4CD4F692.exe 样本卡巴斯基报:Trojan_PSW.Win32.OnLineGames.mu
4CD4F692.exe运行后,在C:\Program Files\Common Files\Microsoft Shared\MSInfo文件夹释放下列文件:
XXXXXXXX.dll
XXXXXXXX.dat
在C:\WINDOWS\Help文件夹释放XXXXXXXX.chm
在C:\WINDOWS\system32文件夹释放verclsid.exe(先将原来的verclsid.exe改名为verclsid.exe.bak)
注:XXXXXXXX为随机数字
在注册表中添加下列启动项:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
XXXXXXXX.dll(本次感染为:423F27F3.dll )
在HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options分支添加N个劫持项,废掉多个杀软、防火墙以及常用手工杀毒工具软件。
Trojan-PSW.Win32.OnLineGames.mu病毒的手工杀毒流程:
1、将IceSword.exe改名为IS.EXE运行。用IceSword禁止进程创建。
2、结束系统核心进程以外的所有进程。
3、删除下列文件:
C:\Program Files\Common Files\Microsoft Shared\MSInfo文件夹中的:
XXXXXXXX.dll
XXXXXXXX.dat
C:\WINDOWS\Help文件夹中的XXXXXXXX.chm
C:\WINDOWS\system32文件夹中的verclsid.exe
4、展开:HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
删除: XXXXXXXX.dll
5、取消IceSword的“禁止进程创建”。将autoruns.exe改名为autorun.exe运行:www.pcpxp.com 供稿
找到HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
删除:
360rpt.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
360Safe.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
360tray.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
adam.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
AgentSvr.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
AppSvc32.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
autoruns.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
avp.com File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
avp.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
CCenter.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
ccSvcHst.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
FileDsty.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
FTCleanerShell.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
HijackThis.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
IceSword.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
iparmo.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
Iparmor.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
isPwdSvc.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
kabaload.exe File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat
KaScrScn.SCR File not found: C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\423F27F3.dat