就在我上传完这篇博客后,噩梦又降临了。世界并没有安静。我认为我可以绕过弯路走捷径,可问题是你自己定义的捷径有时候不能真正通往目的地。真正的战斗刚刚开始。
为了让更多的人走更少的弯路,我把杀毒方法说一下。
病毒名称:mplay(先这么叫,没发现正式命名,声明这可不是那个万能播放软件。)我中的版本是winsys16_070104.dll。这应该是最新的版本,即2007年1月4日新变种。以前的是winsys16_061209.dll。
发作表面症状:
1、 开机即自动弹出各种各样的网页窗口包括网上商城、色情网站、网络游戏等,占用大量系统资源,根本来不及关闭,电脑就会因资源耗尽而死机。
2、 在c:\windows\system32下生成大量木马文件,如果有杀毒软件的话,这时杀毒软件会不断报警。
3、 用冰刃监视线程,会发现cmd窗口自动后台运行;负责网络端口请求的Svchost占用大量cpu和内存资源,无数的木马exe执行文件后台运行,时间一长网络因堵塞就会中断。
4、 只格式化系统盘而不格其他盘,那么重装系统后会很快再中毒。
病毒工作原理:
1、中毒后,病毒原来在d盘生成一个mplay.com或mplay.pif的隐藏文件,它伪装成系统文件,无法被发现和删除。这就是为什么重装系统不起作用。
2、病毒每发作一次就在c盘根目录中生成mydelm.bat批处理命令。
3.在windows\下改写winsys.ini 并生成hosts.dat文件,删掉会立即再生成。
4.在windows\system32\drivers\etc\下改写hosts文件,关联大批垃圾网站,崩出的窗口都是这儿定义的。
5、根源就是篡改注册表,我以前的注册表知识已经不能与时俱进了,这会儿才发现这两个根键下也能生成随机启动文件,而且更隐蔽。
在HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ 将Userinit由原来的userinit.exe,改成userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_070104.dll start
在HKLM\SOFTWARE\Microsoft\Command Processor\创建"AutoRun"="d:\mplay.com"
此目的是达到运行.bat文件时运行这个病毒,这就是cmd总是在后台运行的原因。
查杀方法:mcafee8.0iwith11patch’4931病毒库无法查杀这个病毒。网上其他的什么恶意软件清理工具包括奇虎360之类的统统白搭,只能通过手动和杀毒软件相结合方式杀毒。
1、 最好重启到安全模式,(开机按F8)。
2、 打开我的电脑\工具\文件夹选项\查看,把隐藏受保护的系统文件(推荐)前面的勾划掉。选中显示所有文件和文件夹。这时回到D盘,你会发现有一个myplay.com的隐藏文件,删除!!
3、 到c盘根目录下,删除mydelm.bat文件,删除windows\system32\drivers\etc\下的hosts文件
4在“运行”中输入regedit进入注册表,修改注册表HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit 为userinit.exe,
删除HKLM\SOFTWARE\Microsoft\Command Processor\AutoRun
如果没有autorun项,则点开“默认”主键,把内容删除。
在注册表中按F3搜索所有mplay.com,将搜所到的结果删除。
5、立即重启,再回到安全模式,用杀毒软件清理病毒释放的木马文件。
6、用hijackthis1.99版扫描系统,看看有无异常,没有的话就大功告成了。
附:我机子中毒后hijackthis的扫描结果,仅供参考。
Logfile of HijackThis v1.99.1
Scan saved at 18:25:06, on 2007-1-6
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
c:\windows\system32\wbem\lsass.exe
C:\Program Files\Freesoft\tools\PrcView.exe
C:\Program Files\Freesoft\恶意软件清理助手\恶意软件清理助手.exe
E:\Program Files\Maxthon\Maxthon.exe
C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.219\HijackThis.exe
O1 - Hosts: 202.109.114.142 survey88.allyes.com
O1 - Hosts: 202.109.114.142 adtaobao.allyes.com
O1 - Hosts: 202.109.114.142 smarttaobao.allyes.com
O1 - Hosts: 202.109.114.142 code.qihoo.com
O1 - Hosts: 202.109.114.142 union.mop.com
O1 - Hosts: 202.109.114.142 js.kkunion.com
O1 - Hosts: 202.109.114.142 v.kkunion.com
O1 - Hosts: 202.109.114.142 v.21cn.com
O1 - Hosts: 202.109.114.142 iplusms.allyes.com
O1 - Hosts: 202.109.114.142 mms.t2t2.com
O1 - Hosts: 202.109.114.142 ivr.dobig.net
O1 - Hosts: 202.109.114.142 www.u8u.com
O1 - Hosts: 202.109.114.142 u.u8u.com
O1 - Hosts: 202.109.114.142 img.zhangxiu.com
O1 - Hosts: 202.109.114.142 tl.linktone.com
O1 - Hosts: 202.109.114.142 channel.e78.com
O1 - Hosts: 202.109.114.142 u.7town.com
O1 - Hosts: 202.109.114.142 union.95ol.com.cn
O1 - Hosts: 202.109.114.142 mms1.95ol.com.cn
O1 - Hosts: 202.109.114.142 mfs.95ol.com.cn
O1 - Hosts: 202.109.114.142 tl.a8.com
O1 - Hosts: 202.109.114.142 ad01.a8.com
O1 - Hosts: 202.109.114.142 u2.caiku.com
O1 - Hosts: 202.109.114.142 mms.caiku.com
O1 - Hosts: 202.109.114.142 code1.caiku.com
O1 - Hosts: 202.109.114.142 pub.lele.com
O1 - Hosts: 202.109.114.142 u.lele.com
O1 - Hosts: 202.109.114.142 7town.com
O1 - Hosts: 202.109.114.142 tvsend.7town.com
O1 - Hosts: 202.109.114.142 ivrsend.7town.com
O1 - Hosts: 202.109.114.142 tlt.7town.com
O1 - Hosts: 202.109.114.142 gsend.7town.com
O1 - Hosts: 202.109.114.142 smssend.7town.com
O1 - Hosts: 202.109.114.142 mmssend.moyu.com
O1 - Hosts: 202.109.114.142 91ivr.com
O1 - Hosts: 202.109.114.142 myad.91ivr.com
O1 - Hosts: 202.109.114.142 u.91ivr.com
O1 - Hosts: 202.109.114.142 union.91ivr.com
O1 - Hosts: 203.191.146.205 corep.dmcast.com
O1 - Hosts: 203.191.146.205 m081.dmcast.com
O1 - Hosts: 203.191.146.205 dcww.dmcast.com
O1 - Hosts: 203.191.146.205 renren.dmcast.com
O1 - Hosts: 203.191.146.205 files.henbang.net
O1 - Hosts: 203.191.146.205 bannerbox.cn
O1 - Hosts: 203.191.146.205 www.bannerbox.cn
O1 - Hosts: 203.191.146.205 action.coopen.cn
O1 - Hosts: 203.191.146.205 u4.sky99.cn
O1 - Hosts: 203.191.146.205 u1.sky99.cn
O1 - Hosts: 203.191.146.205 u2.sky99.cn
O1 - Hosts: 203.191.146.205 u3.sky99.cn
O1 - Hosts: 203.191.146.205 sky99.cn
O1 - Hosts: 203.191.146.205 u.sky99.cn
O1 - Hosts: 203.191.146.205 u.ete.cn
O1 - Hosts: 203.191.146.205 ip.alexaanywhere.com
O1 - Hosts: 203.191.146.205 www.365tan.com
O1 - Hosts: 203.191.146.205 www.winopen.cn
O1 - Hosts: 203.191.146.205 www.tanip.com
O1 - Hosts: 203.191.146.205 alexaanywhere.com
O1 - Hosts: 203.191.146.205 jssb.alexaanywhere.com
O1 - Hosts: 203.191.146.205 ns250.alexaanywhere.com
O1 - Hosts: 203.191.146.205 sb.alexaanywhere.com
O1 - Hosts: 203.191.146.205 ip.alexaanywhere.com
O1 - Hosts: 203.191.146.205 pop.9v.cn
O1 - Hosts: 203.191.146.205 xuni.myad.cn
O1 - Hosts: 203.191.146.205 iebar.t2t2.com
O1 - Hosts: 203.191.146.205 error.newcell.cn
O1 - Hosts: 203.191.146.205 auto.search.msn.com
O1 - Hosts: 203.191.146.205 cns.3721.com
O1 - Hosts: 203.191.146.205 seek.3721.com
O1 - Hosts: 203.191.146.205 name.cnnic.cn
O1 - Hosts: 203.191.146.205 toolsbar.kuaiso.com
O1 - Hosts: 203.191.146.205 www.kuaiso.com
O1 - Hosts: 203.191.146.205 kuaiso.com
O1 - Hosts: 203.191.146.205 www.copyso.com
O1 - Hosts: 203.191.146.205 union.copyso.com
O1 - Hosts: 203.191.146.205 auto.search.msn.com
O1 - Hosts: 203.191.146.205 ok.mop-hz.com
O1 - Hosts: 203.191.146.205 www.ncast.cn
O1 - Hosts: 203.191.146.205 www.ads3721.com
O1 - Hosts: 203.191.146.205 360.ads3721.com
O1 - Hosts: 203.191.146.205 www.maohehe.com
O1 - Hosts: 203.191.146.205 www.5566.net
O1 - Hosts: 203.191.146.205 5566.net
O1 - Hosts: 203.191.146.205 www.gjj.cc
O1 - Hosts: 203.191.146.205 gjj.cc
O1 - Hosts: 203.191.146.205 www.9495.com
O1 - Hosts: 203.191.146.205 9495.com
O1 - Hosts: 203.191.146.205 my123.com
O1 - Hosts: 203.191.146.205 www.my123.com
O1 - Hosts: 203.191.146.205 7b.com.cn
O1 - Hosts: 203.191.146.205 www.7b.com.cn
O1 - Hosts: 203.191.146.205 www.3567.com
O1 - Hosts: 203.191.146.205 3567.com
O1 - Hosts: 203.191.146.205 www.37021.com
O1 - Hosts: 203.191.146.205 37021.com
O1 - Hosts: 203.191.146.205 www.haourl.com
O1 - Hosts: 203.191.146.205 haourl.com
O1 - Hosts: 203.191.146.205 www.37021.net
O1 - Hosts: 203.191.146.205 37021.net
O1 - Hosts: 203.191.146.205 www.4199.com
O1 - Hosts: 203.191.146.205 4199.com
O2 - BHO: AdPopup - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} - C:\Program Files\Common Files\CPUSH\cpush0.dll
O2 - BHO: (no name) - {1F48640D-67C5-435F-9605-DD6135891AAC} - C:\WINDOWS\system32\pkpikmjgztkhshx.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O2 - BHO: IEHlprObj Class - {DE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\POPNTS.DLL
O2 - BHO: cnwin Class - {EC497BD8-460F-44F0-B2A4-8C2B2198035B} - C:\WINDOWS\system32\cnwin.dll
O2 - BHO: SrchHook Class - {F08555B0-9CC3-11D2-AA8E-000000000000} - C:\WINDOWS\system32\IEBHO.dll (file missing)
O2 - BHO: xgqn - {F4E0D95C-4ED4-404D-8FA1-CF76FDD56681} - C:\PROGRA~1\gpww\ktax.dll
O3 - Toolbar: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll
O3 - Toolbar: JuJu吧 - {B0CFAB31-D992-420E-85A0-F29BF0EC5A47} - C:\WINDOWS\system32\IETool.dll (file missing)
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: 时尚精品,体验快感 - {6E5EECAF-8879-4a75-8A88-B44B6382A763} - http://adfarm.mediaplex.com/ad/ck/4080-22910-9640-290?cn=chaoyue;jujusoft;hp&mpro=http://www.ebay.com.cn (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: 易趣购物 - {6E5EECAF-8879-4a75-8A88-B44B6382A763} - http://adfarm.mediaplex.com/ad/ck/4080-22910-9640-290?cn=chaoyue;jujusoft;hp&mpro=http://www.ebay.com.cn (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://qwh.9126.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{2CA4162C-2028-4DF2-B571-49E056C73A72}: NameServer = 202.102.134.68 202.102.152.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{58EBE41B-D783-46DC-BF4A-B91066AEAF32}: NameServer = 202.102.134.68 202.102.152.3
O20 - Winlogon Notify: ScCardLogn - C:\WINDOWS\ScNotify.dll
O23 - Service: fan.eeewl.com - Unknown owner - C:\WINDOWS\system32\nsvce32.exe
O23 - Service: McAfee Framework 服务 (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe