Win32.Hack.NetDoor.s
Win32.Hack.NetDoor.s
病毒别名: 处理时间:2006-05-24 威胁级别:★
中文名称: 病毒类型:黑客程序 影响系统:Win 9x/ME,Win 2000/NT,Win XP,Win 2003
病毒行为:
这是一个黑客后门病毒。该病毒的主要危害是在用户主机留下后门,供黑客的远程连接控制,并下载其它病毒感染计算机。该病毒为图片图标,发作时会真的打开一个图片来迷惑用户,而在后台进行感染用户主机。该病毒还会结束大量杀软进程,降低系统的安全等级。
1,生成文件
%widndows%SYN.exe
%system%drivers
pf.sys
%system%MyPic.jpg
%system%Packet.dll
%system%WanPacket.dll
%system%wpcap.dll
%widndows%HLP.exe
C:Program FilesWindows NTsvchost.exe
C:Program FilesWindows NTlsass.exe
C:Program FilesWindows NTICWUT.DLL
2,添加启动项
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet
"ImagePath" = ""C:Program FilesWindows NTlsass.exe" ServiceStart"
3,设置下列项的注册表值
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
HKLMSOFTWAREMicrosoftInternet ExplorerActiveX Compatibility
"Compatibility Flags" = 0x400
4,删除下列杀软启动项
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
SKYNET Personal FireWall
RavTask
RavMon
RavTimer
RfwMain
URLLSTCK.exe
ccApp
KAVPersonal50
Kavrun
KavPFW
KavStart
iDuba Personal FireWall
KVFW
KvXP
KvMonXP
5,删除下列服务
SYSTEMCurrentControlSetServicesRsCCenter
SYSTEMCurrentControlSetServicesRsRavMon
SYSTEMCurrentControlSetServicesRfwProxySrv
SYSTEMCurrentControlSetServicesRfwService
SYSTEMCurrentControlSetServicesSymantec Core LC
SYSTEMCurrentControlSetServicesSPBBCSvc
SYSTEMCurrentControlSetServicesSNDSrvc
SYSTEMCurrentControlSetServicesSAVScan
SYSTEMCurrentControlSetServicesNSCService
SYSTEMCurrentControlSetServices
avapsvc
SYSTEMCurrentControlSetServicescomHost
SYSTEMCurrentControlSetServicesccSetMgr
SYSTEMCurrentControlSetServicesccProxy
SYSTEMCurrentControlSetServicesccISPwdSvc
SYSTEMCurrentControlSetServicesccEvtMgr
SYSTEMCurrentControlSetServiceskavsvc
SYSTEMCurrentControlSetServicesKWatchSvc
SYSTEMCurrentControlSetServicesKPfwSvc
SYSTEMCurrentControlSetServicesIDriverT
SYSTEMCurrentControlSetServicesKVWSC
SYSTEMCurrentControlSetServicesKVSrvXP
SYSTEMCurrentControlSetServicessrservice
SYSTEMCurrentControlSetServicesBITS
SYSTEMCurrentControlSetServiceswuauserv
SYSTEMCurrentControlSetServicesSharedAccess
SYSTEMCurrentControlSetServiceswscsvc
6,结束下列进程
UpdateAssist.exe
PFWLiveUpdate.exe
PFW.exe
RavQuick.exe
RavCopy.exe
RavUSB.exe
rfwcfg.exe
RavHDBak.exe
ScanBD.exe
MakeBoot.exe
RegClean.exe
RavStore.exe
SmartUp.exe
RsConfig.exe
RsAgent.exe
Rav.exe
RegGuide.exe
RavTask.exe
RavTimer.exe
RavStub.exe
rfwmain.exe
RavMon.exe
rfwproxy.exe
CCenter.exe
RavMonD.exe
rfwsrv.exe
LUCOMS~1.EXE
LUALL.EXE
NMain.exe
ccApp.exe
SPBBCSvc.exe
ccSetMgr.exe
ccProxy.exe
SNDSrvc.exe
ccEvtMgr.exe
symlcsvc.exe
navapsvc.exe
ccPwdSvc.exe
SAVScan.exe
NSCSRVCE.EXE
comHost.exe
kav.exe
kavsvc.exe
KAVLog2.EXE
Rescue.EXE
KRecycle.EXE
Update.EXE
KSAMain.EXE
KATMain.EXE
KASMain.EXE
KAVPFW.EXE
KAV32.EXE
KMailMon.EXE
KPFW32.EXE
KAVStart.EXE
KWatch.EXE
KPFWSvc.EXE
VirusBox.kxp
kvupload.exe
KVStub.kxp
KVScan.kxp
KvReport.kxp
KVLSUI.kxp
KVHiStory.kxp
kvdisk.kxp
KvDetect.exe
KVOL.exe
KVCenter.kxp
KRegEx.exe
kvinit.exe
kvfw.exe
KvXP.kxp
TrojDie.kxp
KvMailMag.kxp
KVMonXP.kxp
UIHost.exe
IDriverT.exe
kvwsc.exe
KVSrvXP.exe
agentsvr.exe
Symantec Core LC
SPBBCSvc
SNDSrvc
SAVScan
NSCService
navapsvc
comHost
ccSetMgr
ccProxy
ccISPwdSvc
ccEvtMgr
kavsvc
KWatchSvc
KPfwSvc
IDriverT
KVWSC
KVSrvXP
srservice
BITS
wuauserv
SharedAccess
wscsvc
8,其它
%system%drivers
pf.sys、%system%Packet.dll、%system%WanPacket.dll、%system%wpcap.dll为一组网络工具程序,非病毒,用户可以自己删除。