Trojan.Win32.Agent.uc

王朝百科·作者佚名  2010-02-19  
宽屏版  字体: |||超大  

病毒名称: Trojan.Win32.Agent.uc

病毒类型: 木马

文件 MD5: dc3536d9a7f57ec7ee29cdf0256a3608

公开范围: 完全公开

危害等级: 中

文件长度:353,532 字节

感染系统: Windows98以上版本

开发工具: Microsoft Visual C++ 6.0 - 7.0

加壳类型: 未知壳

命名对照: Symentec[无]

Mcafee[无]

病毒描述:

该病毒是一个压缩文件,病毒运行后会打开一个图片,达到欺骗用户的目的,其中含有两个可执行的病毒文件和相关动态链接库。病毒运行后,会将自身相关文件复制到%system32%下,删除注册表项,终止相关服务,使杀毒软件失效,新建Internet服务,终止相关进程,并上网下载文件。

行为分析:

1、该病毒是一个文件,其中含有两个可执行的病毒文件:HLP.exe、SYN.exe。病毒运行后将自身文件复制到%system32%下:

%system32%mypic.jpg

%system32%packet.dll

%system32%wanpacket.dll

%system32%wpcap.dll

%system32%drivers

pf.sys

2、删除注册表项:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

DependOnGroup

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

DependOnService

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

Description

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

DisplayName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

Enum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

Enum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

EnumCount

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

EnumNextInstance

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

ErrorControl

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

FailureActions

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

ImagePath

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

ObjectName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

Parameters

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

ParametersServiceDll

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

Security

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

SecuritySecurity

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

Start

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBITS

Type

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessDependOnGroup

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessDependOnService

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessDescription

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessDisplayName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessEnumCount

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessEnumNextInstance

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessEpochEpoch

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessErrorControl

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessImagePath

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessObjectName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParameters

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall Policy

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyDomainProfile

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyDomainProfile

AuthorizedApplications

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyDomainProfile

AuthorizedApplicationsList

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyDomainProfile

AuthorizedApplicationsList\%windir%system32sessmgr.exe

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyStandardProfile

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyStandardProfile

AuthorizedApplications

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyStandardProfile

AuthorizedApplicationsList

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccess

ParametersFirewall PolicyStandardProfileAuthorizedApplications

List\%windir%system32sessmgr.exe

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewallPolicyStandardProfile

AuthorizedApplicationsListC:Program FilesThunderNetwork

ThunderThunder.exe

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersFirewall PolicyStandardProfile

EnableFirewall

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessParametersServiceDll

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessSetup

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessSetupInterfacesUnfirewalledAtUpdate

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessSetupInterfacesUnfirewalledAtUpdateAll

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessSetupServiceUpgrade

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessStart

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

SharedAccessType

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srservice

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceDependOnGroup

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceDependOnService

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceDescription

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceDisplayName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceEnumCount

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceEnumNextInstance

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceErrorControl

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceImagePath

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceObjectName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceParameters

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceParametersServiceDll

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceSecurity

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceSecuritySecurity

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceStart

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

srserviceType

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvc

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcDependOnService

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcDescription

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcDisplayName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcEnumCount

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcEnumNextInstance

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcErrorControl

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcImagePath

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcObjectName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcParameters

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcParametersServiceDll

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcSecurity

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcSecuritySecurity

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcStart

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wscsvcType

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauserv

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservDescription

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservDisplayName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservEnum

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservEnumCount

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservEnumNextInstance

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservErrorControl

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservImagePath

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservObjectName

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservParameters

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservParametersServiceDll

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservSecurity

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservSecuritySecurity

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservStart

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

wuauservType

3、终止以下服务:

Windows Firewall/Internet Connection Sharing(ICS)

Background Intelligent Transfer Service

System Restore Service

SecurityCenter

Automatic Updates

4、新建注册表项:

HKEY_CURRENT_USERSoftwareMicrosoftWindows

ShellNoRoamMUICache

键值:字串:(原病毒所在路径)= "MyPic"

HKEY_CURRENT_USERSoftwareMicrosoftWindows

ShellNoRoamMUICache

键值:字串:"C:WINDOWSHLP.exe"= "HLP"

HKEY_CURRENT_USERSoftwareMicrosoftWindows

ShellNoRoamMUICache

键值:字串:"C:WINDOWSsystem32shimgvw.dll

"= "Windows 图片和传真查看器"

HKEY_CURRENT_USERSoftwareWinRAR SFX

键值:字串:"C%WINDOWS%"="C:WINDOWS"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"Description "="为 Internet 连接提供基础服务

,如果此服务被停止,多数 Internet 软件将无法正常运行。如果此服务被

禁用,任何依赖它的服务将无法启动。"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"DisplayName"="Internet"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"ImagePath "=""C:Program FilesWindows NT

lsass.exe" ServiceStart"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"ObjectName "="LocalSystem"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"Description"="为 Internet 连接提供基础服务,如果此

服务被停止,多数 Internet 软件将无法正常运行。如果此服务被禁用,

任何依赖它的服务将无法启动。"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"DisplayName"="Internet"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"ImagePath "=""C:Program FilesWindows NT

lsass.exe" ServiceStart"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"ObjectName"= "LocalSystem"

5、新建服务:

HKEY_LOCAL_MATHINSYSTEMCurrentControlSetServicesInternet。

(为 Internet 连接提供基础服务E,如果此服务被停止,多数 Internet 软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动)

6、尝试关闭反病毒进程,如:

kav.exe

kavsvc.exe

Rav.exe

RavMon.exe

……

7、尝试下载:

http://goowy.box.*****static/e6efh1kgde.jpg

http://notidgbwds*****ewebspace.com/not_v1/not_ini_v1.jpg

http://notidgbwd*****rfreewebspace.com/

http://notidgbwdsg.5****.com/not_v1/not_ini_v1.jpg

……

注:% System%是一个可变路径。病毒通过查询操作系统来决定当前System文件夹的位置。Windows2000/NT中默认的安装路径是C:WinntSystem32,windows95/98/me中默认的安装路径是C:WindowsSystem,windowsXP中默认的安装路径是C:WindowsSystem32。

--------------------------------------------------------------------------------

清除方案 :

1、使用安天木马防线可彻底清除此病毒(推荐)。

2、手工清除请按照行为分析删除对应文件,恢复相关系统设置。

(1) 使用安天木马防线“进程管理”关闭病毒进程

(2) 删除病毒文件

%system32%mypic.jpg

packet.dll

wanpacket.dll

wpcap.dll

%system32%driversnpf.sys

(3) 恢复病毒修改的注册表项目,删除病毒添加的注册表项

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012006052220060529

键值:字串:”CachePath”= "%USERPROFILE%Local SettingsHistoryHistory.IE5MSHist012006052220060529”

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012006060120060602

键值:字串:“CachePrefix”= ":2006060120060602: "

HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache

键值:字串:” C:Clean.bat”= "Clean"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache

键值:字串:"C:Documents and Settingscommander桌面MyPic.exe"= "MyPic"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache

键值:字串:"C:WINDOWSHLP.exe"= "HLP"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache

键值:字串:"C:WINDOWSsystem32shimgvw.dll"= "Windows 图片和传真查看器"

HKEY_CURRENT_USERSoftwareWinRAR SFX

键值:字串: "C%WINDOWS%"="C:WINDOWS"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"Description "="为 Internet 连接提供基础服务,如果此服务被停止,多数 Internet 软件将无法正常运行。如果此服务被

用,任何依赖它的服务将无法启动。"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"DisplayName"="Internet"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"ImagePath "=""C:Program FilesWindows NTlsass.exe" ServiceStart"

HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesInternet

键值:字串:"ObjectName "="LocalSystem"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"Description"="为 Internet 连接提供基础服务,如果此服务被停止,多数 Internet 软件将无法正常运行。如果此服务被

用,任何依赖它的服务将无法启动。"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"DisplayName"="Internet"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"ImagePath "=""C:Program FilesWindows NTlsass.exe" ServiceStart"

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesInternet

键值:字串:"ObjectName"= "LocalSystem"

 
免责声明:本文为网络用户发布,其观点仅代表作者个人观点,与本站无关,本站仅提供信息存储服务。文中陈述内容未经本站证实,其真实性、完整性、及时性本站不作任何保证或承诺,请读者仅作参考,并请自行核实相关内容。
 
© 2005- 王朝百科 版权所有