20170618

Trojan.Klassir

Trojan.Klassir
【外部リンク】
https://www.symantec.com/ja/jp/security_response/print_writeup.jsp?docid=2005-030223-4952-99
Windows の起動時に必ず Trojan.Klassir が実行されるように設定します。

次のプロセスを停止しようとします。

lexplore.exe
Drunk_lol.pif
Webcam_004.pif
sexy_bedroom.pif
naked_party.pif
love_me.pif
osm.exe
cz.exe
LOL.scr
Webcam.pif
hahahaha.pif
me_2005.pif
sister.pif
winhost.exe
LOL.scr
Webcam.pif
bedroom-thongs.pif
naked_drunk.pif
LMAO.pif
ROFL.pif
underware.pif
Hot.pif
new_webcam.pif
msnus.exe
sexy.jpg
updates.exe
msnmsr.exe
bedroom-things.pifnaked_drunk.pif
my_pussy.pif
ROFL.pif
Hot.pif
new_webcam.pif
ISASS.EXE
Beautiful Ass.pif
John Kerry as Super Chicken.scr
Kool.pif
Me & you pic!.pif
Me Pissed!.pif
sexy.pif
She Could Fit her Ass in a Teacup.pif
she's fuckin fit.pif
titanic2.jpg.pif
winis.exe
nvsc32.exe

次のファイルを削除しようとします。

Drunk_lol.pif
WINDOWSSystem32Drunk_lol.pif
WINDOWSSystemDrunk_lol.pif
WinntSystemDrunk_lol.pif
Webcam_004.pif
WINDOWSSystem32Webcam_004.pif
WINDOWSSystemWebcam_004.pif
WinntSystemWebcam_004.pif
sexy_bedroom.pif
WINDOWSSystem32sexy_bedroom.pif
WINDOWSSystemsexy_bedroom.pif
WinntSystemsexy_bedroom.pif
aked_party.pif
WINDOWSSystem32 aked_party.pif
WINDOWSSystem aked_party.pif
WinntSystem aked_party.pif
love_me.pif
WINDOWSSystem32love_me.pif
WINDOWSSystemlove_me.pif
Winntlove_me.pif
osm.exe
WINDOWSSystem32lexplore.exe
WINDOWSSystemlexplore.exe
WinntSystemlexplore.exe
LOL.scr
Webcam.pif
hahahaha.pif
me_2005.pif
sister.pif
cz.exe
WINDOWSSystem32winhost.exe
WINDOWSSystemwinhost.exe
WinntSystemwinhost.exe
LOL.scr
Webcam.pif
edroom-thongs.pif
aked_drunk.pif
LMAO.pif
ROFL.pif
underware.pif
Hot.pif
ew_webcam.pif
WINDOWSSystem32msnus.exe
WIDNOWSSystemmsnus.exe
WinntSystemmsnus.exe
sexy.jpg
WINDOWSSystem32updates.exe
WINDOWSSystemupdates.exe
WinntSystemupdates.exe
WINDOWSSystem32msnmsr.exe
WINDOWSSystemmsnmsr.exe
WinntSystemmsnsr.exe
Webcam.pif
edroom-things.pif
aked_drunk.pif
my_pussy.pif
WINDOWSSystem32ISASS.EXE
WINDOWSSystemISASS.EXE
WinntSystemISASS.EXE
Beautiful Ass.pif
John Kerry as Super Chicken.scr
Kool.pif
Me & you pic!.pif
Me Pissed!.pif
sexy.pif
She Could Fit her Ass in a Teacup.pif
she's fuckin fit.pif
itanic2.jpg.pif
WINDOWSSystem32winis.exe
WINDOWSSystemwinis.exe
WinntSystemwinis.exe
WINDOWSSystem32 vsc32.exe
WINDOWSSystem vsc32.exe
WinntSystem vsc32.exe
--

注目の投稿

Shadowserver Foundation http://65.49.1.117/

Shadowserver Foundation port 14491 discarded for LINK-FRMWRK: NO ENTRY IN LOOKUP TABLE TO COMPLETE OPERATION, GigaEthernet2.0 Wistron Neweb ...

人気の投稿