打印

[原创] 病毒分析报告:msport.dll/……/game8.exe

病毒分析报告:msport.dll/……/game8.exe

病毒名称:game8.exe
病毒大小:26,154 字节
加壳方式:Upack 0.3.9 beta2s -> Dwing [Overlay]
脱壳大小:88,064 字节
编写语言:Borland Delphi v3.0 *
病毒预警:3级
病毒指纹:
SHA-160         : 406414F2773FFC68B7E6A072042DD87FB7133904
MD5             : E069C3EF0C41B86AB48D00BE66D097DD
RIPEMD-160      : 4A96D08DFE08B0DF44E7FDC60DA75825CC10AFDF
CRC-32          : C86EC7DA
命名对照:
http://scanner.virus.org/
ArcaVir1.0.4Trojan.Psw.Onlinegames.Tu3.39794 secs
avast!3.0.0Clean0.00478077 secs
AVG Anti Virus7.5.47Clean2.68099 secs
BitDefender7.1Clean4.70251 secs
CAT QuickHeal9.00Clean4.4323 secs
ClamAV0.90/3270Clean0.208995 secs
Dr. Web4.33.0Clean8.75378 secs
F-PROT4.6.7Clean1.62262 secs
F-Secure1.02Clean0.209508 secs
H+BEDV AntiVir2.1.10-40Clean6.05688 secs
McAfee Virusscan5.10.0New Malware.n1.95304 secs
NOD322.51.1Clean3.49587 secs
Norman Virus Control5.70.01W32/Suspicious_U.gen6.74328 secs
Panda9.00.00Clean1.56817 secs
Sophos Sweep4.17.0Mal/Packer5.28013 secs
Trend Micro8.310-1002Clean0.499315 secs
VBA323.12.0Clean2.82012 secs
VirusBuster1.3.3Packed/Upack2.1315 secs

http://www.virustotal.com
AhnLab-V32007.5.16.105.18.2007 no virus found
AntiVir7.4.0.2305.18.2007 no virus found
Authentium4.93.805.18.2007 no virus found
Avast4.7.997.005.18.2007 no virus found
AVG7.5.0.46705.19.2007 no virus found
BitDefender7.205.20.2007 no virus found
CAT-QuickHeal9.0005.18.2007(Suspicious) - DNAScan
ClamAVdevel-2007041605.19.2007 no virus found
DrWeb4.3305.19.2007 no virus found
eSafe7.0.15.005.17.2007suspicious Trojan/Worm
eTrust-Vet30.7.364405.19.2007 no virus found
Ewido4.005.19.2007Trojan.OnLineGames.tu
FileAdvisor105.20.2007 no virus found
Fortinet2.85.0.005.20.2007suspicious
F-Prot4.3.2.4805.18.2007 no virus found
F-Secure6.70.13030.005.18.2007W32/Suspicious_U.gen.dropper
IkarusT3.1.1.705.20.2007Trojan-Dropper.Win32.Agent.ane
Kaspersky4.0.2.2405.20.2007Trojan-PSW.Win32.OnLineGames.tu
McAfee503405.18.2007New Malware.n
Microsoft1.250305.20.2007VirTool:Win32/Obfuscator.C
NOD32v2227705.18.2007 no virus found
Norman5.80.0205.18.2007W32/Suspicious_U.gen
Panda9.0.0.405.19.2007Suspicious file
Prevx1V205.20.2007 no virus found
Sophos4.17.005.18.2007Mal/Packer


Aditional Information
File size: 26154 bytes
MD5: e069c3ef0c41b86ab48d00be66d097dd
SHA1: 406414f2773ffc68b7e6a072042dd87fb7133904
packers: UPACK
packers: UPack

文章作者:[G-AVR]孤单每一天
文章地址:http://hi.baidu.com/renlangliu/blog/item/8cb8094c7c0369f8d72afc2a.html
测试平台:win2000PROSP4+VM
病毒运行后释放msport.dll/fksdy.dll/wgptl.dll/wtrmm.dll/hreax.dll到%systemroot%\system32目录下,调用SetWindowsHookEx函数挂接explorer.exe,使得父进程为explorer.exe启动的的进行全部进行注入,并添加注册表启动项,释放批处理文件删除病毒自身。病毒使用了线程互守,使得单线程无法被结束,rootkit自身的注册表启动项,达到无法找出启动项的目的(有启动项存在,键值为空)
注册表启动项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
        <{1496D5ED-7A09-46D0-8C92-B8E71A4304DF}><C:\WINNT\system32\msacn.dll>
反汇编察看似乎病毒有操作host文件的行为,2000下没有运行成功
.Upack:004030FA                     mov         ecx, offset s_DriversEtcHos ; "drivers\\etc\\hosts"
病毒清除:
使用SC打开explorer.exe进程,选中“禁止线程创建”,全部选择以上的病毒线程,右键点击“全局卸载指定模块”即可清除该病毒,SC请到我的网盘下载,使用教程请参见以前的文章。

TOP

Processed in 0.039942 second(s), 5 queries, Gzip enabled.