SREng日志所见异常项:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<InternetEx><C:\windows\system\1.exe> [N/A]
<wsvs><C:\windows\wsvs.exe> [N/A]
<upxdnd><C:\DOCUME~1\baohelin\LOCALS~1\Temp\upxdnd.exe> [N/A]
<cmdbcs><C:\windows\cmdbcs.exe> [N/A]
<mppds><C:\windows\mppds.exe> [N/A]
<msccrt><C:\windows\msccrt.exe> [N/A]
<wsttrs><C:\windows\wsttrs.exe> [N/A]
<Internet><C:\windows\system\svchost.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<internet><C:\windows\system\taskmgr.exe /scan> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><684745M.BMP> [N/A]
==================================
浏览器加载项
[Flash 7]
{492B8F66-B8CF-4F7A-B0EE-B7383B92F5BA} <C:\WINDOWS\system\IceHBO.dll, N/A>
==================================
被病毒插入的进程
[PID: 1388][C:\windows\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 1860][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 1852][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 2156][C:\Program Files\Opera\Opera.exe] [Opera Software, 7561]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 2972][C:\windows\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 2848][C:\Program Files\Tiny Firewall Pro\amon.exe] [Computer Associates International, Inc., 6.5.3.2]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 2556][C:\windows\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 532][C:\SREng\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\windows\684745M.BMP] [N/A, N/A]
[C:\windows\system\C.dll] [N/A, N/A]
病毒进程:
[PID: 616][C:\windows\system\internat.exe] [N/A, N/A]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 3880][C:\windows\system\1.exe] [N/A, N/A]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 2220][C:\windows\system\svchost.exe] [N/A, N/A]
[C:\windows\684745M.BMP] [N/A, N/A]
[C:\windows\system\C.dll] [N/A, N/A]
[PID: 3288][C:\windows\system\taskmgr.exe] [N/A, N/A]
[C:\windows\684745M.BMP] [N/A, N/A]
[C:\windows\system\C.dll] [N/A, N/A]
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\打开(&O)\command=setup.exe
[D:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\打开(&O)\command=setup.exe
结束病毒进程后,需要删除的病毒文件(见附图)。
至于被病毒感染的.exe文件,请用杀软清除其中的病毒代码。瑞星19.09.42已可查杀此毒。
我的实战结果显示:用SSM,可以制服这个蠕虫(不会发生“再次感染”)。即使那些被感染的.exe一时无法处理(须等待杀软升级处理),只要将SSM设置妥当,且用SSM将病毒的.exe程序归入bolcked组,那些被此毒感染过的.exe就运行不了。