汗,那个网址会下载灰鸽子
MS06-14漏洞,10进制加密
解后得:
http://hacktt.512j.com/nana/kdjj.exe
http://hacktt.512j.com/nana/exe.vbs
====================================================
[ DetectionInfo ]
* Sandbox name: NO_MALWARE
* Signature name: W32/Hupigon.dam
* Compressed: NO
[ General information ]
* Accesses executable file from resource section.
* Creating several executable files on hard-drive.
* File length: 293376 bytes.
* MD5 hash: ab975258b4c0bdc6158152700614214f.
[ Changes to filesystem ]
* Creates file C:\WINDOWS\DHOP.cn.
* Creates file C:\WINDOWS\DHOP.DLL.
[ Changes to registry ]
* Creates key "HKLM\System\CurrentControlSet\Services\Miarosoft Corpoystion".
* Sets value "ImagePath"="C:\WINDOWS\DHOP.cn" in key "HKLM\System\CurrentControlSet\Services\Miarosoft Corpoystion".
* Sets value "DisplayName"="DHOP Seystam Applia" in key "HKLM\System\CurrentControlSet\Services\Miarosoft Corpoystion".
[ Process/window information ]
* Creates a mutex DHOP.cn.
* Attempts to access service "Miarosoft Corpoystion".
* Creates service "Miarosoft Corpoystion (DHOP Seystam Applia)" as "C:\WINDOWS\DHOP.cn".
[ Signature Scanning ]
* C:\WINDOWS\DHOP.cn (293376 bytes) : no signature detection.
* C:\WINDOWS\DHOP.DLL (246784 bytes) : no signature detection.
看看有没有批量删除文本的工具吧
~~~