瑞星不报一个
样本来自
http://bbs.ikaka.com/showtopic-8623515.aspx调用cmd执行以下命令sc delete avp
net1 start server
sc delete RavCCenter
sc delete RsScanSrv
sc delete RavTask
释放文件C:\rsv.dll并加载"C:\WINDOWS\system32\rundll32.exe" C:\rsv.dll,RSDK
该文件加载后
篡改文件system32\drivers\asyncmac.sys
再加载,实现恢复SSDT
释放文件:X:\AUTORUN.INF
X:\GRIL.PIF
%WinDir%\Fonts\smyns.sys并安装驱动
删除以下注册表:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\360Safetray
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\360Safebox
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KavStart
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ccApp
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vptray
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\RavTray
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\egui
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\essact
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
联网下载病毒http://c.wuc9.com/tt.txt
http://c.wuc9.com/dd/33.exe
http://c.wuc9.com/dd/4.exe
http://c.wuc9.com/dd/6.exe
http://c.wuc9.com/dd/99.exe
http://c.wuc9.com/dd/10.exe
用户系统信息:Opera/9.64 (Windows NT 5.1; U; zh-cn) Presto/2.1.1