今天发现瑞星防火墙连报2个程序要连接网络,从文件名看基本可以确定是木马.
打开IceSword发现确实有两个可疑进程,但最新的瑞星杀毒软件依然很沉默.
打开瑞星杀毒仍然无法检测到这2个木马.看来还不如防火墙有用-_-
分析一下发现这2个木马都没加壳,但都有网络相关的函数导入.
看文件日期,两个文件都是2006.1.20(3天前)创建的.
一个是IRJIT.dll,描述是"Microsoft irJIT Module",竟然打着微软的幌子,
藏到windows\system32\wbem中,不过看文件时间就发现与众不同.
其自身加入到服务中,服务的描述让人无语:
"管理 IP 安全客户端策略以及启动,为 IP 安全驱动程序提供存储支持。"
另一个是Network.dll,描述是"QQFACE",版权是"COMENET TECHNOLOGY",
藏到program files\common files\sand中,自身加入到服务中,
服务的描述实在诱人:"提供网络地址转换、名称解析和/或入侵保护服务。
如果此服务被禁用,任何依赖它的服务将无法启动。"
怎么看都与QQ无关,即使与QQ有关,也不可能是名为COMENET公司的产品.
扔到VIRUSTOTAL检测,结果为:
This is a report processed by VirusTotal on 01/23/2006 at 03:33:03 (CET) after scanning the file "IRJIT.dll" file.
Antivirus Version Update Result
AntiVir 6.33.0.77 01.20.2006 no virus found
Avast 4.6.695.0 01.20.2006 no virus found
AVG 718 01.20.2006 no virus found
Avira 6.33.0.77 01.20.2006 no virus found
BitDefender 7.2 01.23.2006 no virus found
CAT-QuickHeal 8.00 01.21.2006 no virus found
ClamAV devel-20051123 01.21.2006 no virus found
DrWeb 4.33 01.22.2006 DLOADER.Trojan
eTrust-InoculateIT 23.71.57 01.22.2006 no virus found
eTrust-Vet 12.4.2052 01.20.2006 no virus found
Ewido 3.5 01.22.2006 no virus found
Fortinet 2.54.0.0 01.22.2006 no virus found
F-Prot 3.16c 01.20.2006 no virus found
Ikarus 0.2.59.0 01.20.2006 no virus found
Kaspersky 4.0.2.24 01.22.2006 Trojan-Downloader.Win32.QQHelper.u
McAfee 4679 01.20.2006 no virus found
NOD32v2 1.1373 01.20.2006 no virus found
Norman 5.70.10 01.20.2006 no virus found
Panda 9.0.0.4 01.22.2006 no virus found
Sophos 4.01.0 01.22.2006 no virus found
Symantec 8.0 01.23.2006 no virus found
TheHacker 5.9.2.078 01.20.2006 no virus found
UNA 1.83 01.21.2006 no virus found
VBA32 3.10.5 01.22.2006 no virus found
This is a report processed by VirusTotal on 01/23/2006 at 03:17:47 (CET) after scanning the file "Network.dll" file.
Antivirus Version Update Result
AntiVir 6.33.0.77 01.20.2006 no virus found
Avast 4.6.695.0 01.20.2006 no virus found
AVG 718 01.20.2006 no virus found
Avira 6.33.0.77 01.20.2006 no virus found
BitDefender 7.2 01.23.2006 no virus found
CAT-QuickHeal 8.00 01.21.2006 no virus found
ClamAV devel-20051123 01.21.2006 no virus found
DrWeb 4.33 01.22.2006 DLOADER.Trojan
eTrust-InoculateIT 23.71.57 01.22.2006 no virus found
eTrust-Vet 12.4.2052 01.20.2006 no virus found
Ewido 3.5 01.22.2006 no virus found
Fortinet 2.54.0.0 01.22.2006 no virus found
F-Prot 3.16c 01.20.2006 no virus found
Ikarus 0.2.59.0 01.20.2006 no virus found
Kaspersky 4.0.2.24 01.22.2006 not-a-virus:AdWare.Win32.AdHelper.f
McAfee 4679 01.20.2006 no virus found
NOD32v2 1.1373 01.20.2006 no virus found
Norman 5.70.10 01.20.2006 no virus found
Panda 9.0.0.4 01.22.2006 no virus found
Sophos 4.01.0 01.22.2006 no virus found
Symantec 8.0 01.23.2006 no virus found
TheHacker 5.9.2.078 01.20.2006 no virus found
UNA 1.83 01.21.2006 no virus found
VBA32 3.10.5 01.22.2006 no virus found
看来Kaspersky果然名不虚传啊,而DrWeb在国内似乎无人知晓.
幸好这两个木马没有插入线程,否则防火墙也拦不住.
先不上报,保留木马样本,
看看其他杀软什么时候能截获此病毒即可看出杀毒能力如何.