病毒.名称:N/A(Kaspersky) ) :Px`] 5
病毒别名:Backdoor.Jusi.i(瑞星) pE0@m-p
病毒大小:216,576 字节 RmOkb~
加壳方式:SVKP ?#nk}=;g8
样本MD5:e17774b70be4427768180286a6889fae ~*~aFf5
样本SHA1:408004ef3de3eb50dd0ebfc3885ed319301e223d [i>D|X
传播方式:恶意网页、其它病毒下载 rTJ;s
"av G#rsH
技术分析 R?}%rP+^e
========== }?O>.W,/
这又是一个版本信息模仿微软的木马,在文件属性的.版本里可以看到如下版本信息: B2WPbox
文件版本:5.2.3790.1830 /R6\_oM
描述:Generic Host Process for Win32 Services .R@XstQ
版权:(C) Microsoft Corporation. All rights reserved. }wJH@'0+
产品.名称:Microsoft(R) Windows(R) Operating System 55,2eg#{O
公司:Microsoft Corporation %/!f^PIwX
木马运行后复制自身到系统目录: wNNg"}&P
%System%NeroCheck.exe 9OlJC[
释放dll注入进程: ?/~Q9My
%System%NeroCheck.dll lACS^(
以及%System%SVKP.sys文件。 kn`O3cW/
使用%temp%delmeexe.bat批处理删除自身: {7 ](-
@echo off g"g3|$#Ej|
:loop whGtVx|zR
del "exe" SK*<H~2
del "%temp%delmeexe.bat" P$@:T[}v
if exist %temp%delmeexe.bat goto loop 字串9 3q6FV7Fv&b
木马创建以下服务: 9c5DEq
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesCiSvrc] Fa{[kJ8z
显示名:Indexing Services EYn9ln_]u
描述:Indexes contents and properties of files on loc.al and remote computers; provides rapid access to files through flexible querying language. z$(`{
o%a
可执行文件的路径:%System%NeroCheck.exe -afNiNiY
清除步骤 q!Z{qt*`um
========== u_o]\D~
1. 删除木马的.服务项: tCu.Fc@
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesCiSvrc] Ty3.u9c4
2. 重新启动计算机 uNqN &7g
3. 删除.木马文件: <^ratz!-
%System%NeroCheck.exe 7$*x&We
%System%NeroCheck.dll zIr-Rx'dL^
%System%SVKP.sys 5)->.* G*