10-16-2008
04:11 PM
- last edited on
10-17-2008
11:56 AM
by
Tony_Weiss
Sample download:
[link removed]
Kaspersky Internet Security 2009 Report:
Internet Explorer (events: 2)
2008/10/16 下午 10:22:04 Placed in group Untrusted : Heur.Downloader
2008/10/16 下午 10:22:05 Autorun Denied: KLPrivileges/KLSelfStart
2008/10/16 下午 10:22:05 Autorun Denied: KLPrivileges/KLSelfStart
Internet Explorer (events: 2)
2008/10/16 下午 10:22:05 Placed in group Untrusted : Heur.Downloader
2008/10/16 下午 10:22:05 Autorun Denied: KLPrivileges/KLSelfStart
2008/10/16 下午 10:22:05 Autorun Denied: KLPrivileges/KLSelfStart
Internet Explorer (events: 2)
2008/10/16 下午 10:22:09 Placed in group High Restricted
2008/10/16 下午 10:22:09 Create C:\WINDOWS\system32\winlbi32.dll Denied: KLSystemData/KLSystemFiles/SystemDll
2008/10/16 下午 10:22:09 Create C:\WINDOWS\system32\winlbi32.dll Denied: KLSystemData/KLSystemFiles/SystemDll
2008/10/16 下午 10:22:09 Create C:\WINDOWS\system32\winlbi32.dll Denied: KLSystemData/KLSystemFiles/SystemDll
2008/10/16 下午 10:22:09 Process start c:\windows\system32\cmd.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionPro
2008/10/16 下午 10:22:14 Code intrusion c:\program files\internet explorer\iexplore.exe Denied: KLPrivileges/KLPermissionAppAccess/KLPermissionPro
2008/10/16 下午 10:22:14 Code intrusion c:\program files\internet explorer\iexplore.exe Denied: KLPrivileges/KLPermissionAppAccess/KLPermissionPro
2008/10/16 下午 10:22:14 Process start c:\documents and settings\administrator\local settings\temp\twe3.bat Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionPro
2008/10/16 下午 10:22:15 Process start c:\documents and settings\administrator\desktop\keygen.bat Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionPro
Internet Explorer (events: 2)
2008/10/16 下午 10:22:10 Placed in group Trusted/MICROSOFT
2008/10/16 下午 10:22:11 Access to internal browser data Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObj
[edit: removed link per the Participation Guidelines and Terms of Service. Link is still on file.]
10-16-2008 04:14 PM
10-16-2008 04:24 PM - edited 10-16-2008 04:34 PM
Just want to Remind Symantec development team to FIX or upgrade Self-Defence
and Remain everyone have to upgrade to NIS 2009 because 2009 can detected as Suspicious. AH. 109
NIS2009+AntiBot is better !
:)
Regards from Taiwan !
AVPClub Security Forum - Kaspersky Section Moderator " Bug "
10-16-2008 05:34 PM
