瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 致“影子110”——关于你那个样本

1   1  /  1  页   跳转

致“影子110”——关于你那个样本

致“影子110”——关于你那个样本

与先前那个网友提供的样本基本相同。感染系统后,HJ日志中出现大量O1项,但无其它异常发现:

O1 - Hosts: 218.5.76.71 1ting.com
O1 - Hosts: 218.5.76.71 www.1ting.com
O1 - Hosts: 218.5.76.71 yy138.com
O1 - Hosts: 218.5.76.71 www.yy138.com
O1 - Hosts: 218.5.76.71 dj99.com
O1 - Hosts: 218.5.76.71 www.dj99.com
O1 - Hosts: 218.5.76.71 520music.com
O1 - Hosts: 218.5.76.71 www.520music.com
O1 - Hosts: 218.5.76.71 vv66.com
O1 - Hosts: 218.5.76.71 www.vv66.com
O1 - Hosts: 218.5.76.71 666ccc.com
O1 - Hosts: 218.5.76.71 www.666ccc.com
O1 - Hosts: 218.5.76.71 666qqq.com
O1 - Hosts: 218.5.76.71 www.666qqq.com
O1 - Hosts: 218.5.76.71 100yy.com
O1 - Hosts: 218.5.76.71 www.100yy.com
O1 - Hosts: 218.5.76.71 006.net
O1 - Hosts: 218.5.76.71 www.006.net
O1 - Hosts: 218.5.76.71 2t.cn
O1 - Hosts: 218.5.76.71 www.2t.cn
O1 - Hosts: 218.5.76.71 cococ.com
O1 - Hosts: 218.5.76.71 www.cococ.com
O1 - Hosts: 218.5.76.71 ting.cococ.com
O1 - Hosts: 218.5.76.71 yymp3.com
O1 - Hosts: 218.5.76.71 www.yymp3.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 7760.com
O1 - Hosts: 218.5.76.71 www.7760.com
O1 - Hosts: 218.5.76.71 568.com
O1 - Hosts: 218.5.76.71 www.568.com
O1 - Hosts: 218.5.76.71 nowok.net
O1 - Hosts: 218.5.76.71 www.nowok.net
O1 - Hosts: 218.5.76.71 chinamp3.com
O1 - Hosts: 218.5.76.71 www.chinamp3.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 7t7t.com
O1 - Hosts: 218.5.76.71 www.7t7t.com
O1 - Hosts: 218.5.76.71 haoting.com
O1 - Hosts: 218.5.76.71 www.haoting.com
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 st020.com
O1 - Hosts: 218.5.76.71 www.st020.com
O1 - Hosts: 218.5.76.71 music.jschina.com.cn
O1 - Hosts: 218.5.76.71 real2000.org
O1 - Hosts: 218.5.76.71 www.real2000.org
O1 - Hosts: 218.5.76.71 6bb.com
O1 - Hosts: 218.5.76.71 www.6bb.com
O1 - Hosts: 218.5.76.71 5474.com
O1 - Hosts: 218.5.76.71 www.5474.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 ting88.com
O1 - Hosts: 218.5.76.71 www.ting88.com
O1 - Hosts: 218.5.76.71 tt78.com
O1 - Hosts: 218.5.76.71 www.tt78.com
O1 - Hosts: 218.5.76.71 8yh.com
O1 - Hosts: 218.5.76.71 mp3.8yh.com
O1 - Hosts: 218.5.76.71 ibmp3.com
O1 - Hosts: 218.5.76.71 www.ibmp3.com
O1 - Hosts: 218.5.76.71 feifa.com
O1 - Hosts: 218.5.76.71 www.feifa.com
O1 - Hosts: 218.5.76.71 music.feifa.com
O1 - Hosts: 218.5.76.71 91f.net
O1 - Hosts: 218.5.76.71 www.91f.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 ting163.com
O1 - Hosts: 218.5.76.71 www.ting163.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 wo99.com
O1 - Hosts: 218.5.76.71 www.wo99.com
O1 - Hosts: 218.5.76.71 jnnc.com
O1 - Hosts: 218.5.76.71 www.jnnc.com
O1 - Hosts: 218.5.76.71 mtv123.com
O1 - Hosts: 218.5.76.71 www.mtv123.com
O1 - Hosts: 218.5.76.71 dj520.com
O1 - Hosts: 218.5.76.71 www.dj520.com
O1 - Hosts: 218.5.76.71 7xi.net
O1 - Hosts: 218.5.76.71 www.7xi.net
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 mtvtop.net
O1 - Hosts: 218.5.76.71 www.mtvtop.net
O1 - Hosts: 218.5.76.71 mtvtop.com
O1 - Hosts: 218.5.76.71 www.mtvtop.com
O1 - Hosts: 218.5.76.71 xaonline.com
O1 - Hosts: 218.5.76.71 music.xaonline.com
O1 - Hosts: 218.5.76.71 musictea.com
O1 - Hosts: 218.5.76.71 www.musictea.com
O1 - Hosts: 218.5.76.71 tfol.com
O1 - Hosts: 218.5.76.71 www.tfol.com
O1 - Hosts: 218.5.76.71 yyue.com
O1 - Hosts: 218.5.76.71 www.yyue.com
O1 - Hosts: 218.5.76.71 yyue.net
O1 - Hosts: 218.5.76.71 www.yyue.net

AUTORUNS可见注册表中的木马启动加载信息:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
(见图1),就是注册表中看到的"{CF49F9F2-A8D3-464F-83EC-6AFC6573C267}"=""


查杀:

1、用KILLBOX强行删除下列木马文件:

C:\WINDOWS\system32\21313.dll
C:\WINDOWS\system32\Direct17a.bat

2、重建hosts文件(文件内容已经完全被木马冲掉了):
打开记事本,写入:127.0.0.1      localhost
以hosts为名,保存到C:\WINDOWS\system32\drivers\etc目录下。

3、清理注册表:

展开 :HKEY_CLASSES_ROOT\CLSID\
删除:{CF49F9F2-A8D3-464F-83EC-6AFC6573C267}

展开:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

删除:"{CF49F9F2-A8D3-464F-83EC-6AFC6573C267}"=""

附件附件:

下载次数:245
文件类型:image/pjpeg
文件大小:
上传时间:2006-1-14 22:08:30
描述:
预览信息:EXIF信息



最后编辑2006-01-25 17:56:27
分享到:
gototop
 

版主,不知是为什么,我运行rxjh.exe时并没有像你说的那样,生成那几个文件,
我是用SSM监控它运行的,

它运行后首先要更改我的注册表,(更改IE首页~)
接着要求调用  C:\WINDOWS\system32\drwtsn32.exe
连续几次都调用这个drwtsn32.exe  (我点了允许)
最让我不能理解的是,最后在 ssm中看到drwtsn32.exe要求结束rxjh.exe的运行???
我不明白,它调用drwtsn32.exe  是什么意图,还有,drwtsn32.exe是干什么用的,,,

另,这个rxjh.exe至今瑞星都没有报有毒~~~~~?唉~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT