|
病毒行为:
1、恶意程序运行后,会释放以下文件:
%System%\usmt\mig_hy.bk 444,416 字节 //恶意程序备份
%System%\wbem\svchost.exe 444,416 字节
2、修改注册表
注册表键: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
注册表值: tcpmg
类型: REG_SZ
值: %System%\wbem\svchost.exe
3、尝试下载以下文件:
http://www.coolmelife.com/download/srv.exe
http://www.coolmelife.com/download/a.dll
http://www.coolmelife.com/download/b.dll
http://www.coolmelife.com/download/c.dll
http://www.coolmelife.com/download/project2.exe
//均未成功
生成以下文件:
%Temp%\~I7PRUGI1VAC.BaT 12,891 字节
%Temp%\~V5SFDYCLNTKs.VbS 294 字节
%Temp%\~V5SFDYCLNTKs.ExE 294 字节
4、访问http://www.ip686.com/popwin.js
//此脚本指向通过Ms06-046漏洞传播的网页木马,下载恶意程序vip.exe
http://219.129.239.191/web.htm
http://219.129.239.191/vip2.htm
http://219.129.239.191/vip1.htm
http://219.129.239.191/vip.exe 12,891 字节
5、生成以下文件:
%System%\CA2E57DE.EXE 12,891 字节
%System%\BA4DCF44.DLL 32,768 字节
执行CA2E57DE.EXE -d
并将CA2E57DE.EXE加载为系统服务
[HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Services\71BAD7C5]
"Description"="BA4DCF44"
"DisplayName"="71BAD7C5"
"ImagePath"="C:\\WINDOWS\\System32\\CA2E57DE.EXE -d"
"ObjectName"="LocalSystem"
6、下载更新文件http://down.hunll.com/popwin/update.txt
并下载以下恶意程序:
http://219.129.239.191/cs/01mh.exe 12,537 字节
http://219.129.239.191/cs/02jh.exe 14,740 字节
http://219.129.239.191/cs/03ms.exe 15,216 字节
http://219.129.239.191/cs/04wl.exe 14,088 字节
http://219.129.239.191/cs/05gj.exe 12,964 字节
http://219.129.239.191/cs/06qj.exe 12,656 字节
http://219.129.239.191/cs/07zx.exe 13,880 字节
http://219.129.239.191/cs/08zt.exe 14,100 字节
http://219.129.239.191/cs/09dh.exe 12,063 字节
http://219.129.239.191/cs/10my.exe 13,772 字节
http://219.129.239.191/cs/11wd.exe 18,432 字节
http://219.129.239.191/cs/12tl.exe 12,944 字节
http://219.129.239.191/cs/13cq.exe 12,892 字节
http://219.129.239.191/cs/14qq.exe 33,397 字节
http://219.129.239.191/cs/15xx.exe 12,760 字节
http://219.129.239.191/cs/16xx.exe 13,280 字节
http://219.129.239.191/cs/17xx.exe 16,536 字节
http://219.129.239.191/cs/18xx.exe 10,784 字节
http://219.129.239.191/cs/19xx.exe 已失效
http://219.129.239.191/cs/20xx.exe 18,432 字节
http://219.129.239.191/cc/my_70084.exe 20,480 字节
http://219.129.239.191/cc/dodolook4120.exe 已失效
http://219.129.239.191/cc/ad_2311.exe 262,524 字节
|