摘自国外网站
明天还要去解决呢
1. COVERT ANALYSIS OF: TOPBARW1.EXE
File Names Used: 3
Paths Used: 1
Common File Name: TOPBARW1.EXE
Common Path: %WINDIR%\SYSTEM32\
Vendor Information: No Vendor details specified
TOPBARW1.EXE may use 3 or more path and file names, these are the most common:
1 :%WINDIR%\SYSTEM32\REGOLDED.EXE
2 :%WINDIR%\SYSTEM32\XXXRRRRR.EXE
File Name Structure: Normal
File and Path Structure: Normal
2. RELATIONSHIP ANALYSIS OF: TOPBARW1.EXE
No relationship details available for this
object3. ACTIVITY ANALYSIS OF: TOPBARW1.EXE
The following behaviors have been observed for this
object:
Invokes dll components.
Creates Run Keys.
Runs other programs.
Communicates with web sites using httpout protocols.
Has outbound communications.
4. PROPAGATION ANALYSIS OF: TOPBARW1.EXE
Malware Group Propagation Rate: Moderate (spreading)
Malware Group: Covert Sys Exec
Copyright Prevx Limited 2005, 2006