Ransom.MSIL.THANOS.THABGBA
Trojan-Ransom.Thanos (Ikarus), HEUR:Trojan-Ransom.MSIL.Encoder.gen (Kaspersky)
Windows

恶意软件类型:
Ransomware
有(yǒu)破坏性?:
没有(yǒu)
加密?:
是的
In the Wild:
是的
概要
它以其他(tā)恶意软件释放的文(wén)件或用(yòng)户访问恶意网站时不知不觉下载的文(wén)件的形式到达系统。它开始执行然后再删除。
技(jì )术详细信息
新(xīn)病毒详细信息
它以文(wén)件的形式出现在系统中(zhōng),可(kě)能(néng)是其他(tā)恶意软件投放的,或者是用(yòng)户在访问恶意网站时无意中(zhōng)下载的。
它可(kě)能(néng)是由下列恶意软件植入:
安(ān)装(zhuāng)
它添加下列互斥条目,确保一次只会运行一个副本:
- e660f428-738e-469e-93fc-20803ca8aa37
自启动技(jì )术
它将下列文(wén)件植入 Windows 用(yòng)户启动文(wén)件夹,以便在系统每次启动时自动执行:
- %User Startup%\mystartup.lnk
(注意: %User Startup% 是当前用(yòng)户的启动文(wén)件夹,通常位于 C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup (Windows NT)、C:\Documents and Settings\{User name}\Start Menu\Programs\Startup (Windows 2003(32-bit)、XP、2000(32-bit)) 和 C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit))。)
其他(tā)系统修改
它会创建以下注册表项以禁用(yòng)安(ān)全相关的应用(yòng)程序:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender\Real-Time Protection
DisableBehaviorMonitoring = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender
DisableAntiSpyware = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender\Real-Time Protection
DisableOnAccessProtection = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender\Real-Time Protection
DisableScanOnRealtimeEnable = 1
其他(tā)详细信息
该程序执行以下操作(zuò):
- It terminates the following processes if found using the following commands:
- "taskkill.exe" /IM mspub.exe /F
- "taskkill.exe" /IM onenote.exe /F
- "taskkill.exe" /IM agntsvc.exe /F
- "taskkill.exe" /IM PccNTMon.exe /F
- "taskkill.exe" /IM synctime.exe /F
- "taskkill.exe" /IM thebat.exe /F
- "taskkill.exe" /IM excel.exe /F
- "taskkill.exe" /IM msaccess.exe /F
- "taskkill.exe" /IM steam.exe /F
- "taskkill.exe" /IM firefoxconfig.exe /F
- "taskkill.exe" /IM CNTAoSMgr.exe /F
- "taskkill.exe" /IM dbeng50.exe /F
- "taskkill.exe" /IM sqlwriter.exe /F
- "taskkill.exe" /IM infopath.exe /F
- "taskkill.exe" /IM mspub.exe /F
- "taskkill.exe" /IM Ntrtscan.exe /F
- "taskkill.exe" /IM outlook.exe /F
- "taskkill.exe" /IM mydesktopservice.exe /F
- "taskkill.exe" /IM encsvc.exe /F
- "taskkill.exe" /IM tbirdconfig.exe /F
- "taskkill.exe" /IM mbamtray.exe /F
- "taskkill.exe" /IM mydesktopqos.exe /F
- "taskkill.exe" /IM thebat64.exe /F
- "taskkill.exe" /IM zoolz.exe /F
- "taskkill.exe" /IM tmlisten.exe /F
- "taskkill.exe" /IM sqlservr.exe /F
- "taskkill.exe" /IM winword.exe /F
- "taskkill.exe" /IM visio.exe /F
- "taskkill.exe" /IM mydesktopqos.exe /F
- "taskkill.exe" /IM mydesktopservice.exe /F
- "taskkill.exe" /IM mysqld.exe /F
- "taskkill.exe" /IM isqlplussvc.exe /F
- "taskkill.exe" /IM msftesql.exe /F
- "taskkill.exe" /IM sqbcoreservice.exe /F
- "taskkill.exe" /IM ocomm.exe /F
- "taskkill.exe" IM thunderbird.exe /F
- "taskkill.exe" /IM mysqld-nt.exe /F
- "taskkill.exe" /IM dbsnmp.exe /F
- "taskkill.exe" /IM powerpnt.exe /F
- "taskkill.exe" /IM xfssvccon.exe /F
- "taskkill.exe" /IM wordpad.exe /F
- "taskkill.exe" /IM mysqld-opt.exe /F
- "taskkill.exe" /IM ocautoupds.exe /F
- It terminates all running processes unless the following strings are found in the process name:
- chrome
- opera
- msedge
- iexplore
- firefox
- explorer
- wininit
- winlogon
- SearchApp
- SearchIndexer
- SearchUI
- It checks if the following programs are running. If they are, the said programs are terminated, and the main ransomware program will terminate as well:
- http analyzer stand-alone
- fiddler
- effetech http sniffer
- firesheep
- IEWatch Professional
- wireshark portable
- sysinternals tcpview
- dumpcap
- wireshark
- ollydbg
- x64dbg
- x32dbg
- dnspy
- dnspy-x86
- de4dot
- ilspy
- dotpeek
- dotpeek64
- ida64
- RDG Packer Detector
- CFF Explorer
- PEiD
- protection_id
- LordPE
- pe-sieve
- MegaDumper
- UnConfuserEx
- Universal_Fixer
- NoFuserEx
- NetworkMiner
- NetworkTrafficView
- HTTPNetworkSniffer
- tcpdump
- intercepter
- intercepter-NG
- It deletes the following registry subkeys to delete shadow copies:
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- vssadmin.exe
- vssadmin.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- wmic.exe
- wmic.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- wbadmin.exe
- wbadmin.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- bcdedit.exe
- bcdedit.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- powershell.exe
- powershell.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- diskshadow.exe
- diskshadow.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- net.exe
- net.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- The malware disables the following using powershell console:
- "DisableRealtimeMonitoring"
- "DisableBehaviorMonitoring"
- "DisableBlockAtFirstSeen"
- "DisableIOAVProtection"
- "DisablePrivacyMode"
- "SignatureDisableUpdateOnStartupWithoutEngine"
- "DisableArchiveScanning"
- "DisableIntrusionPreventionSystem"
- "DisableScriptScanning"
- "SubmitSamplesConsent"
- "MAPSReporting"
- "HighThreatDefaultAction"
- "ModerateThreatDefaultAction"
- "LowThreatDefaultAction"
- "SevereThreatDefaultAction"
解决方案
Step 2
对于Windows ME和XP用(yòng)户,在扫描前,请确认已禁用(yòng)系统还原功能(néng),才可(kě)全面扫描计算机。
Step 3
请注意,在执行此恶意软件/间谍软件/灰色软件期间,并非所有(yǒu)文(wén)件、文(wén)件夹、注册表项和条目都安(ān)装(zhuāng)在您的计算机上。这可(kě)能(néng)是由于安(ān)装(zhuāng)不完整或其他(tā)操作(zuò)系统条件造成的。如果找不到相同的文(wén)件/文(wén)件夹/注册表信息,请继续下一步。
Step 4
重启进入安(ān)全模式
Step 5
删除该注册表值
注意事项:错误编辑Windows注册表会导致不可(kě)挽回的系统故障。只有(yǒu)在您掌握后或在系统管理(lǐ)员的帮助下才能(néng)完成这步。或者,请先阅读Microsoft文(wén)章,然后再修改计算机注册表。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
- DisableAntiSpyware=1
- DisableAntiSpyware=1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- DisableBehaviorMonitoring=1
- DisableBehaviorMonitoring=1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- DisableOnAccessProtection=1
- DisableOnAccessProtection=1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- DisableScanOnRealtimeEnable=1
- DisableScanOnRealtimeEnable=1
Step 6
搜索和删除这些文(wén)件
- %User Temp%\RESTORE_FILES_INFO.txt
- %User Startup%\mystartup.lnk
- %User Temp%\RESTORE_FILES_INFO.txt
- %User Startup%\mystartup.lnk
Step 7
重启进入正常模式,使用(yòng)亚信安(ān)全产(chǎn)品扫描计算机,检测Ransom.MSIL.THANOS.THABGBA文(wén)件 如果检测到的文(wén)件已被亚信安(ān)全产(chǎn)品清除、删除或隔离,则无需采取进一步措施。可(kě)以选择直接删除隔离的文(wén)件。请参阅知识库页(yè)面了解详细信息。
Step 8
使用(yòng)亚信安(ān)全产(chǎn)品扫描计算机,并删除检测到的Ransom.MSIL.THANOS.THABGBA文(wén)件 如果检测到的文(wén)件已被亚信安(ān)全产(chǎn)品清除、删除或隔离,则无需采取进一步措施。可(kě)以选择直接删除隔离的文(wén)件。请参阅知识库页(yè)面了解详细信息。
Step 9
从备份中(zhōng)还原被加密的文(wén)件。