<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.@BAIDU CISRT在百度]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[http://www.cisrt.org/bbs/ http://www.cisrt.org/blog/]]></description>
<link>http://hi.baidu.com/cisrt</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[【CISRT2007100】木马 msvcrt.dll Relive.dll msvcrt.bak 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/c69c3b73cf80851f8701b0ad.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1531"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1531</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007100<br>
<strong>病毒名称</strong>：Virus.Win32.AutoRun.bk（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.Agent.qs（瑞星）<br>
<strong>病毒大小</strong>：23,087 字节<br>
<strong>加壳方式</strong>：PE_Patch.UPX UPX<br>
<strong>样本MD5</strong>：3d4d01638f3e206c7bbbde769a3f2182<br>
<strong>样本SHA1</strong>：8d6d71216a588155554226efe84eed2c8011c38a<br>
<strong>发现时间</strong>：2007.7.10<br>
<strong>更新时间</strong>：2007.7.17<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播，其它木马或病毒下载<br>
<br>
<br>
<strong>技术分析<br>
</strong>==========<br>
<br>
变种：<br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1358" target="_blank"><strong><font color="#810081">【CISRT2007075】木马 romdrivers.dll romdrivers.bak 解决方案</font></strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1486" target="_blank"><strong><font color="#810081">【CISRT2007090】木马 msvcrt.dll Relive.dll msvcrt.bak&nbsp;&nbsp; 解决方案</font></strong></a><br>
<br>
木马运行后复制自身到：<br>
<strong>%ProgramFiles%\Internet Explorer\msvcrt.bak<br>
</strong>释放dll注入Explorer.exe进程：<br>
<strong>%ProgramFiles%\Internet Explorer\msvcrt.dll<br>
</strong>同时还创建msvcrt.dll的副本，作为BHO启动：<br>
<strong>%ProgramFiles%\Common Files\Relive.dll<br>
</strong></p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1531"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1531</strong></a></p>
<strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 删除木马创建的注册表信息：<br>
<br>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1531###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1531###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{0FAD2E16-C8EF-5AC1-1E6A-AE3FD8EF56B3}"<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{0FAD2E16-C8EF-5AC1-1E6A-AE3FD8EF56B3}]<br>
<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3626E66-B13B-C628-ACDF-BDABCFA265E1}]<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{D3626E66-B13B-C628-ACDF-BDABCFA265E1}]</div>
</div>
<br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除木马相关文件：<br>
<strong>%ProgramFiles%\Internet Explorer\msvcrt.bak<br>
%ProgramFiles%\Internet Explorer\msvcrt.dll<br>
%ProgramFiles%\Common Files\Relive.dll</strong><br>
<br>
<strong>4.</strong> 删除反病毒软件安装目录下的ws2_32.dll目录，可以使用rd /s命令，比如：<br>
<br>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1531###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1531###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >rd /s C:\KAV2007\ws2_32.dll<br>
rd /s "C:\Program Files\Rising\Rav\ws2_32.dll"</div>
</div>
<br>
<strong>5.</strong> 创建%System%\drivers\etc\hosts文件：<br>
内容为一行即可：<br>
<br>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1531###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1531###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >127.0.0.1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; localhost</div>
</div>
<br>
<em>发布时间：2007-07-17 10:41<br>
更新时间：2007-07-17 18:10</em>
<p><strong></strong></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1531"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1531</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/c69c3b73cf80851f8701b0ad.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/c69c3b73cf80851f8701b0ad.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:54</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/c69c3b73cf80851f8701b0ad.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007099】木马 Agent.dll gfdwq.bbr adapi32.dll 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/426a88163fa99952f3de32ac.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1527"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1527</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007099<br>
<strong>病毒名称</strong>：Trojan-PSW.Win32.OnLineGames.tn（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.OnlineGames.dfz（瑞星）<br>
　　　　　 Win32.PSWTroj.OnLineGames.tn.86016 [exe]（毒霸）, Win32.Troj.OnlineGames.ny.126976 [dll]（毒霸）<br>
<strong>病毒大小</strong>：27,967 字节<br>
<strong>加壳方式</strong>：UPack<br>
<strong>样本MD5</strong>：d37bea844c36c786fa6136ffd283cf8a<br>
<strong>样本SHA1</strong>：6939b106bb146fb7194c01e9c14ec036672a8565<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.10<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析<br>
</strong>==========<br>
<br>
木马运行后释放dll到系统目录：<br>
<strong>%System%\Agent.dll<br>
</strong>创建副本：<br>
<strong>%System%\gfdwq.bbr<br>
%System%\adapi32.dll<br>
%System%\aetpksw.dll<br>
%System%\hytsx.dll<br>
%System%\wiytd.dll<br>
%System%\wkjhl.dll<br>
%System%\wljhj.dll<br>
%System%\wlkhm.dll<br>
%System%\zeqax.dll<br>
</strong>并将这些dll注入进程。<br>
</p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1527"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1527</strong></a></p>
<strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 重命名木马文件：<br>
<strong>%System%\Agent.dll</strong><br>
<br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除重命名过的木马文件：<br>
<strong>%System%\Agent.dll</strong><br>
<br>
<strong>4.</strong> 删除其它木马副本：<br>
<strong>%System%\gfdwq.bbr<br>
%System%\adapi32.dll<br>
%System%\aetpksw.dll<br>
%System%\hytsx.dll<br>
%System%\wiytd.dll<br>
%System%\wkjhl.dll<br>
%System%\wljhj.dll<br>
%System%\wlkhm.dll<br>
%System%\zeqax.dll</strong><br>
<br>
<strong>5.</strong> 删除ShellExecuteHooks启动项：<br>
<br>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1527###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1527###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{D8E0E3BA-D55F-4A08-8EE4-0A59E0284124}"<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{D8E0E3BA-D55F-4A08-8EE4-0A59E0284124}]</div>
</div>
<br>
<strong>6.</strong> 删除木马创建的注册表信息：<br>
<br>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1527###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1527###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_CURRENT_USER\Windows]</div>
</div>
<br>
<em>发布时间：2007-07-16 17:35</em>
<p><strong></strong></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1527"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1527</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/426a88163fa99952f3de32ac.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/426a88163fa99952f3de32ac.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:53</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/426a88163fa99952f3de32ac.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007098】木马 dhapri.dll 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/b563a61b8d02ce1a8618bfac.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1526"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1526</strong></a></p>
<strong>档案编号</strong>：CISRT2007098<br>
<strong>病毒名称</strong>：Trojan-Downloader.Win32.Small.exh（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.Zhengtu.jzr [exe]（瑞星）, Trojan.PSW.Win32.XYOnline.be [dll]（瑞星）<br>
　　　　　 Win32.TrojDownloader.Small.86016 [exe]（毒霸）, Win32.Troj.DownloaderT.ew.14897 [dll]（毒霸）<br>
<strong>病毒大小</strong>：10,540 字节<br>
<strong>加壳方式</strong>：UPack<br>
<strong>样本MD5</strong>：3979a7b883ac774a09afabb3f0236eb3<br>
<strong>样本SHA1</strong>：418b69bdaba42fbd8a492f286031a8f71ccc55c7<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.12<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析</strong><br>
==========<br>
<br>
变种：<br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1524" target="_blank"><strong><font color="#810081">【CISRT2007096】木马 qhbpri.dll 解决方案</font></strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1525" target="_blank"><strong><font color="#810081">【CISRT2007097】木马 wdapri.dll 解决方案</font></strong></a><br>
<br>
木马运行后释放dll到系统目录：<br>
<strong>%System%\dhapri.dll</strong><br>
<p><strong></strong></p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1526"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1526</strong></a></p>
<p><strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 重命名木马文件：<br>
<strong>%System%\dhapri.dll</strong><br>
<br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除重命名过的木马文件：<br>
<strong>%System%\dhapri.dll</strong><br>
<br>
<strong>4.</strong> 删除ShellExecuteHooks启动项：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1526###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1526###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{12311A42-AC1B-158F-FD32-5674345F23A1}"="dhapri.dll"<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{12311A42-AC1B-158F-FD32-5674345F23A1}]</div>
</div>
<p><br>
<strong>5.</strong> 编辑AppInit_DLLs值数据为空，删除“dhapri.dll”：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1526###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1526###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]<br>
"AppInit_DLLs"=""</div>
</div>
<p><br>
<strong>6.</strong> 删除木马修改的注册表信息：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1526###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1526###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]<br>
"NoAutoUpdate"=dword:00000001<br>
"AUOptions"=dword:00000001<br>
<br>
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]<br>
"EnableFirewall"=dword:00000000</div>
</div>
<p><br>
（或根据自己需要进行设置）<br>
<br>
<br>
<em>发布时间：2007-07-16 17:17<br>
更新时间：2007-07-19 17:28</em></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1526"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1526</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/b563a61b8d02ce1a8618bfac.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/b563a61b8d02ce1a8618bfac.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:52</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/b563a61b8d02ce1a8618bfac.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007097】木马 wdapri.dll 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/6b6085efc89491ecce1b3ea3.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1525"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1525</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007097<br>
<strong>病毒名称</strong>：Trojan-Downloader.Win32.Small.ewc（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.AskTao.y（瑞星）<br>
　　　　　 Win32.Troj.Downloader.ew.65536 [exe]（毒霸）, Win32.Troj.Small.dw.14852 [dll]（毒霸）<br>
<strong>病毒大小</strong>：9,798 字节<br>
<strong>加壳方式</strong>：UPack<br>
<strong>样本MD5</strong>：daea52c1ba806fe8dffa6718aed64ea4<br>
<strong>样本SHA1</strong>：67d61ae2d8d46f9ffa9e73f007038af84245b511<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.12<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析</strong><br>
==========<br>
<br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1524" target="_blank"><strong><font color="#810081">【CISRT2007096】木马 qhbpri.dll 解决方案</font></strong></a>的变种，运行后释放dll到系统目录：<br>
<strong>%System%\wdapri.dll</strong><br>
<br>
创建ShellExecuteHooks启动项：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{1F12545B-1212-1314-5679-4512ACEF8901}"="wdapri.dll"<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{1F12545B-1212-1314-5679-4512ACEF8901}\InprocServer32]<br>
@="%System%\wdapri.dll"</div>
</div>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1525"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1525</strong></a></p>
<p><strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 重命名木马文件：<br>
<strong>%System%\wdapri.dll</strong><br>
<br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除重命名过的木马文件：<br>
<strong>%System%\wdapri.dll</strong><br>
<br>
<strong>4.</strong> 删除ShellExecuteHooks启动项：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{1F12545B-1212-1314-5679-4512ACEF8901}"="wdapri.dll"<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{1F12545B-1212-1314-5679-4512ACEF8901}]</div>
</div>
<p><br>
<strong>5.</strong> 编辑AppInit_DLLs值数据为空，删除“wdapri.dll”：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]<br>
"AppInit_DLLs"=""</div>
</div>
<p><br>
<strong>6.</strong> 删除木马修改的注册表信息：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1525###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]<br>
"NoAutoUpdate"=dword:00000001<br>
"AUOptions"=dword:00000001<br>
<br>
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]<br>
"EnableFirewall"=dword:00000000</div>
</div>
<p><br>
（或根据自己需要进行设置）<br>
<br>
<br>
<em>发布时间：2007-07-16 16:51<br>
更新时间：2007-07-19 17:28</em></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1525"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1525</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/6b6085efc89491ecce1b3ea3.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/6b6085efc89491ecce1b3ea3.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:51</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/6b6085efc89491ecce1b3ea3.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007096】木马 qhbpri.dll 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/211fc8c45a88b7c839db49a2.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1524"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1524</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007096<br>
<strong>病毒名称</strong>：Trojan-Spy.Win32.Delf.uv（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.AskTao.y [exe]（瑞星）, Trojan.PSW.Win32.QQHX.f [dll]（瑞星）<br>
　　　　　 Win32.Troj.Delf.uv.86016 [exe]（毒霸）, Win32.Troj.Delf.uv.14889 [dll]（毒霸）<br>
<strong>病毒大小</strong>：10,065 字节<br>
<strong>加壳方式</strong>：UPack<br>
<strong>样本MD5</strong>：ddc6cd2c893a0d67ab8c4bde5f53a399<br>
<strong>样本SHA1</strong>：0219645ee9338ae6f8bd5e01feca454da540f1dd<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.11<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析</strong><br>
==========<br>
<br>
木马运行后释放dll到系统目录：<br>
<strong>%System%\qhbpri.dll</strong><br>
<br>
创建ShellExecuteHooks启动项：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{26368135-64FA-BC34-DA32-DCF4FD431C92}"="qhbpri.dll"<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{26368135-64FA-BC34-DA32-DCF4FD431C92}\InprocServer32]<br>
@="%System%\qhbpri.dll"</div>
</div>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1524"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1524</strong></a></p>
<p><strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 重命名木马文件：<br>
<strong>%System%\qhbpri.dll</strong><br>
<br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除重命名过的木马文件：<br>
<strong>%System%\qhbpri.dll</strong><br>
<br>
<strong>4.</strong> 删除ShellExecuteHooks启动项：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{26368135-64FA-BC34-DA32-DCF4FD431C92}"="qhbpri.dll"<br>
<br>
[HKEY_CLASSES_ROOT\CLSID\{26368135-64FA-BC34-DA32-DCF4FD431C92}]</div>
</div>
<p><br>
<strong>5.</strong> 编辑AppInit_DLLs值数据为空，删除“qhbpri.dll”：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]<br>
"AppInit_DLLs"=""</div>
</div>
<p><br>
<strong>6.</strong> 删除木马修改的注册表信息：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1524###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]<br>
"NoAutoUpdate"=dword:00000001<br>
"AUOptions"=dword:00000001<br>
<br>
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]<br>
"EnableFirewall"=dword:00000000</div>
</div>
<p><br>
（或根据自己需要进行设置）<br>
<br>
<br>
<em>发布时间：2007-07-16 16:44<br>
更新时间：2007-07-19 17:28</em></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1524"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1524</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/211fc8c45a88b7c839db49a2.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/211fc8c45a88b7c839db49a2.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:50</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/211fc8c45a88b7c839db49a2.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007095】木马 WMIApiSrv.dll 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/99bf23d3586880033af3cfa2.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1523"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1523</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007095<br>
<strong>病毒名称</strong>：Trojan-Proxy.Win32.Small.du（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.OnlineGames.dfy [exe]（瑞星）, Trojan.PSW.Win32.OnlineGames.dhb [dll]（瑞星）<br>
　　　　　 Win32.Troj.Small.du.23552 [exe]（毒霸）, Win32.Troj.AgentT.hl.66048 [dll]（毒霸）<br>
<strong>病毒大小</strong>：26,112 字节<br>
<strong>加壳方式</strong>：<br>
<strong>样本MD5</strong>：e5015a86c2771d46e34e951f4095d85e<br>
<strong>样本SHA1</strong>：bb391492ad21ab9ddb1e5eeb2a992c1b7e672a0d<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.11<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析<br>
</strong>==========<br>
<br>
变种：<br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=614" target="_blank"><strong>【CISRT2006089】木马 windhcp.ocx 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=500" target="_blank"><strong>【CISRT2006069】setvp.exe windhcp.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=654" target="_blank"><strong>【CISRT2007008】木马 xpdhcp.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1219" target="_blank"><strong>【CISRT2007053】木马 windhcp.ocx 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1220" target="_blank"><strong>【CISRT2007054】木马 msdebug.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1221" target="_blank"><strong>【CISRT2007055】木马 RemoteDbg.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1222" target="_blank"><strong>【CISRT2007056】木马 windds32.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1522" target="_blank"><strong><font color="#810081">【CISRT2007094】木马 netsrvcs.dll 解决方案</font></strong></a><br>
<br>
木马运行后释放dll到系统目录：<br>
<strong>%System%\WMIApiSrv.dll<br>
</strong></p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1523"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1523</strong></a></p>
<p><strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 删除服务：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1523###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1523###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMIApiSrv]</div>
</div>
<p><br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除文件：<br>
<strong>%System%\WMIApiSrv.dll</strong><br>
<br>
<br>
<em>发布时间：2007-07-16 16:04</em></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1523"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1523</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/99bf23d3586880033af3cfa2.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/99bf23d3586880033af3cfa2.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:49</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/99bf23d3586880033af3cfa2.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007094】木马 netsrvcs.dll 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/0e734faf805e7df8fbed50a1.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1522"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1522</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007094<br>
<strong>病毒名称</strong>：Trojan-Proxy.Win32.Small.du [exe]（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.OnlineGames.dfy [exe]（瑞星）<br>
　　　　　 Win32.Troj.Small.du.23552 [exe]（毒霸）, Win32.Troj.Agent.22528 [dll]（毒霸）<br>
<strong>病毒大小</strong>：26,112 字节<br>
<strong>加壳方式</strong>：<br>
<strong>样本MD5</strong>：0a9ce30dc9f61d4b6536fd21be047d77<br>
<strong>样本SHA1</strong>：0da9afd0e99b7d99c1e809b1c92dae09e63319e0<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.12<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析<br>
</strong>==========<br>
<br>
变种：<br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=614" target="_blank"><strong>【CISRT2006089】木马 windhcp.ocx 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=500" target="_blank"><strong>【CISRT2006069】setvp.exe windhcp.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=654" target="_blank"><strong>【CISRT2007008】木马 xpdhcp.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1219" target="_blank"><strong>【CISRT2007053】木马 windhcp.ocx 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1220" target="_blank"><strong>【CISRT2007054】木马 msdebug.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1221" target="_blank"><strong>【CISRT2007055】木马 RemoteDbg.dll 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1222" target="_blank"><strong>【CISRT2007056】木马 windds32.dll 解决方案</strong></a><br>
<br>
木马运行后释放dll到系统目录：<br>
<strong>%System%\netsrvcs.dll<br>
</strong></p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1522"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1522</strong></a></p>
<p><strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 删除服务：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1522###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1522###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WZCSRVC]</div>
</div>
<p><br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除文件：<br>
<strong>%System%\netsrvcs.dll</strong><br>
<br>
<br>
<em>发布时间：2007-07-16 15:54</em></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1522"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1522</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/0e734faf805e7df8fbed50a1.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/0e734faf805e7df8fbed50a1.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:48</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/0e734faf805e7df8fbed50a1.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007093】木马 AVPSrv.exe AVPSrv.dll 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/21454c8210e7e6a10cf4d2a1.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1521"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1521</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007093<br>
<strong>病毒名称</strong>：Trojan-PSW.Win32.OnLineGames.abl（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.OnlineGames.dhv [exe]（瑞星）, Trojan.PSW.Win32.OnlineGames.dhu [dll]（瑞星）<br>
　　　　　 Win32.PSWTroj.OnLineGames.YA.49152 [exe]（毒霸）, Win32.PSWTroj.OnLineGames.19968 [dll]（毒霸）<br>
<strong>病毒大小</strong>：15,872 字节<br>
<strong>加壳方式</strong>：PE_Patch.UPX UPX<br>
<strong>样本MD5</strong>：5c6fa1762a3168380c5b4b1078110e16<br>
<strong>样本SHA1</strong>：080fb644e48457124d8576ede2badfb65c611db4<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.12<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析<br>
</strong>==========<br>
<br>
木马运行后将自身复制到：<br>
<strong>%Windows%\AVPSrv.exe<br>
</strong>释放dll注入进程：<br>
<strong>%System%\AVPSrv.dll<br>
</strong></p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1521"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1521</strong></a></p>
<p><strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 删除启动项：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1521###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1521###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>
"AVPSrv"="%Windows%\AVPSrv.exe"</div>
</div>
<p><br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除文件：<br>
<strong>%Windows%\AVPSrv.exe<br>
%System%\AVPSrv.dll</strong><br>
<br>
<br>
<em>发布时间：2007-07-16 15:34</em></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1521"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1521</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/21454c8210e7e6a10cf4d2a1.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/21454c8210e7e6a10cf4d2a1.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:47</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/21454c8210e7e6a10cf4d2a1.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007092】盗Q木马 SysWin64.Sys SysWin64.Jmp 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/07a5a61cc151978887d6b6a1.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1520"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1520</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007092<br>
<strong>病毒名称</strong>：Backdoor.Win32.WinterLove.z（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.QQPass.qmd（瑞星）<br>
<strong>病毒大小</strong>：33,389 字节<br>
<strong>加壳方式</strong>：UPX<br>
<strong>样本MD5</strong>：2f62e3984b452173edbdecdbc7437d77<br>
<strong>样本SHA1</strong>：e7e8e9146813c762ffa296b93ad9487ec1efd350<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.12<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析<br>
</strong>==========<br>
<br>
变种：<br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=242" target="_blank"><strong>【CISRT2006032】盗Q木马 system.jmp system.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=449" target="_blank"><strong>【CISRT2006056】盗Q木马 system.jmp system16.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=506" target="_blank"><strong>【CISRT2006073】盗Q木马 system.jmp system18.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=696" target="_blank"><strong>【CISRT2007020】盗Q木马 system.jmp SystemKb.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1058" target="_blank"><strong>【CISRT2007050】盗Q木马 NewInfo.dll system.2dt 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1429" target="_blank"><strong><font color="#810081">【CISRT2007082】木马 NewInfo.bmt system.2dt 解决方案</font></strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1498" target="_blank"><strong><font color="#810081">【CISRT2007091】木马 System16.ins System16.jup 解决方案</font></strong></a><br>
<br>
盗Q木马，运行后将自身复制到：<br>
<strong>%ProgramFiles%\Internet Explorer\PLUGINS\SysWin64.Jmp<br>
</strong>释放dll注入进程：<br>
<strong>%ProgramFiles%\Internet Explorer\PLUGINS\SysWin64.Sys</strong></p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1520"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1520</strong></a></p>
<p><strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 删除木马创建的ShellExecuteHooks项：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1520###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1520###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_CLASSES_ROOT\CLSID\{40117B96-998D-4D80-8F89-5E9DBD9F3460}]<br>
<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{40117B96-998D-4D80-8F89-5E9DBD9F3460}"</div>
</div>
<p><br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除文件：<br>
<strong>%ProgramFiles%\Internet Explorer\PLUGINS\SysWin64.Jmp<br>
%ProgramFiles%\Internet Explorer\PLUGINS\SysWin64.Sys</strong><br>
<br>
<strong>4.</strong> 删除注册表内容：<br>
<br>
</p>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1520###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1520###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_CURRENT_USER\Software\Tencent\Gm]</div>
</div>
<p><br>
<em>发布时间：2007-07-16 15:29</em></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1520"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1520</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/07a5a61cc151978887d6b6a1.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/07a5a61cc151978887d6b6a1.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:46</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/07a5a61cc151978887d6b6a1.html</guid>
</item>

<item>
        <title><![CDATA[【CISRT2007091】木马 System16.ins System16.jup 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/cisrt/blog/item/1c9e63c618a0f8189d163da0.html]]></link>
        <description><![CDATA[
		
		<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1498"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1498</strong></a></p>
<p><strong>档案编号</strong>：CISRT2007091<br>
<strong>病毒名称</strong>：Trojan-Spy.Win32.Delf.vw [exe]（Kaspersky）<br>
<strong>病毒别名</strong>：Trojan.PSW.Win32.Agent.qa [exe]（瑞星）<br>
<strong>病毒大小</strong>：23,285 字节<br>
<strong>加壳方式</strong>：UPX<br>
<strong>样本MD5</strong>：eb7423cd13b67cf1a9ea24dd2bee541f<br>
<strong>样本SHA1</strong>：a086686d52a147dc63d97eb54911b74eb6e947d0<br>
<strong>发现时间</strong>：2007.7<br>
<strong>更新时间</strong>：2007.7.12<br>
<strong>关联病毒</strong>：<br>
<strong>传播方式</strong>：通过恶意网页传播、其它木马下载<br>
<br>
<br>
<strong>技术分析<br>
</strong>==========<br>
<br>
变种：<br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=242" target="_blank"><strong>【CISRT2006032】盗Q木马 system.jmp system.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=449" target="_blank"><strong>【CISRT2006056】盗Q木马 system.jmp system16.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=506" target="_blank"><strong>【CISRT2006073】盗Q木马 system.jmp system18.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=696" target="_blank"><strong>【CISRT2007020】盗Q木马 system.jmp SystemKb.sys 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1058" target="_blank"><strong>【CISRT2007050】盗Q木马 NewInfo.dll system.2dt 解决方案</strong></a><br>
<a href="http://www.cisrt.org/bbs/viewthread.php?tid=1429" target="_blank"><strong><font color="#810081">【CISRT2007082】木马 NewInfo.bmt system.2dt 解决方案</font></strong></a><br>
<br>
木马运行后将自身复制到：<br>
<strong>%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\System16.jup<br>
</strong>释放dll注入进程：<br>
<strong>%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\System16.ins</strong></p>
<p><strong>完整内容请访问：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1498"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1498</strong></a></p>
<strong>清除步骤<br>
</strong>==========<br>
<br>
<strong>1.</strong> 删除木马创建的ShellExecuteHooks项：<br>
<br>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1498###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1498###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_CLASSES_ROOT\CLSID\{014A26F5-FBAD-4549-9CA1-C38210704BD1}]<br>
<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<br>
"{014A26F5-FBAD-4549-9CA1-C38210704BD1}"</div>
</div>
<br>
<strong>2.</strong> 重新启动计算机<br>
<br>
<strong>3.</strong> 删除文件：<br>
<strong>%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\System16.ins<br>
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\System16.jup</strong><br>
<br>
<strong>4.</strong> 删除注册表内容：<br>
<br>
<div class="msgbody">
<div class="msgheader">
<div class="right"><a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1498###">[Copy to clipboard]</a> <a class="smalltxt" href="http://www.cisrt.org/bbs/viewthread.php?tid=1498###">[ <span >-</span> ]</a></div>
CODE:</div>
<div class="msgborder" >[HKEY_CURRENT_USER\Software\Tencent\Ie]</div>
</div>
<br>
<em>发布时间：2007-07-13 11:30<br>
更新时间：2007-07-13 21:53</em>
<p><strong></strong></p>
<p><strong>原文链接：</strong><a href="http://www.cisrt.org/bbs/viewthread.php?tid=1498"><strong>http://www.cisrt.org/bbs/viewthread.php?tid=1498</strong></a></p> <a href="http://hi.baidu.com/cisrt/blog/item/1c9e63c618a0f8189d163da0.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/cisrt/blog/category/%C1%F7%D0%D0%B2%A1%B6%BE%BD%E2%BE%F6%B7%BD%B0%B8">流行病毒解决方案</a>&nbsp;<a href="http://hi.baidu.com/cisrt/blog/item/1c9e63c618a0f8189d163da0.html#comment">查看评论</a>]]></description>
        <pubDate>2007-09-27  14:45</pubDate>
        <category><![CDATA[流行病毒解决方案]]></category>
        <author><![CDATA[CISRT]]></author>
		<guid>http://hi.baidu.com/cisrt/blog/item/1c9e63c618a0f8189d163da0.html</guid>
</item>


</channel>
</rss>