开头数字为1
O16 - DPF: {10000000-1000-0000-1000-000000000000}-
ms-its:mhtml:
file://C:\foo.mht!hoop://www.free32.com/POP.CHM::/sp.exe
TrojanDownloader.VBS.Psyme.q 和 Trojan.Win32.Spooner.f
ms-its:mhtml:
file://C:\MAIN.MHT!hoop://d.dialer2004.com//bestporn/main.chm::/load.exe
TrojanDownloader.Win32.Donn.r 和 TrojanProxy.Win32.Mitglieder.x
ms-its:mhtml:
file://C:\MAIN.MHT!hoop://d.dialer2004.com//ruzan/main.chm::/load.exe TrojanDownloader.Win32.Donn.r
mhtml:
file://C:\ARCHIVE.MHT!hoop://195.225.176.3//mas2/server.exe Trojan.Win32.Scagent.d
O16 - DPF: {10003000-1000-0000-1000-000000000000}-
ms-its:mhtml:
file://c:\nosuch.mht!hoop://195.225.177.8/count/chm/cool.chm::/cool.exe
TrojanDownloader.Win32.Agent.av
ms-its:mhtml:
file://C:\foo.mht!hoop://81.211.105.37/30096/online.chm::/on-line.exe
TrojanDownloader.Win32.Agent.k
ms-its:mhtml:
file://C:\foo.mht!hoop://195.225.177.13/11223/online.chm::/on-line.exe
TrojanDropper.Win32.Small.hx
ms-its:mhtml:
file://C: oo.mht!hoop://sexxxxtv.com/module.chm::/in.exe Trojan-Downloader.JS.generic
O16 - DPF: {10954C80-4F0F-11D3-B17C-00C0DFE39736}-
hoop://hot.thebugs.ws/fav.exe Trojan.Win32.StartPage.fg
O16 - DPF: {10A1B95D-5E35-4935-8BC3-D43E81E8105E}-
hoop://directplugin.com/dialers/109446.exe not-a-virus:PornWare.Downloader.Tibsystems
O16 - DPF: {11010101-1001-1111-1000-110112345678}-
ms-its:mhtml:
file://c:\nosuch.mht!hoop://69.50.179.54/winsearchie32.chm::/winsearchie32.exe
TrojanDropper.Win32.Small.ig
ms-its:mhtml:
file://c:\nosuch.mht!hoop://69.50.173.253/winsearchie32.chm::/winsearchie32.exe
TrojanDropper.Win32.Small.ig
ms-its:mhtml:
file://c:\nosuch.mht!hoop://69.31.79.102/searchinfoxyz.chm::/searchinfoxyz.exe
TrojanDownloader.Win32.Small.zd
ms-its:mhtml:
file://C:oo.mht!hoop://cellaphone.net/helps/079057/iehelp.chm::/win.exe
Trojan-Downloader.Win32.Small.aag
O16 - DPF: {11010101-1001-1111-1000-110164567732}-
ms-its:mhtml:
file://C:MAIN.MHT!hoop://www.008i.com//x//f//10213//inst.chm::/f10213.exe
TrojanDownloader.Win32.WinShow.af
O16 - DPF: {11111111-1111-1111-1111-11??????????}-
mhtml:
file://C:NO_SUCH_MHT.MHT!hoop://www.008k.com/partner/inst/f10213.exe
TrojanDownloader.Win32.Petrolin.a
mhtml:
file://C:NO_SUCH_MHT.MHT!hoop://www.008k.com/partner/inst/f22776.exe
TrojanDownloader.Win32.Small.ug
[请注意,?在这里代表某个数字,该种木马下载器的CLSID后几位是变动的,指向的是以f开头后加5个数字作为文件名的exe文件。]
O16 - DPF: {11111111-1111-1111-1111-111111111111}-
mhtml:
file://C:NXSFT.MHT!hoop://66.117.38.54:80/iex/ofile.exe?xdat=&url=hoop://66.117.38.54:80/dexDK534.exe
mhtml:
file://C:NXSFT.MHT!hoop://66.117.38.54:80/iex/ofile.exe?url=hoop://66.117.38.54:80/dexDE554.exe
mhtml:
file://C:NXSFT.MHT!hoop://66.117.38.54:80/iex/ofile.exe?url=hoop://66.117.38.54:80/dexDE535.exe
mhtml:
file://C:NXSFT.MHT!hoop://66.117.37.5:80/iex/ofile.exe?url=hoop://66.117.37.5:80/dexGB285.exe
mhtml:
file://C:NXSFT.MHT!hoop://66.117.38.54:80/iex/ofile.exe?url=hoop://66.117.38.54:80/dexUS585.exe
以上各exe文件均属于TrojanDownloader.Win32.Small家族
hoop://ams-download.nocreditcard.com/download/newdial-erp/1498/dialer.exe
not-a-virus:PornWare.Dialer.TBS-Access
hoop://ams-download.nocreditcard.com/download/newdial-erp/1676/dialer.exe
not-a-virus:PornWare.Dialer.TBS-Access
hoop://usa-download.nocreditcard.net/download/newdial-erp/1736/dialer.exe
not-a-virus:PornWare.Dialer.TBS-Access
hoop://207.246.124.105/cabs/ROOSTRS3002/TPS108.cab not-a-virus:AdvWare.BiSpy.d
hoop://www.springboard.nl/plugin/hotpages3.exe not-a-virus:PornWare.Dialer.Generic
hoop://seks.a4.pl/porno-filmy.exe not-a-virus:PornWare.Dialer.Plsex
[遇到CLSID:11111111-1111-1111-1111-111111111111(也许末尾几位有变动)请大家多加注意,因为这些项目可能与IE一个漏洞相关。这个CLSID下,如下的几个都很可能是恶意的。
file://c:\info6.cab
file://c:\windows\temp\demo.exe
file://c:\windows\calc.exe]
O16 - DPF: {11111111-1111-1111-1111-111111111112}-
hoop://www.latenight.nl/launcher.exe TrojanDownloader.Win32.Small.et
O16 - DPF: {11111111-1111-1111-1111-111111111123}-
ms-its:mhtml:
file://c:\nosuch.mht!hoop://www.search-and-more.com/clk/148.chm::/file.exe
TrojanDropper.Win32.Small.ig
ms-its:mhtml:
file://c:\nosuch.mht!hoop://www.search-and-more.com/clk/123.chm::/file.exe
TrojanDropper.Win32.Small.ig
新版本为 TrojanDropper.Win32.Small.lf
ms-its:mhtml:
file://D:est.mht!hoop://yanliangbbs.com/Skins/Default/_notes/test.chm::/test.exe
TrojanDropper.Win32.Delf.ef
its:mhtml:
file://C:.mht!hoop://69.50.191.52/2484/b.chm::/b.exe Trojan.Win32.StartPage.hb
O16 - DPF: {11111111-1111-1111-1111-111111111157}-
ms-its:mhtml:
file://c:\nosuch.mht!hoop://213.159.117.131/legal/x.chm::/load.exe
TrojanDownloader.Win32.Harnig.w
ms-its:mhtml:
file://c:\nosuch.mht!hoop://petite-virgins.biz/dl/adv15/x.chm::/load.exe
TrojanDownloader.Win32.Harnig.l
ms-its:mhtml:
file://c:\nosuch.mht!hoop://cashsearch.biz/legal/x.chm::/load.exe
TrojanDownloader.Win32.Harnig.r
ms-its:mhtml:
file://c:\nosuch.mht!hoop://213.159.117.131/dl/adv94/x.chm::/load.exe
TrojanDownloader.Win32.Harnig.y
ms-its:mhtml:
file://c:\nosuch.mht!hoop://213.159.117.133/dl/adv74/x.chm::/load.exe
TrojanDownloader.Win32.Harnig.y
ms-its:mhtml:
file://c:\nosuch.mht!hoop://super-gals.com/scj/rotation/templates/um2/x.chm::/ad.exe
TrojanDownloader.Win32.Donn.u
ms-its:mhtml:
file://c:\nosuch.mht!hoop://213.159.117.133/dl/adv63/x.chm::/load.exe
TrojanDownloader.Win32.Harnig.gen
ms-its:mhtml:
file://c:\nosuch.mht!hoop://213.159.117.133/dl/adv65/x.chm::/load.exe
TrojanDownloader.Win32.Harnig.al
ms-its:mhtml:
file://c:\nosuch.mht!hoop://213.159.117.133/dl/adv156/x.chm::/load.exe
TrojanDownloader.Win32.Small.yx
O16 - DPF: {11111111-1111-1111-1111-111111111171}-
ms-its:mhtml:
file://c:\\nosuch.mht!hoop://line-plus.com/newhelp.chm::/newhelp.exe
Trojan.Win32.StartPage.ij
O16 - DPF: {11111111-1111-1111-1111-111111111237}-
hoop://69.31.87.70/1/deaDE348.exe Trojan.Win32.Dialer.ay
O16 - DPF: {11111111-1111-1111-1111-111111111435}-
hoop://popka1978.ud-dial.biz/dexmsbb.exe Trojan.Win32.Dialer.av
O16 - DPF: {11111111-1111-1111-1111-11237}-
hoop://63.219.178.91/1/deaNZ309.exe Trojan.Win32.Dialer.ay
O16 - DPF: {11120607-1001-1111-1000-110199901123}-
hoop://www.n28.net/n009/on-line.exe Trojan.Win32.Dialer.ce
ms-its:mhtml:
file://C:\x.mht!hoop://sxwall.com//page1.chm::/test.exe
TrojanDownloader.Win32.Small.xt
O16 - DPF: {11212111-2121-1311-1141-115611111222} –
ms-its:mhtml:
file://d: oo.mht!hoop://69.50.166.213/users/john/web/axe/x.chm::/update.exe
Trojan-Downloader.Win32.Small.anf
O16 - DPF: {1167BEEB-1CB0-47C0-A491-1E40B8EF1285}-
hoop://www.cursorzone.com/cursors/Cherub_setup_td035.cab not-a-virus:AdvWare.IGetNet
hoop://media.euniverse.com/cursorzone/files/Cherub_setup_td035.cab TrojanDownloader.Win32.Keenval.c
O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000}-
hoop://www.eingang69.de/EroticAccess/Cabs/1796024.cab Trojan.Win32.Dialer.ck
hoop://www.browserplugin.com/eroticAccess/cabs/1764015.cab Trojan.Win32.Dialer.ck
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797}-(Installer Class)
hoop://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab TrojanDownloader.Win32.IstBar.fa
hoop://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab TrojanDownloader.Win32.IstBar.gen
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489}-
hoop://www.2nd-thought.com/files/install052.exe Trojan.Win32.SecondThought.g
hoop://www.2nd-thought.com/files/install.exe Trojan.Win32.SecondThought.r
hoop://www.2nd-thought.com/files/install042.exe Trojan.Win32.SecondThought.c
[注:hoop://www.2nd-thought.com/files/install0??.exe(??为两位数字) 均为Trojan.Win32.SecondThought及其变种]
O16 - DPF: {13D81535-D540-41F0-E8C3-6B94033D7FA9}-
hoop://82.179.166.72/1/gdnCN208.exe Trojan.Win32.Dialer.ay
O16 - DPF: {142016BF-5CCA-4C8D-AC01-C4A8F4044AD5}-
hoop://media.euniverse.com/cursorzone/files/Cat_Running_setup_td035.cab
TrojanDownloader.Win32.Keenval
TrojanDownloader.Win32.Keenval.b
TrojanDownloader.Win32.Keenval.c
O16 - DPF: {146D0CDE-BDC7-0DD9-25CA-00BB7ECE235A}-
hoop://213.159.117.150/1/gdnUS14.exe Trojan.Win32.Dialer.ay
O16 - DPF: {14B4AA8C-B624-440E-9730-26BA47E48A24}-
hoop://www.cursorzone.com/cursors/waving_flag2_setup_td035.cab not-a-virus:AdvWare.IGetNet
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A}-
hoop://www.spywarenuker.com/product/camp/SpywareNuker_com/SpywareNukerInstaller.exe TrojanDownloader.Win32.Agent.h
O16 - DPF: {15651C7C-E812-44A2-A9AC-B467A2233E7D} (SrchHook Class) -
hoop://www.123mania.com/GIDCAI32.cab not-a-virus:AdvWare.123Mania.c
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
hoop://public.windupdates.com/get_file.php?bt=ie&p=742ae6aabe7d3a41bcf4a5afcbb90dcf34dad1f7e20e580a8628a9310ebdbc79ff97ebe1e10940b1a7ee84d6b88713ffc07adc36a6c198daa84af66cad27b7bddb:0bcd3b08a0018c359992be6d71d48cd1
bridge-c284.cab/WinAdCtlX.dll not-a-virus:AdWare.WinAD
hoop://static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c1.cab not-a-virus:AdWare.WinAD.j
hoop://static.windupdates.com/cab/CDTInc/ie/bridge-c8.cab not-a-virus:AdWare.WinAD.j
hoop://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge-c15.cab not-a-virus:AdWare.WinAD.w
O16 - DPF: {1678F7E1-C422-11D0-AD7D-00400515CAAA} -
hoop://files.cometsystems.com/cometcursor/21_cometzone/comet.cab not-a-virus:AdWare.Comet.a
hoop://files.cometsystems.com/cometcursor/cobrand/comet.cab not-a-virus:AdWare.Comet.a
hoop://files.cometsystems.com/cometcursor/comet.cab not-a-virus:AdWare.Comet.g
O16 - DPF: {171DFC0E-BE53-4919-9DFB-528560D5153B}-
hoop://media.euniverse.com/cursorzone/files/spider_setup_td035.cab
TrojanDownloader.Win32.Keenval 和 TrojanDownloader.Win32.Keenval.b
O16 - DPF: {172AD74F-3EB9-6839-80BA-2C9F70F7C31B}-
hoop://213.159.117.150/1/gdnUS14.exe Trojan.Win32.Dialer.ay
O16 - DPF: {17716803-0E74-1448-ECCC-179A4786F337}-
hoop://213.159.117.150/1/gdnUS14.exe Trojan.Win32.Dialer.ay