木马清除大师815个病毒样本分析报告(Updated at 2008-05-09).
2008-05-09日我们的蜜罐网络一共捕获815个病毒样本,木马病毒以gfhynrth.dll,mndscsrv.dll,oohxbbyt.dll,WinSys16.Sys,yxcsbhlp.dll, yzztemsn.dll,zptlbsys.dll,zxmsawin.dll,zywmdime.dll,zyzxeime.dll, 变种数量最大,详细报告如下:
注:以下病毒均可以通过木马清除大师强力查杀,下载地址:http://www.lofocus.com/download
| 文件名 |
大小 |
CRC |
是否加壳 |
变种数量 |
病毒类型 |
| ~78.tmp |
10496bytes |
0X0B5E407E |
否 |
1 |
BackDoor |
| zzz.sys |
10880bytes |
0X33E2F002 |
否 |
1 |
KeyLogger |
| zyzxfime.dll |
536584bytes |
0XA5845E0E |
否 |
2 |
BackDoor |
| zyzxeime.dll |
536324bytes |
0X414D715D |
否 |
3 |
Trojan |
| zywmdime.dll |
537096bytes |
0XA8543F94 |
否 |
4 |
Password |
| zywlaime.dll |
536324bytes |
0X2FE5F3AA |
否 |
2 |
Trojan |
| zxpmmt.dll |
222208bytes |
0X7ECD0FFD |
否 |
1 |
Password |
| zxmsawin.dll |
535812bytes |
0X890989A2 |
否 |
5 |
KeyLogger |
| zrquiy.dll |
211456bytes |
0XC976200A |
否 |
2 |
BackDoor |
| zptlbsys.dll |
535300bytes |
0X11FA25C4 |
否 |
5 |
KeyLogger |
| yzztemsn.dll |
534276bytes |
0XCBC1E76E |
否 |
4 |
Trojan |
| yxcsbhlp.dll |
532740bytes |
0X0B68F968 |
否 |
4 |
Trojan |
| ypcqchlp.dll |
533252bytes |
0X9263AFC4 |
否 |
2 |
BackDoor |
| ydgn.dll |
44176bytes |
0X165CCF18 |
否 |
1 |
Password |
| x[1].exe |
6786bytes |
0X2963DFBC |
是 |
1 |
Password |
| xgnfn.dll |
25744bytes |
0XCC3D08C1 |
否 |
1 |
BackDoor |
| X7349.com |
149010bytes |
0X04B65FA7 |
否 |
2 |
Trojan |
| wzig2.exe |
24684bytes |
0X470F50F2 |
是 |
1 |
Password |
| WinSys16.Sys |
48252bytes |
0X6EFBE4C8 |
否 |
3 |
BackDoor |
| vuzf5.exe |
18712bytes |
0X980AC0AE |
否 |
1 |
BackDoor |
| urlcatch.dll |
36864bytes |
0XB70E0EFF |
否 |
2 |
BackDoor |
| update.exe |
11916bytes |
0XC1314585 |
是 |
4 |
BackDoor |
| uaqn5.exe |
18200bytes |
0X9EDC137A |
否 |
1 |
Trojan |
| toayvl.dll |
218624bytes |
0X9D0F18A1 |
否 |
2 |
Password |
| tmpFE.tmp |
8192bytes |
0X119F171E |
否 |
1 |
Password |
| tmpFD.tmp |
7368bytes |
0X007E017E |
是 |
1 |
Trojan |
| tmpFC.tmp |
159708bytes |
0XA014297A |
是 |
1 |
Password |
| tmp104.tmp |
107352bytes |
0X5767A773 |
否 |
1 |
Trojan |
| tmp103.tmp |
19784bytes |
0XAD6EB34B |
是 |
1 |
KeyLogger |
| tmp102.tmp |
5689bytes |
0X65F56606 |
是 |
1 |
Trojan |
| s[1].exe |
1408bytes |
0X5652F15B |
是 |
1 |
BackDoor |
| SysWoWa8.dll |
20251bytes |
0X4B6E67D5 |
是 |
1 |
KeyLogger |
| SysWdPp.dll |
18581bytes |
0X4AD31A13 |
是 |
1 |
Trojan |
| sycw22.exe |
16977bytes |
0X6E2398A9 |
是 |
1 |
BackDoor |
| svhost[1].exe |
24252bytes |
0X86B729C2 |
是 |
1 |
Password |
| svcos[1].exe |
23584bytes |
0X08418DA1 |
否 |
1 |
KeyLogger |
| svchost.exe |
23404bytes |
0XF2039784 |
是 |
1 |
BackDoor |
| SVCH0ST.pif |
13740bytes |
0X20AD106B |
是 |
1 |
KeyLogger |
| sperls.dll |
7168bytes |
0X316C7345 |
否 |
2 |
BackDoor |
| solp23.exe |
15640bytes |
0X12F569B9 |
否 |
1 |
KeyLogger |
| smpdtg.dll |
215040bytes |
0XCDE4BC8F |
否 |
2 |
BackDoor |
| SETUP.EXE |
1536bytes |
0X6CEE38FC |
否 |
1 |
Trojan |
| sehhter.dll |
26392bytes |
0X528A2563 |
否 |
1 |
Password |
| sefawe.dll |
8192bytes |
0XDB4A4E5B |
否 |
1 |
Trojan |
| rybl25.exe |
20357bytes |
0XC668EE93 |
是 |
1 |
Trojan |
| rgfjj.dll |
25880bytes |
0X659FAFFA |
否 |
1 |
Password |
| rdthr.dll |
33048bytes |
0X8E405F81 |
否 |
1 |
Trojan |
| qjke0.exe |
31343bytes |
0X02DEB62E |
是 |
1 |
BackDoor |
| pxnt16.exe |
18481bytes |
0XB052260C |
是 |
1 |
KeyLogger |
| ptjhchlp.dll |
533764bytes |
0X793E951E |
否 |
2 |
Trojan |
| ppfilm[1].exe |
1410bytes |
0X0B44D99C |
否 |
1 |
Trojan |
| pop.sys |
1792bytes |
0XA1625B05 |
否 |
1 |
BackDoor |
| ozfycbyt.dll |
533252bytes |
0XF39376E1 |
否 |
2 |
KeyLogger |
| owxo31.exe |
15640bytes |
0X1A3D03B7 |
否 |
1 |
BackDoor |
| oqrthc.dll |
28952bytes |
0XDDEF2C58 |
否 |
1 |
Password |
| opshabty.dll |
532740bytes |
0X803C8739 |
否 |
2 |
BackDoor |
| oohxbbyt.dll |
536324bytes |
0X246A8DEE |
否 |
4 |
KeyLogger |
| ojrr24.exe |
16757bytes |
0X7D10BD64 |
是 |
1 |
Trojan |
| ntuser.com |
23717bytes |
0XB6EA58C4 |
是 |
1 |
Password |
| NTDUBECT.EXE |
48132bytes |
0X00C4BC81 |
是 |
1 |
Password |
| msosmsp2p32.sys |
3072bytes |
0X472CB8CC |
否 |
2 |
KeyLogger |
| msosmsfpfis64.sys |
2560bytes |
0X904ADF24 |
否 |
1 |
KeyLogger |
| msosmhfp03.dll |
14395bytes |
0X90262420 |
是 |
1 |
Trojan |
| msosmhfp00.dll |
14346bytes |
0X7506CF98 |
是 |
2 |
Trojan |
| msosdohs00.dll |
13695bytes |
0X7946B30A |
是 |
1 |
BackDoor |
| msepbe.dll |
3464bytes |
0X9CC48826 |
是 |
1 |
BackDoor |
| MSDOS.bat |
14984bytes |
0X48E2E8B0 |
是 |
1 |
KeyLogger |
| mpmycapi.dll |
534276bytes |
0XBD7275E1 |
否 |
2 |
BackDoor |
| mnmhcsrv.dll |
537608bytes |
0X16AD6DFB |
否 |
2 |
Password |
| mndscsrv.dll |
532740bytes |
0X5D1B6EC2 |
否 |
4 |
Password |
| mm[1].exe |
13740bytes |
0X20AD106B |
是 |
1 |
KeyLogger |
| mlhs7.exe |
20329bytes |
0XD95AFF83 |
是 |
1 |
BackDoor |
| MicroSoft.pif |
73598bytes |
0X573D261F |
否 |
1 |
Password |
| mgmgmm.dll |
26392bytes |
0XA18ABF7F |
否 |
1 |
BackDoor |
| lkpy25.exe |
20221bytes |
0X6815AED8 |
是 |
1 |
Password |
| kkdn4.exe |
16664bytes |
0X3E2329A8 |
否 |
1 |
KeyLogger |
| khjy26.exe |
15048bytes |
0X4DA019C1 |
是 |
1 |
BackDoor |
| kenecb.dll |
3951bytes |
0X85A0FBE9 |
是 |
1 |
KeyLogger |
| jzijj.dll |
29976bytes |
0X5A145919 |
否 |
1 |
Trojan |
| jyjlt.dll |
38680bytes |
0XD0D9DD67 |
否 |
1 |
BackDoor |
| jqjg14.exe |
23184bytes |
0XB260F6A4 |
否 |
1 |
BackDoor |
| job[1].exe |
3796bytes |
0X3DB34BD5 |
是 |
1 |
KeyLogger |
| jill29.exe |
15128bytes |
0X78E8462C |
否 |
1 |
BackDoor |
| ismhasrv.exe |
17223bytes |
0XC93A9BDA |
是 |
1 |
Password |
| ijsg15.exe |
18649bytes |
0X9759948C |
是 |
1 |
Trojan |
| iejc19.exe |
17176bytes |
0XBF919E6D |
否 |
1 |
BackDoor |
| iebar23.0.dll |
450560bytes |
0X6C1571F7 |
否 |
1 |
Password |
| hxjz10.exe |
20013bytes |
0X46100C05 |
是 |
1 |
BackDoor |
| hfjg.dll |
28440bytes |
0XCC2BB576 |
否 |
1 |
BackDoor |
| hboy28.exe |
17176bytes |
0XA4B15714 |
否 |
1 |
BackDoor |
| go[1].exe |
13824bytes |
0XC9A5698B |
否 |
1 |
BackDoor |
| gnli17.exe |
19013bytes |
0XCBF07174 |
是 |
1 |
Trojan |
| gmjgty.dll |
8704bytes |
0X65792401 |
否 |
2 |
Password |
| gfhynrth.dll |
32024bytes |
0X38706C6B |
否 |
3 |
Trojan |
| getd15.exe |
18677bytes |
0XF2434C37 |
是 |
1 |
Trojan |
| fzvy30.exe |
13920bytes |
0X90E95839 |
是 |
1 |
KeyLogger |
| fyvf20.exe |
32893bytes |
0X759214BB |
否 |
1 |
Trojan |
| fjyjy.dll |
29976bytes |
0X703F213B |
否 |
1 |
Trojan |
| fjnbv.dll |
26392bytes |
0X613F6DB8 |
否 |
1 |
KeyLogger |
| fgkx22.exe |
15124bytes |
0X05B726F5 |
是 |
1 |
Trojan |
| fdght.dll |
8192bytes |
0X57AE96E3 |
否 |
2 |
Password |
| epimjs.dll |
102468bytes |
0X7638EF06 |
否 |
1 |
Password |
| ektvm.dll |
16285bytes |
0X0C0FEDED |
是 |
1 |
BackDoor |
| efsr8.exe |
20645bytes |
0X9F3F1752 |
是 |
1 |
Password |
| eewn18.exe |
16152bytes |
0X9885E0E9 |
否 |
1 |
BackDoor |
| dscef.dll |
24856bytes |
0XBDFAE3D4 |
否 |
1 |
Trojan |
| down[1].exe |
2555bytes |
0XF81902CD |
是 |
3 |
BackDoor |
| djzu3.exe |
23696bytes |
0X04CAA79B |
否 |
1 |
KeyLogger |
| ctfmon.exe |
5052bytes |
0XF8FE8D01 |
是 |
2 |
Password |
| cssp6.exe |
22296bytes |
0XD1BA3C15 |
否 |
1 |
BackDoor |
| crugd.dll |
42640bytes |
0X022A6815 |
否 |
2 |
BackDoor |
| chcj1.exe |
23168bytes |
0X15F60474 |
是 |
1 |
Password |
| cftmon.exe |
5052bytes |
0X592E809B |
是 |
1 |
KeyLogger |
| BoBo_ActiveX_V3[1].ocx |
791136bytes |
0X667F1D32 |
否 |
1 |
BackDoor |
| blic12.exe |
14616bytes |
0X33EAD058 |
是 |
1 |
KeyLogger |
| bhomgr.dll |
126976bytes |
0X5A09468E |
否 |
2 |
Trojan |
| bfxb27.exe |
12840bytes |
0X02E7FAB6 |
是 |
1 |
KeyLogger |
| barhelp24.0.dll |
265216bytes |
0XFE2BC92A |
否 |
1 |
Password |
| bak[1].css |
13732bytes |
0X4E5CCA82 |
是 |
2 |
Trojan |
| azqp9.exe |
20405bytes |
0X675862A3 |
是 |
1 |
KeyLogger |
| autolive.dll |
98304bytes |
0X8BB67F35 |
否 |
2 |
Trojan |
| auqw13.exe |
16016bytes |
0X6DF4CAC4 |
否 |
1 |
Trojan |
| atloader.dll |
36864bytes |
0XAAED1AB7 |
否 |
2 |
BackDoor |
| anistio.exE |
16137bytes |
0X8C5FFB1B |
是 |
1 |
Password |
| anistio.dll |
24860bytes |
0X8A83F8F7 |
否 |
1 |
KeyLogger |
| aitlasys.exe |
15353bytes |
0XE1BBBB92 |
是 |
1 |
Trojan |
| adx.dll |
32768bytes |
0XB9D4AE93 |
否 |
2 |
Password |
| a014[1].exe |
1968bytes |
0X55918990 |
是 |
1 |
Trojan |
| 900[1].exe |
19020bytes |
0XC5A31F37 |
是 |
1 |
BackDoor |
| 9.exe |
18498bytes |
0X392D0ED6 |
是 |
4 |
Password |
| 8.exe |
15697bytes |
0X5B280E7F |
是 |
4 |
BackDoor |
| 7.exe |
14418bytes |
0X7D7CF9A7 |
是 |
3 |
BackDoor |
| 6.exe |
23696bytes |
0X1DB22390 |
否 |
4 |
Password |
| 5.exe |
18712bytes |
0X85397E2A |
否 |
4 |
Trojan |
| 4.exe |
18200bytes |
0X30A8AEFD |
否 |
5 |
Trojan |
| 360tray.exe |
28672bytes |
0X3F587103 |
否 |
2 |
KeyLogger |
| 3.exe |
15353bytes |
0X1DF90060 |
是 |
4 |
BackDoor |
| 2.exe |
20405bytes |
0X51E33209 |
是 |
4 |
Trojan |
| 19.exe |
32892bytes |
0X1418731A |
否 |
1 |
Trojan |
| 18.exe |
16112bytes |
0X9466B553 |
是 |
1 |
KeyLogger |
| 17.exe |
14180bytes |
0X78D17658 |
是 |
3 |
Password |
| 16186MM.DLL |
46897bytes |
0XAE8E7CA8 |
否 |
1 |
BackDoor |
| 16186M.exe |
28789bytes |
0XD22E6FB2 |
是 |
1 |
KeyLogger |
| 16.exe |
16318bytes |
0X3BA70607 |
是 |
3 |
Password |
| 15.exe |
16152bytes |
0XA1EAE6FC |
否 |
4 |
KeyLogger |
| 14.exe |
18834bytes |
0X341D336C |
是 |
4 |
BackDoor |
| 13.exe |
18654bytes |
0X0BABD71F |
是 |
4 |
Trojan |
| 12.exe |
15282bytes |
0XC311711A |
是 |
5 |
Trojan |
| 11.exe |
15656bytes |
0X1FD5247F |
是 |
5 |
Password |
| 10.exe |
14212bytes |
0X8283B6D4 |
是 |
4 |
Trojan |
| 1.exe |
16664bytes |
0X25C2997C |
否 |
4 |
Password |
| 014[1].exe |
23717bytes |
0XB6EA58C4 |
是 |
2 |
BackDoor |
| 0014[1].exe |
13772bytes |
0X4D41129E |
是 |
3 |
BackDoor |
| 00110.dll |
1249280bytes |
0XCEC81391 |
否 |
1 |
Password |
| 0.exe |
15741bytes |
0X4A44EC26 |
是 |
5 |
Password | |