瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了..
熋貓ゞ - 2008-12-26 4:44:00
我妈妈上网时候,接到个"系统正被病毒入侵,请下载xpAntispyware2009来保护你的电脑"(英文的),我妈妈不知道,就下载了,,...
其实我还没有安装了瑞星2009,现在安装了以后,却不能查杀出任何病毒,包括使用卡卡,360......
而且我通过瑞星查找漏洞,下载更新,却显示不能连接到服务器.
通过浏览器也不能连接.
每次开机都有个安全危机的叉在右下脚,显示不能找到杀毒软件(其实我有瑞星).

大家知道怎么解决吗?!!
上别的网可以,就是不能上microsoft的更新网.

用户系统信息:Mozilla/5.0 (Windows; U; Windows NT 6.0; zh-CN; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
熋貓ゞ - 2008-12-26 5:36:00
请帮助我解决,一定啊..
:kaka4: :kaka4: :kaka4: :kaka4:
soboy - 2008-12-26 8:06:00
微软打击假冒软件:9天清理近40万台PC
12月25日消息,微软最近表示,在打击假冒安全软件活动的第二个月中,已经从近40万台PC上卸载了“Antivirus 2009”假冒软件。

  据国外媒体报道称,12月版“恶意软件清除工具”以最流行的假冒安全软件之一“Antivirus 2009”为打击目标。据微软称,“恶意软件清除工具”自12月9日发布以来,在9天之内就从394000多台PC上卸载了假冒安全软件 “Antivirus 2009”。

  上月,微软还从近100万台PC上卸载了象“Advanced Antivirus”、“Ultimate Antivirus 2008”和“XPert Antivirus”等另外数款假冒安全软件。

  12月版“恶意软件清除工具”针对的是被微软称为“W32/FakeXPA”的一种不同的恶意软件,其中包括名为“Antivirus XP”、“AntivirusXP 2008”和“Antivirus 2009”等假冒反病毒软件。

  由于犯罪分子作梗,Windows用户逐渐陷入假冒安全软件陷阱。据一名研究人员表示,犯罪分子通过在用户PC上安装假冒安全软件、然后再以不断的弹出式广告和病毒感染威胁来催促用户支付40-50美元购买毫无价值的信息,每年可以从中获得高达500万美元的收入。

  12月版“恶意软件清除工具”还将另外一款被微软认为是木马软件的“W32/Yektel”恶意软件作为清除目标。W32/Yektel模仿了 IE的安全警告功能。新版W32/Yektel木马软件在谷歌搜索结果网页中插入假冒的安全警告。一旦探测到URL中包含有“google”,就会插入下述假冒消息“Google已经检测到你的PC上有未注册的Antivirus 2009,Google建议你激活Antivirus 2009,以保护你的PC免受来自互联网的恶意软件侵扰。”

当然,Yektel的IE和Google警告中的链接会将用户引到一个催促用户支付50美元Antivirus 2009注册费的站点。

Windows用户可以通过微软网站或Windows更新服务下载“恶意软件清除工具”。
soboy - 2008-12-26 8:09:00
:default3: :default3: :default3:
目前还不知道怎么解决中
soaika - 2008-12-26 8:12:00
用卡卡扫描下流氓软件试试
soboy - 2008-12-26 8:13:00
你只能去微软官网:下载"恶意软件清除工具"
soboy - 2008-12-26 8:17:00
第三方安全软件目前还未能。。。
熋貓ゞ - 2008-12-26 10:41:00
谢谢大家了..
卡卡扫描过了..没有用啊....
试试恶意软件清除工具,有了好消息就告诉大家. .
熋貓ゞ - 2008-12-26 10:48:00
貌似有点作用,让我再仔细看看.
谢谢,soboy了.
夲號ヱ被ジ盜 - 2008-12-26 12:50:00
Downloader.Win32.Agent.bs
http://www.ca.com/cn/securityadvisor/virusinfo/virus.aspx?id=74719



病毒详细信息
Win32/FakeAV.JW 发布日期:
2008/11/5
上次更新时间:
2008/11/5

威胁评估 总体风险: 


猖獗程度: 



破坏程度: 


普遍程度: 


特征 类型 : Trojan
类别 : Win32
其他名称: Downloader.Win32.Agent.bs (Kaspersky), TrojanDownloader:Win32/FakeRean (MS OneCare)

即时保护信息
特征码产品删除指导
31.6.6140
CA Antivirus 2007
查看
31.6.6140
eTrust Antivirus v7/8*
查看
7.x/6140
eTrust EZ Antivirus 7.x
查看
31.6.6140
Vet 7
查看


工具 下载特征码文件
扫描病毒
提交病毒样本



描述
感染方式
有效负载
其他信息

描述 Win32/FakeAV.JW is a trojan that disguises itself as a legitimate anti-virus program and displays various popup messages warning of fake infections. It may also download additional malware to the compromised system. 返回顶部

感染方式 When executed, Win32/FakeAV.JW informs the user that it is downloading "XP Antivirus 2009":



It downloads the following files from the URL www.xpantispyware-2009.com:

Binaries1.cab
Binaries2.cab
Binaries3.cab


It extracts and executes the downloaded files, then creates the following directory containing the malware files:

%Program Files%\XP_AntiSpyware

Note: %Program Files% is a variable location. The malware determines the location of the current Program Files folder by querying the operating system. A typical location for this folder would be C:\Program Files.

It also creates the following files as part of its installation:

%Windows%\wiadebug.log
%Windows%\wiaservc.log
%Documents and Settings%\<
username >\Start Menu\Programs\XP_AntiSpyware\Uninstall.lnk
%Documents and Settings%\<
username>\Start Menu\Programs\XP_AntiSpyware\XP_AntiSpyware.lnk

Note: %Windows% and %Documents and Settings% are variable locations. The malware determines the locations of these folders by querying the operating system. The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95, 98 and ME is C:\Windows; and for XP and Vista is C:\Windows. A typical location for Documents and Settings is C:\Documents and Settings.   

The trojan adds the registry entry below to automatically execute itself on system start:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\XP Antispyware 2009 = "%Program Files%\XP_AntiSpyware\XP_AntiSpyware.exe" /hide"

It also adds the following registry entries:

HKCU\Control Panel\don't load\scui.cpl = "No"
HKCU\Control Panel\don't load\wscui.cpl = "No"
HKLM\SOFTWARE\XP_Antispyware
HKLM\SOFTWARE\XP_Antispyware\info = "<
date of infection >"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XP_AntiSpyware


Additionally, the trojan displays the user interface for "XP Antivirus 2009", where it pretends to scan the system while reporting numerous 'infections':



返回顶部

有效负载 Disables Security NotificationsWin32/FakeAV.JW disables the Windows Firewall, updates, and antivirus reports by modifying the registry entries below:

HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify = dword:00000001
HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify = dword:00000001
HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify = dword:00000001


Displays False WarningsWin32/FakeAV.JW displays a fake Windows Security Center:



as well as warnings about fake infections:



It also displays popup messages in the taskbar that inform the user of false infections:

Privacy alert!
Your system was found to be infected with intercepting programs. These can log your activity and damage your privacy. Click here for XP Antispyware 2009 spyware removal.


------------------------------------------------------------

Trojan detected!
A piece of malicious code was found in your system which can replicate itself if no action is taken. Click here to have your system cleaned by XP Antispyware 2009.


------------------------------------------------------------

Spyware alarm!
Our scan has reported that pieces of malicious spyware code are present on your hard drive. To get rid of security threats, click here for a XP Antispyware 2009 scan.


------------------------------------------------------------

Privacy is at risk!
Attention, keylogging and intercepting scripts were detected. Your private data may be disclosed to third parties. Click here and XP Antispyware 2009 will remove the infection.






Downloads and Executes Arbitrary FilesWin32/FakeAV.JW attempts to access the following websites to report its activities and to download additional rogue software:

domake-progress.com
do-managedscan.com
domanaged-scan.com
do-fixed-progress
do-monster-scan.com
xp-as-2009.com
xpas2009.com
xpantispyware-2009.com
xp-antispyware-2009.com
xp-antispyware2009.com
xpas-2009.com
xp-as2009.com


返回顶部

其他信息 Below is a screenshot of the website that attempts to entice users to download the trojan. Product certifications displayed in the website are fake and designed to scam unsuspecting users:



The following are additional images of Win32/FakeAV.JW running on an affected system:





Analysis by Zarestel Ferrer
熋貓ゞ - 2008-12-26 12:52:00
我在我vista的机子上下载了,试了可以.
但是转移到我的xp机子上,就不行了...根本打开不了..
哎,,,我又试了试,这个病毒,把我所有的microsoft更新程序都屏蔽了..!!!
从microsoft.com上面什么都下载不了.!!!!!!!
夲號ヱ被ジ盜 - 2008-12-26 13:00:00
来个SRENG日志
http://www.kztechs.com/sreng/download.html
x应该可以解决
http://www.micropoint.com.cn/mpdownload.php
SORRY。。。。。打错了
打不出来屏蔽了
熋貓ゞ - 2008-12-27 6:42:00
10楼的兄弟很厉害啊..
就是那个!!!!
一模一样的东西. !!!
好险我没有交钱!!!!!

在12楼下载看看的说...
熋貓ゞ - 2008-12-27 6:44:00
我说,
那个 x主动防御软件可不可以帮我解决啊?!!!!
大哥,你那个叉是什么意思啊......(可以还是不可以嘛....)

貌似那个病毒十分顽强....
什么有点作用的东西都被它给屏蔽了..
我还在安全模式试了一下,不行啊..
soboy - 2008-12-27 8:27:00


引用:
原帖由 熋貓ゞ 于 2008-12-27 6:44:00 发表
我说,
那个 x主动防御软件可不可以帮我解决啊?!!!!
大哥,你那个叉是什么意思啊......(可以还是不可以嘛....)

貌似那个病毒十分顽强....
什么有点作用的东西都被它给屏蔽了..
我还在安全模式试了一下,不行啊..

x
我没用过,只要是因为它英文版我安装不了
LZ弄好记得说说经验
夲號ヱ被ジ盜 - 2008-12-27 12:59:00
http://devbuilds.kaspersky-labs. ... 6.12.2008_11-34.exe
试试卡巴的顽固清除工具(更新至2008.12.26)
应该杀出FraudTool.Win32.XPSecurityCenter.as
刚才研究了下

删除注册表的
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run xp antispyware 2009

删除DLL:
%program_files%\xp_antispyware\pthreadvc2.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcr80.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcp80.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcm80.dll
%program_files%\xp_antispyware\htmlayout.dll
%program_files%\xp_antispyware\avengn.dll
删除注册表:
HKEY_CURRENT_USER\control panel\don't load scui.cpl
HKEY_CURRENT_USER\control panel\don't load wscui.cpl
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run xp antispyware 2009
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xp_antispyware
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xp_antispyware displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xp_antispyware uninstallstring
HKEY_LOCAL_MACHINE\software\xp_antispyware
HKEY_LOCAL_MACHINE\software\xp_antispyware info
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run xp antispyware 2009
删除文件:_scui.cpl
081022_6692386
avengn.dll
azysymemur.vbs
file[1].exe
flashba.pdf
flashba1.pdf
install(2).ex17
install(2).ex18
install.ex11
install.ex12
install.ex13
install.ex15
install.ex16
install.ex19
install.ex20
install.ex21
brastk.exe
install.exe
uninstall.exe
wini10252.exe
wini10431.exe
wini10602.exe
wini10731.exe
wscui.cpl
xp_antispyware.exe
wini10451631.exe
ysywim.exe
zecevy.scr
zogojiv.exe
%desktopdirectory%\xp_antispyware.lnk
%profile%\application data\azysymemur.vbs
%profile%\application data\ewaqog.db
%profile%\application data\microsoft\internet explorer\quick launch\xp_antispyware.lnk
%profile%\application data\oxev._dl
%profile%\application data\ujef.dl
%profile%\application data\zecevy.scr
%profile%\documents\baja.dat
%profile%\documents\ogufybufub._dl
%profile%\documents\tohiwaxaw.dat
%program_files%\common files\aludi.bat
%program_files%\common files\etyxe.dl
%program_files%\common files\ikuqywa.bin
%program_files%\common files\qiqifos.pif
%program_files%\xp_antispyware\pthreadvc2.dll
%program_files%\xp_antispyware\avengn.dll
%program_files%\xp_antispyware\comp.dat
%program_files%\xp_antispyware\data\daily.cvd
%program_files%\xp_antispyware\htmlayout.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\microsoft.vc80.crt.manifest
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcm80.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcp80.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcr80.dll
%program_files%\xp_antispyware\uninstall.exe
%program_files%\xp_antispyware\wscui.cpl
%program_files%\xp_antispyware\xp_antispyware.cfg
%program_files%\xp_antispyware\xp_antispyware.exe
%programs%\xp_antispyware\uninstall.lnk
%programs%\xp_antispyware\xp_antispyware.lnk
%system%\_scui.cpl
%system%\agat.lib
%system%\atoqore.bin
%system%\focegyj.dat
%system%\wini10731.exe
%windows%\eruqogoxuc.dl
%windows%\odajuxomyf.dat
%windows%\olyzo.com
%windows%\ovexaz.bat
%windows%\utan.dat
%windows%\yvisycum.lib
%program_files%\xp_antispyware\pthreadvc2.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcr80.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcp80.dll
%program_files%\xp_antispyware\microsoft.vc80.crt\msvcm80.dll
%program_files%\xp_antispyware\htmlayout.dll
%program_files%\xp_antispyware\avengn.dll
zogojiv.exe
wini10602.exe
ysywim.exe
wini10451631.exe
wini10431.exe
wini10252.exe
file[1].exe
install.exe
brastk.exe
%program_files%\xp_antispyware\xp_antispyware.exe
%system%\wini10731.exe
%program_files%\xp_antispyware\uninstall.exe
删除目录:
%program_files%\xp_antispyware
%programs%\xp_antispyware
熋貓ゞ - 2008-12-29 10:42:00
看来,只有重装了....
重装才是王道啊.....

郁闷.
1
查看完整版本: 我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了..