|
|
病毒行为: 1、恶意程序运行后,会释放以下文件: %System%\usmt\mig_hy.bk 444,416 字节 //恶意程序备份 %System%\wbem\svchost.exe 444,416 字节 2、修改注册表 注册表键: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 注册表值: tcpmg 类型: REG_SZ 值: %System%\wbem\svchost.exe 3、尝试下载以下文件: http://www.coolmelife.com/download/srv.exe http://www.coolmelife.com/download/a.dll http://www.coolmelife.com/download/b.dll http://www.coolmelife.com/download/c.dll http://www.coolmelife.com/download/project2.exe //均未成功 生成以下文件: %Temp%\~I7PRUGI1VAC.BaT 12,891 字节 %Temp%\~V5SFDYCLNTKs.VbS 294 字节 %Temp%\~V5SFDYCLNTKs.ExE 294 字节 4、访问http://www.ip686.com/popwin.js //此脚本指向通过Ms06-046漏洞传播的网页木马,下载恶意程序vip.exe http://219.129.239.191/web.htm http://219.129.239.191/vip2.htm http://219.129.239.191/vip1.htm http://219.129.239.191/vip.exe 12,891 字节 5、生成以下文件: %System%\CA2E57DE.EXE 12,891 字节 %System%\BA4DCF44.DLL 32,768 字节 执行CA2E57DE.EXE -d 并将CA2E57DE.EXE加载为系统服务 [HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Services\71BAD7C5] "Description"="BA4DCF44" "DisplayName"="71BAD7C5" "ImagePath"="C:\\WINDOWS\\System32\\CA2E57DE.EXE -d" "ObjectName"="LocalSystem" 6、下载更新文件http://down.hunll.com/popwin/update.txt 并下载以下恶意程序: http://219.129.239.191/cs/01mh.exe 12,537 字节 http://219.129.239.191/cs/02jh.exe 14,740 字节 http://219.129.239.191/cs/03ms.exe 15,216 字节 http://219.129.239.191/cs/04wl.exe 14,088 字节 http://219.129.239.191/cs/05gj.exe 12,964 字节 http://219.129.239.191/cs/06qj.exe 12,656 字节 http://219.129.239.191/cs/07zx.exe 13,880 字节 http://219.129.239.191/cs/08zt.exe 14,100 字节 http://219.129.239.191/cs/09dh.exe 12,063 字节 http://219.129.239.191/cs/10my.exe 13,772 字节 http://219.129.239.191/cs/11wd.exe 18,432 字节 http://219.129.239.191/cs/12tl.exe 12,944 字节 http://219.129.239.191/cs/13cq.exe 12,892 字节 http://219.129.239.191/cs/14qq.exe 33,397 字节 http://219.129.239.191/cs/15xx.exe 12,760 字节 http://219.129.239.191/cs/16xx.exe 13,280 字节 http://219.129.239.191/cs/17xx.exe 16,536 字节 http://219.129.239.191/cs/18xx.exe 10,784 字节 http://219.129.239.191/cs/19xx.exe 已失效 http://219.129.239.191/cs/20xx.exe 18,432 字节 http://219.129.239.191/cc/my_70084.exe 20,480 字节 http://219.129.239.191/cc/dodolook4120.exe 已失效 http://219.129.239.191/cc/ad_2311.exe 262,524 字节 |