[2006-04-15]明修栈道、暗渡陈仓的灰鸽子BackDoor.Gpigeon.5.dq(第3版)

endurer 原创

2006-04-15 第3版 补充瑞星的回复:manageBackdoor.Gpigeon.ynjG_Server.exeBackdoor.Gpigeon.ykh
2006-04-12 第2版 补充Kaspersky的回复:manage 、G_Server.exe均为Backdoor.Win32.GrayBird.id
2006-04-12 第1

昨晚帮同事弄使用Win XP SP1的电脑,瑞星开机自动扫描报告:

IEXPLORE.EXE>>c:/Program Files/Internet Explorer/IEXPLORE.EXE感染BackDoor.Gpigeon.5.dq,清除成功。


用HijackThis扫描log,发现可疑服务启动项:

 


 

O23 - Service: Media Server - Unknown owner - C:/Program.exe (file missing)

 


 

重启到安全模式,设置系统显示所有文件和文件夹,不隐藏已知类型文件扩展名

没有发现文件C:/Program.exe。

到控制面板--》系统工具--》服务中,检查服务Media Server,发现该服务实际对应的文件是:C:/Program Files/Common Files/manage

文件manage的创建时间是:2006-04-11 18:07,文件大小是242 KB (247,808 字节)。

发现文件C:/Program Files/Common Files/1.22.exe,创建时间是:2006-04-11 18:08,经比较,此文件与manage完全相同。

发现文件c:/windows/G_Server.exe,创建时间为:2006-03-22 14:54,文件大小是594 KB (608,335 字节),使用JPG格式的图标,相当有迷惑性。

Server response


Results of a file scan

This is a report processed by VirusTotal on 04/11/2006 at 17:10:19 (CET) after scanning the file "unknown---G_Server.exe.rar" file.

AntivirusVersionUpdateResult
AntiVir6.34.0.2404.11.2006Heuristic/Crypted.Layered
Avast4.6.695.004.03.2006no virus found
AVG38604.11.2006no virus found
Avira6.34.0.5604.11.2006no virus found
BitDefender7.204.11.2006no virus found
CAT-QuickHeal8.0004.11.2006no virus found
ClamAVdevel-2006020204.11.2006no virus found
DrWeb4.3304.11.2006no virus found
eTrust-InoculateIT23.71.12604.11.2006no virus found
eTrust-Vet12.4.215804.11.2006no virus found
Ewido3.504.11.2006no virus found
Fortinet2.71.0.004.11.2006no virus found
F-Prot3.16c04.11.2006no virus found
Ikarus0.2.59.004.11.2006no virus found
Kaspersky4.0.2.2404.11.2006no virus found
McAfee473704.10.2006no virus found
NOD32v21.148204.11.2006no virus found
Norman5.90.1504.11.2006no virus found
Panda9.0.0.404.11.2006Suspicious file
Sophos4.04.004.11.2006no virus found
Symantec8.004.11.2006no virus found
TheHacker5.9.7.12804.11.2006no virus found
UNA1.8304.07.2006no virus found
VBA323.10.504.11.2006no virus found

 

VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Do not reply to this message. It has been generated by an automatic address that will not handle any reply. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

紫郢剑侠

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值