debug,exe还连网读取下载列表hxxp://1ni8sami.cn/9/jx.txt下载木马病毒30个
木马植入完毕后.sreng日志可疑项目如下:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><xpsbos.dll offscrl.dll lenowos.dll jolinos.dll cmonos.dll dickus.dll cxhole.dll therbrek.dll manleu.dll jacknove.dll wdhotem.dll crtnumo.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{021F087F-4378-545F-74FA-37D345AD7A8C}><C:\WINDOWS\system32\mttwfh.dll> []
<{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}><C:\WINDOWS\system32\oohxdbyt.dll> []
<{EB71E0B3-E97D-4D30-8733-E28266467617}><C:\WINDOWS\system32\wyhesm.dll> []
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll> []
<{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll> []
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> []
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll> []
<{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}><C:\WINDOWS\system32\fmcvxy.dll> []
<{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}><C:\WINDOWS\system32\fsrgeb.dll> []
<{53D44DB6-E22B-4B17-97D3-572C96CCA6E1}><C:\WINDOWS\system32\zsdgff.dll> []
<{006CA8A1-61BC-4774-A54C-F49034270BAD}><C:\WINDOWS\system32\zgtwfx.dll> []
<{0B846B26-BFE6-4E8E-A948-1DB17B77B483}><C:\WINDOWS\system32\tdfhex.dll> []
<{28766E1C-74B0-4417-8C75-F12AE309EF35}><C:\WINDOWS\system32\wzcfsw.dll> []
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> []
<{50A8A8C4-EDC9-4ABD-A0A2-2E2418982189}><C:\WINDOWS\system32\kgfghd.dll> []
正在运行的进程
[PID: 1244 / enao][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mttwfh.dll] [N/A, ]
[C:\WINDOWS\system32\oohxdbyt.dll] [N/A, ]
[C:\WINDOWS\system32\wyhesm.dll] [N/A, ]
[C:\WINDOWS\system32\ddserh.dll] [N/A, ]
[C:\WINDOWS\system32\rfdswc.dll] [N/A, ]
[C:\WINDOWS\system32\jfrwdh.dll] [N/A, ]
[C:\WINDOWS\system32\sgdewg.dll] [N/A, ]
[C:\WINDOWS\system32\fmcvxy.dll] [N/A, ]
[C:\WINDOWS\system32\fsrgeb.dll] [N/A, ]
[C:\WINDOWS\system32\zsdgff.dll] [N/A, ]
[C:\WINDOWS\system32\zgtwfx.dll] [N/A, ]
[C:\WINDOWS\system32\tdfhex.dll] [N/A, ]
[C:\WINDOWS\system32\wzcfsw.dll] [N/A, ]
[C:\WINDOWS\system32\wrqszl.dll] [N/A, ]
[C:\WINDOWS\system32\kgfghd.dll] [N/A, ]
[PID: 352 / enao][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rfdswc.dll] [N/A, ]
[C:\WINDOWS\system32\ddserh.dll] [N/A, ]
[C:\WINDOWS\system32\wyhesm.dll] [N/A, ]
[C:\WINDOWS\system32\kgfghd.dll] [N/A, ]
[C:\WINDOWS\system32\wzcfsw.dll] [N/A, ]
[C:\WINDOWS\system32\wrqszl.dll] [N/A, ]
[C:\WINDOWS\system32\tdfhex.dll] [N/A, ]
[C:\WINDOWS\system32\zgtwfx.dll] [N/A, ]
[C:\WINDOWS\system32\zsdgff.dll] [N/A, ]
[C:\WINDOWS\system32\fsrgeb.dll] [N/A, ]
[C:\WINDOWS\system32\mttwfh.dll] [N/A, ]
[C:\WINDOWS\system32\fmcvxy.dll] [N/A, ]
[C:\WINDOWS\system32\sgdewg.dll] [N/A, ]
[C:\WINDOWS\system32\jfrwdh.dll] [N/A, ]
[PID: 868 / enao][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jfrwdh.dll] [N/A, ]
[C:\WINDOWS\system32\rfdswc.dll] [N/A, ]
[C:\WINDOWS\system32\ddserh.dll] [N/A, ]
[C:\WINDOWS\system32\wyhesm.dll] [N/A, ]
[C:\WINDOWS\system32\kgfghd.dll] [N/A, ]
[C:\WINDOWS\system32\wzcfsw.dll] [N/A, ]
[C:\WINDOWS\system32\wrqszl.dll] [N/A, ]
[C:\WINDOWS\system32\tdfhex.dll] [N/A, ]
[C:\WINDOWS\system32\zgtwfx.dll] [N/A, ]
[C:\WINDOWS\system32\zsdgff.dll] [N/A, ]
[C:\WINDOWS\system32\fsrgeb.dll] [N/A, ]
[C:\WINDOWS\system32\mttwfh.dll] [N/A, ]
[C:\WINDOWS\system32\fmcvxy.dll] [N/A, ]
[C:\WINDOWS\system32\sgdewg.dll] [N/A, ]
[PID: 440 / enao][E:\tool\sreng2\SRE2ff54df.EXE] [Smallfrogs Studio, 2.6.12.1018]
[C:\WINDOWS\system32\kgfghd.dll] [N/A, ]
[C:\WINDOWS\system32\wzcfsw.dll] [N/A, ]
[C:\WINDOWS\system32\wrqszl.dll] [N/A, ]
[C:\WINDOWS\system32\tdfhex.dll] [N/A, ]
[C:\WINDOWS\system32\zgtwfx.dll] [N/A, ]
[C:\WINDOWS\system32\zsdgff.dll] [N/A, ]
[C:\WINDOWS\system32\fsrgeb.dll] [N/A, ]
[C:\WINDOWS\system32\mttwfh.dll] [N/A, ]
[C:\WINDOWS\system32\fmcvxy.dll] [N/A, ]
[C:\WINDOWS\system32\sgdewg.dll] [N/A, ]
[C:\WINDOWS\system32\jfrwdh.dll] [N/A, ]
[C:\WINDOWS\system32\rfdswc.dll] [N/A, ]
[C:\WINDOWS\system32\ddserh.dll] [N/A, ]
[C:\WINDOWS\system32\wyhesm.dll] [N/A, ]
清除方法C:\WINDOWS\system32\kgfghd.dll
C:\WINDOWS\system32\wzcfsw.dll
C:\WINDOWS\system32\wrqszl.dll
C:\WINDOWS\system32\tdfhex.dll
C:\WINDOWS\system32\zgtwfx.dll
C:\WINDOWS\system32\zsdgff.dll
C:\WINDOWS\system32\fsrgeb.dll
C:\WINDOWS\system32\mttwfh.dll
C:\WINDOWS\system32\fmcvxy.dll
C:\WINDOWS\system32\sgdewg.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\rfdswc.dll
C:\WINDOWS\system32\ddserh.dll
C:\WINDOWS\system32\wyhesm.dll
C:\WINDOWS\system32\oohxdbyt.dll
上面文件用XDelBox一次性删除
(enao.ys168.com 下载)
复制上面所有要删除的文件,打开XDelBox,在待删除列表点 右键==>选择 剪贴版导入不检查路径==>点 右键==>选择==>立刻重启执行删除
编辑<AppInit_DLLs>内容为空 即删除<xpsbos.dll offscrl.dll lenowos.dll jolinos.dll cmonos.dll dickus.dll cxhole.dll therbrek.dll manleu.dll jacknove.dll wdhotem.dll crtnumo.dll>
删除注册表项目
<{021F087F-4378-545F-74FA-37D345AD7A8C}><C:\WINDOWS\system32\mttwfh.dll> []
<{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}><C:\WINDOWS\system32\oohxdbyt.dll> []
<{EB71E0B3-E97D-4D30-8733-E28266467617}><C:\WINDOWS\system32\wyhesm.dll> []
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll> []
<{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll> []
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> []
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll> []
<{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}><C:\WINDOWS\system32\fmcvxy.dll> []
<{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}><C:\WINDOWS\system32\fsrgeb.dll> []
<{53D44DB6-E22B-4B17-97D3-572C96CCA6E1}><C:\WINDOWS\system32\zsdgff.dll> []
<{006CA8A1-61BC-4774-A54C-F49034270BAD}><C:\WINDOWS\system32\zgtwfx.dll> []
<{0B846B26-BFE6-4E8E-A948-1DB17B77B483}><C:\WINDOWS\system32\tdfhex.dll> []
<{28766E1C-74B0-4417-8C75-F12AE309EF35}><C:\WINDOWS\system32\wzcfsw.dll> []
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> []
<{50A8A8C4-EDC9-4ABD-A0A2-2E2418982189}><C:\WINDOWS\system32\kgfghd.dll> []