
KeyLogger |
| 1.exe |
148122bytes |
0XC212F4A3 |
否 |
4 |
BackDoor |
| 0[1].exe |
24948bytes |
0X01FF4440 |
是 |
1 |
Password |
| 014[1].exe |
23717bytes |
0XB6EA58C4 |
是 |
3 |
KeyLogger |
| 0014[1].exe |
15042bytes |
0X8CDA294B |
是 |
1 |
KeyLogger |
| 00042.exe |
14737bytes |
0XEE260C23 |
是 |
3 |
BackDoor |
| 00041.exe |
15869bytes |
0XBACC00D9 |
是 |
3 |
BackDoor |
| 00040.exe |
15241bytes |
0XE6C7053F |
是 |
3 |
KeyLogger |
| 00036.exe |
11700bytes |
0X248C7481 |
是 |
3 |
Trojan |
| 00035.exe |
18769bytes |
0X9BF5B462 |
是 |
3 |
KeyLogger |
| 00031.exe |
14854bytes |
0X21FE81F1 |
是 |
3 |
BackDoor |
| 00030.exe |
18645bytes |
0X8B9746B8 |
是 |
3 |
KeyLogger |
| 00021.exe |
12240bytes |
0X68150E24 |
是 |
3 |
KeyLogger |
| 00020.exe |
14063bytes |
0XE1977874 |
是 |
1 |
KeyLogger |
| 00019.exe |
15656bytes |
0X576960DD |
是 |
3 |
Password |
| 00016.exe |
15959bytes |
0XC6F927D7 |
是 |
3 |
Trojan |
| 00015.exe |
11963bytes |
0XD73EB5D0 |
是 |
3 |
Trojan |
| 00014.exe |
19003bytes |
0X52B4976C |
是 |
3 |
Password |
| 00011.exe |
15603bytes |
0X4524BD54 |
是 |
2 |
Trojan |
| 00006.exe |
15741bytes |
0XFF0D8FA7 |
是 |
3 |
KeyLogger |
| 00004.exe |
17738bytes |
0XA3BD81A0 |
是 |
3 |
BackDoor |
| 00003.exe |
14180bytes |
0X3F375063 |
是 |
3 |
KeyLogger |
| 00002.exe |
19633bytes |
0X92DE215A |
是 |
3 |
BackDoor |
| 00001.exe |
20605bytes |
0X43C08D8B |
是 |
3 |
Trojan |
| 0.exe |
19024bytes |
0X9AC59684 |
是 |
1 |
KeyLogger | |