瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了..

12   1  /  2  页   跳转

[求助] 我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了..

我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了..

我妈妈上网时候,接到个"系统正被病毒入侵,请下载xpAntispyware2009来保护你的电脑"(英文的),我妈妈不知道,就下载了,,...
其实我还没有安装了瑞星2009,现在安装了以后,却不能查杀出任何病毒,包括使用卡卡,360......
而且我通过瑞星查找漏洞,下载更新,却显示不能连接到服务器.
通过浏览器也不能连接.
每次开机都有个安全危机的叉在右下脚,显示不能找到杀毒软件(其实我有瑞星).

大家知道怎么解决吗?!!
上别的网可以,就是不能上microsoft的更新网.

用户系统信息:Mozilla/5.0 (Windows; U; Windows NT 6.0; zh-CN; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
分享到:
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

请帮助我解决,一定啊..
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

微软打击假冒软件:9天清理近40万台PC
12月25日消息,微软最近表示,在打击假冒安全软件活动的第二个月中,已经从近40万台PC上卸载了“Antivirus 2009”假冒软件。

  据国外媒体报道称,12月版“恶意软件清除工具”以最流行的假冒安全软件之一“Antivirus 2009”为打击目标。据微软称,“恶意软件清除工具”自12月9日发布以来,在9天之内就从394000多台PC上卸载了假冒安全软件 “Antivirus 2009”。

  上月,微软还从近100万台PC上卸载了象“Advanced Antivirus”、“Ultimate Antivirus 2008”和“XPert Antivirus”等另外数款假冒安全软件。

  12月版“恶意软件清除工具”针对的是被微软称为“W32/FakeXPA”的一种不同的恶意软件,其中包括名为“Antivirus XP”、“AntivirusXP 2008”和“Antivirus 2009”等假冒反病毒软件。

  由于犯罪分子作梗,Windows用户逐渐陷入假冒安全软件陷阱。据一名研究人员表示,犯罪分子通过在用户PC上安装假冒安全软件、然后再以不断的弹出式广告和病毒感染威胁来催促用户支付40-50美元购买毫无价值的信息,每年可以从中获得高达500万美元的收入。

  12月版“恶意软件清除工具”还将另外一款被微软认为是木马软件的“W32/Yektel”恶意软件作为清除目标。W32/Yektel模仿了 IE的安全警告功能。新版W32/Yektel木马软件在谷歌搜索结果网页中插入假冒的安全警告。一旦探测到URL中包含有“google”,就会插入下述假冒消息“Google已经检测到你的PC上有未注册的Antivirus 2009,Google建议你激活Antivirus 2009,以保护你的PC免受来自互联网的恶意软件侵扰。”

当然,Yektel的IE和Google警告中的链接会将用户引到一个催促用户支付50美元Antivirus 2009注册费的站点。

Windows用户可以通过微软网站或Windows更新服务下载“恶意软件清除工具”。
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....


目前还不知道怎么解决中
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

用卡卡扫描下流氓软件试试
您好,您所拨打的用户已关机,请稍后再拨,如要留言请回复1,如要求视频请回复2,如闲得蛋疼请回复3后就近联系当地医院预约割蛋手术,尿频尿急请直接上厕所并服用三金片
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

你只能去微软官网:下载"恶意软件清除工具"
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

第三方安全软件目前还未能。。。
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

谢谢大家了..
卡卡扫描过了..没有用啊....
试试恶意软件清除工具,有了好消息就告诉大家. .
gototop
 

回复:我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

貌似有点作用,让我再仔细看看.
谢谢,soboy了.
gototop
 

回复: 我的xp系统被xpAntispyware2009俘虏了..!!!--帮帮忙啊,系统不能更新升级了.....

Downloader.Win32.Agent.bs
http://www.ca.com/cn/securityadvisor/virusinfo/virus.aspx?id=74719



病毒详细信息
Win32/FakeAV.JW 发布日期:
2008/11/5
上次更新时间:
2008/11/5

威胁评估 总体风险: 


猖獗程度: 



破坏程度: 


普遍程度: 


特征 类型 : Trojan
类别 : Win32
其他名称: Downloader.Win32.Agent.bs (Kaspersky), TrojanDownloader:Win32/FakeRean (MS OneCare)

即时保护信息
特征码产品删除指导
31.6.6140
CA Antivirus 2007
查看
31.6.6140
eTrust Antivirus v7/8*
查看
7.x/6140
eTrust EZ Antivirus 7.x
查看
31.6.6140
Vet 7
查看


工具 下载特征码文件
扫描病毒
提交病毒样本



描述
感染方式
有效负载
其他信息

描述 Win32/FakeAV.JW is a trojan that disguises itself as a legitimate anti-virus program and displays various popup messages warning of fake infections. It may also download additional malware to the compromised system. 返回顶部

感染方式 When executed, Win32/FakeAV.JW informs the user that it is downloading "XP Antivirus 2009":



It downloads the following files from the URL www.xpantispyware-2009.com:

Binaries1.cab
Binaries2.cab
Binaries3.cab


It extracts and executes the downloaded files, then creates the following directory containing the malware files:

%Program Files%\XP_AntiSpyware

Note: %Program Files% is a variable location. The malware determines the location of the current Program Files folder by querying the operating system. A typical location for this folder would be C:\Program Files.

It also creates the following files as part of its installation:

%Windows%\wiadebug.log
%Windows%\wiaservc.log
%Documents and Settings%\<
username >\Start Menu\Programs\XP_AntiSpyware\Uninstall.lnk
%Documents and Settings%\<
username>\Start Menu\Programs\XP_AntiSpyware\XP_AntiSpyware.lnk

Note: %Windows% and %Documents and Settings% are variable locations. The malware determines the locations of these folders by querying the operating system. The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95, 98 and ME is C:\Windows; and for XP and Vista is C:\Windows. A typical location for Documents and Settings is C:\Documents and Settings.   

The trojan adds the registry entry below to automatically execute itself on system start:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\XP Antispyware 2009 = "%Program Files%\XP_AntiSpyware\XP_AntiSpyware.exe" /hide"

It also adds the following registry entries:

HKCU\Control Panel\don't load\scui.cpl = "No"
HKCU\Control Panel\don't load\wscui.cpl = "No"
HKLM\SOFTWARE\XP_Antispyware
HKLM\SOFTWARE\XP_Antispyware\info = "<
date of infection >"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XP_AntiSpyware


Additionally, the trojan displays the user interface for "XP Antivirus 2009", where it pretends to scan the system while reporting numerous 'infections':



返回顶部

有效负载 Disables Security NotificationsWin32/FakeAV.JW disables the Windows Firewall, updates, and antivirus reports by modifying the registry entries below:

HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify = dword:00000001
HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify = dword:00000001
HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify = dword:00000001


Displays False WarningsWin32/FakeAV.JW displays a fake Windows Security Center:



as well as warnings about fake infections:



It also displays popup messages in the taskbar that inform the user of false infections:

Privacy alert!
Your system was found to be infected with intercepting programs. These can log your activity and damage your privacy. Click here for XP Antispyware 2009 spyware removal.


------------------------------------------------------------

Trojan detected!
A piece of malicious code was found in your system which can replicate itself if no action is taken. Click here to have your system cleaned by XP Antispyware 2009.


------------------------------------------------------------

Spyware alarm!
Our scan has reported that pieces of malicious spyware code are present on your hard drive. To get rid of security threats, click here for a XP Antispyware 2009 scan.


------------------------------------------------------------

Privacy is at risk!
Attention, keylogging and intercepting scripts were detected. Your private data may be disclosed to third parties. Click here and XP Antispyware 2009 will remove the infection.






Downloads and Executes Arbitrary FilesWin32/FakeAV.JW attempts to access the following websites to report its activities and to download additional rogue software:

domake-progress.com
do-managedscan.com
domanaged-scan.com
do-fixed-progress
do-monster-scan.com
xp-as-2009.com
xpas2009.com
xpantispyware-2009.com
xp-antispyware-2009.com
xp-antispyware2009.com
xpas-2009.com
xp-as2009.com


返回顶部

其他信息 Below is a screenshot of the website that attempts to entice users to download the trojan. Product certifications displayed in the website are fake and designed to scam unsuspecting users:



The following are additional images of Win32/FakeAV.JW running on an affected system:





Analysis by Zarestel Ferrer
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT