土芭樂數位學堂

BigData 大數據分析, 大數據平台建置及應用 (Hadoop/spark),虛擬核⼼技術,資訊技術的分享, TiddlyWiki教學, Google 服務應用教學, 3D列印創意思維

8月 24, 2009

超可怕的大陸網頁病毒

此病毒,蠻慘的,因為大部分的防毒軟體都偵測不到,而且,此病毒幹了很多壞事。
執行之後,有下面的行為:

[DLL injection]
C:\Documents and Settings\Administrator\Local Settings\Temp\upx.dll (注入檔案總管的執行程序)
C:\WINDOWS\system32\cmdbcs.dll (注入檔案總管的執行程序)
C:\WINDOWS\system32\msccrt.dll (注入檔案總管的執行程序)
C:\WINDOWS\system32\windds32.dll (注入檔案總管的執行程序)
C:\WINDOWS\system32\windhcp.ocx (注入檔案總管的執行程序)
C:\WINDOWS\system32\wsttrs.dll (注入檔案總管的執行程序)
C:\WINDOWS\system32\wsvs.dll (注入檔案總管的執行程序)

[Added service]
NAME: Win32DDS
DISPLAY: Win32 Display Driver
FILE: C:\WINDOWS\system32\\rundll32.exe windds32.dll,input

NAME: WinDHCPsvc
DISPLAY: Windows DHCP Service
FILE: C:\WINDOWS\system32\\rundll32.exe windhcp.ocx,input

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.vbs
C:\Documents and Settings\Administrator\Local Settings\Temp\upx.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\upx.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\zaqxsw[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zaq10[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zaq2[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zaq5[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zaq9[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\zaq4[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\zaq7[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\zaq1[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\zaq3[1].exe
C:\Program Files\Common Files\System\IDrivers.pif
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\ctfnom.exe
C:\WINDOWS\system32\drivers\usbue.sys
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\windds32.dll
C:\WINDOWS\system32\windhcp.ocx
C:\WINDOWS\system32\wsttrs.dll
C:\WINDOWS\system32\wsvs.dll
C:\WINDOWS\wsttrs.exe
C:\WINDOWS\wsvs.exe

[Added registry]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
Value=wsvs,Data=C:\WINDOWS\wsvs.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
Value=wsttrs,Data=C:\WINDOWS\wsttrs.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
Value=upx,Data=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upx.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
Value=msccrt,Data=C:\WINDOWS\msccrt.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
Value=cmdbcs,Data=C:\WINDOWS\cmdbcs.exe

cmdbcs.exe
[ Trend ], "TSPY_ONLINEGA.SF"
ctfnom.exe:
[ Trend ], "TROJ_Generic"
IDrivers.pif:
[ Trend ], "TROJ_DLOADER.HRG"
msccrt.dll:
[ Trend ], "TSPY_ONLINEGA.ZT"
msccrt.exe:
[ Trend ], "TSPY_ONLINEGA.ZT"
upx.dll:
[ Trend ], "TSPY_ZHENGTU.CZ"
upx.exe:
[ Trend ], "TSPY_ZHENGTU.CZ"
windds32.dll:
[ Trend ], "TROJ_AGENT.KNG"
windhcp.ocx:
[ Trend ], "TROJ_AGENT.KNH"
wsttrs.dll:
[ Trend ], "TSPY_ZHENGTU.BO"
wsttrs.exe:
[ Trend ], "TSPY_ONLINEGA.SE"
wsvs.dll:
[ Trend ], "TSPY_LEGMIR.ALO"
wsvs.exe:
[ Trend ], "TSPY_ONLINEGA.GM"
zaq1[1].exe:
[ Trend ], "TSPY_ZHENGTU.CZ"
zaq2[1].exe:
[ Trend ], "TSPY_ONLINEGA.ZT"
zaq3[1].exe:
[ Trend ], "TROJ_AGENT.KEP"
zaq4[1].exe:
[ Trend ], "TSPY_ONLINEGA.GM"
zaq5[1].exe:
[ Trend ], "TSPY_ONLINEGA.SE"
zaq7[1].exe:
[ Trend ], "TROJ_Generic"
zaq9[1].exe:
[ Trend ], "TROJ_AGENT.KEQ"
zaq10[1].exe:
[ Trend ], "TSPY_ONLINEGA.SF"
zaqxsw[1].exe:
[ Trend ], "TROJ_DLOADER.HRG"
1[1].exe:
[ Trend ], "Possible_Infostl"
cmdbcs.dll:
[ Panda ], "Trj/Legmir.AMG"
[ Nod32 ], "a variant of Win32/PSW.Agent.NCC trojan"
[ HBEDV ], "HEUR/Malware"
[ Grisoft ], "Trojan horse PSW.Legendmir.DZP"
usbue.sys:
[ Symantec ], "Trojan Horse"
[ HBEDV ], "TR/Rootkit.Gen"

=================================================================================
預防重於治療:
1. TweakUI 上了沒,電腦記得要事先停掉「可缷除式媒體」的自動播放功能
2. kavo_killer.exe 及 HiJackThis.exe 隨時拿出來執行檢查 ,

沒有留言:

張貼留言