Need help? Ask the community or hire an expert.
Go to Avira Answers
病毒:Worm/Kolab.hbg.1
发现日期:13/12/2012
类型:蠕虫
广泛传播:
病毒传播个案呈报:低程度至中程度
感染/传播能力:低程度至中程度
破坏 / 损害程度:中等程度
静态文件:
文件大小:298.496 字节
MD5 校检和:48b2248688a341e91afd3c7feae72f30
VDF 版本:7.11.53.216 - donderdag 13 december 2012
IVDF 版本:7.11.53.216 - donderdag 13 december 2012

 况概描述 传播方法:
   • 局域网络
   • Messenger


别名:
   •  Panda: W32/Kolabc.BR.worm
   •  Eset: Win32/TrojanDropper.Agent.OPQ
   •  Bitdefender: Backdoor.SDBot.DGFD


平台/操作系统:
   • Windows 2000
   • Windows XP
   • Windows 2003


副作用:
   • 下载恶意文件
   • 植入恶意文件
   • 降低系统安全设置
   • 注册表修改
   • 第三方控件

 文件 它将本身复制到以下位置:
   • %SYSDIR%\logon.exe
   • %WINDIR%\mxmxxl.exe
   • %SYSDIR%\winIogon.exe
   • %SYSDIR%\sy.exe
   • %HOME%\SyncMan.exe
   • %SYSDIR%\winamp.exe
   • %SYSDIR%\SyncMan.exe



它会删除其本身最初执行的副本。



删除以下文件:
   • %SYSDIR%\afcu.bat
   • %SYSDIR%\oucoqifh.bat
   • %SYSDIR%\qcjk.bat
   • %WINDIR%\nfybcnxk.bat
   • %SYSDIR%\drivers\cdrom.sys
   • %SYSDIR%\wlxt.bat
   • %WINDIR%\cudwae.bat
   • %恶意软件执行目录%\djxcapsy.bat
   • %SYSDIR%\yufud.bat



创建以下文件:

– %WINDIR%\logfile32.txt
– %HOME%\oashdihasidhasuidhiasdhiashdiuasdhasd
– %SYSDIR%\ftzzihwk.bat
– %SYSDIR%\nvqwmp.bat
– %SYSDIR%\wkdtequu.bat
– %SYSDIR%\yufud.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %SYSDIR%\dllcache\cdrom.sys 进一步的调查表明,此文件是恶意软件。 检测为: TR/Rootkit.Gen

– %SYSDIR%\rdwoc.bat
– %SYSDIR%\wlxt.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %SYSDIR%\oucoqifh.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %SYSDIR%\itcngkpm.bat
%恶意软件执行目录%\djxcapsy.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %SYSDIR%\qcjk.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %WINDIR%\nfybcnxk.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %SYSDIR%\afcu.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %WINDIR%\cudwae.bat 成功创建后,它会被执行。 此批处理文件用于删除文件。
– %WINDIR%\diqs.bat
– %SYSDIR%\ermtc.bat



它会尝试下载文件:

– 该位置如下所示:
   • http://pey.somebar.ru/**********




它会尝试执行以下文件:

– 文件名:
   • %SYSDIR%\SyncMan.exe


– 文件名:
   • cmd /c ""%SYSDIR%\qcjk.bat" "


– 文件名:
   • cmd /c ""%SYSDIR%\wlxt.bat" "


– 文件名:
   • cmd /c ""%SYSDIR%\itcngkpm.bat" "


– 文件名:
   • cmd /c ""%WINDIR%\cudwae.bat" "


– 文件名:
   • cmd /c ""%SYSDIR%\ftzzihwk.bat" "


– 文件名:
   • cmd /c ""%SYSDIR%\rdwoc.bat" "


– 文件名:
   • cmd /c ""%SYSDIR%\ermtc.bat" "


– 文件名:
   • svchost.exe


– 文件名:
   • cmd.exe


– 文件名:
   • sy.exe


– 文件名:
   • "%WINDIR%\mxmxxl.exe"


– 文件名:
   • SyncMan.exe


– 文件名:
   • cmd /c ""%恶意软件执行目录%\djxcapsy.bat" "


– 文件名:
   • %SYSDIR%\winamp.exe


– 文件名:
   • cmd /c ""%SYSDIR%\oucoqifh.bat" "


– 文件名:
   • cmd /c ""%SYSDIR%\yufud.bat" "


– 文件名:
   • %SYSDIR%\svchost.exe


– 文件名:
   • cmd /c ""%WINDIR%\nfybcnxk.bat" "


– 文件名:
   • %SYSDIR%\logon.exe


– 文件名:
   • cmd /c ""%SYSDIR%\afcu.bat" "

 注册表 会添加以下注册表项,以便在系统重新引导后运行进程:

– [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "SyncMan"="%HOME%\SyncMan.exe"

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "Microsoft Driver Setup"="%WINDIR%\mxmxxl.exe"
   • "SyncMan"="%SYSDIR%\SyncMan.exe"

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\
   Run]
   • "Microsoft Driver Setup"="%WINDIR%\mxmxxl.exe"

–  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • Windows DLL Loader



它会创建以下项,以便绕过 Windows XP 防火墙:

– [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile\AuthorizedApplications\List]
   • "%SYSDIR%\SyncMan.exe"="%SYSDIR%\SyncMan.exe:*:Enabled:Windows DLL
      Loader"



会添加以下注册表项目注册值:

– [HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
   • "MaxUserPort"=dword:0x0000fffe

 Messenger 它是通过 Messenger 传播的。 下面说明了它的特征:

– Windows Live Messenger

该 URL 随后会引用所述恶意软件的副本。 如果用户下载并执行此文件,该感染进程会再次启动。

 网络感染 该恶意软件会尝试以下方式连接其他计算机来作广泛传播/感染。


漏洞攻击:
它会利用以下漏洞攻击:
– MS03-039 (RPCSS 服务中的缓冲区溢出)
– MS04-007 (ASN.1 漏洞)
– MS04-045 (WINS 中的漏洞)
– MS06-040 (服务器服务中的漏洞)


IP 地址生成:
它会创建随机 IP 地址,但会保留自己地址的第一个八进制字节。 之后,它会尝试与所创建的地址建立连接。

 IRC 为了提供系统信息和远程控制,它会连接到以下 IRC 服务器:

服务器: but.som**********.ru
端口: 7575
昵称: [N00_USA_XP_%数字%]

服务器: say.lon**********.in
端口: 4676
昵称: d[%字符串%]b

 进程终止 被终止进程列表:
   • VIPRE.EXE; ISSDM_EN_32.EXE; P08PROMO.EXE; K7TS_SETUP.EXE;
      AVINSTALL.EXE; WITSETUP.EXE; TrendMicro_TISPro_16.1_1063_x32.EXE;
      VBA32-PERSONAL-LATEST-ENGLISH.EXE; CCSETUP210.EXE; FSMB32.EXE;
      FSGK32.EXE; FSAV95.EXE; FSAV530WTBYB.EXE; FSAV530STBYB.EXE;
      FSAV32.EXE; FSAV.EXE; FSAA.EXE; FPROT.EXE; FP-WIN.EXE; FNRB32.EXE;
      FIH32.EXE; FCH32.EXE; FAST.EXE; FAMEH32.EXE; F-STOPW.EXE;
      F-PROT95.EXE; F-PROT.EXE; AFMAIN.EXE; SPIDERUI.EXE; SPIDERNT.EXE;
      ALERTMAN.EXE; RAVMOND.EXE; MAKEREPORT.EXE; BOXMOD.EXE; 360SAFE.EXE;
      360RPT.EXE; 360HOTFIX.EXE; 360TRAY.EXE; NSVMON.NPC; NSAVSVC.NPC;
      NPCGREENAGENT.NPC; PUSCAN.EXE; AYSERVICENT.AYE; AYAGENT.AYE;
      CMDAGENT.EXE; CPF.EXE; VSMON.EXE; ZLCLIENT.EXE; NSUTILITY.EXE;
      NSPUPDT.EXE; NAVQSCAN.EXE; NSPMAIN.EXE; NSPUPSVC.EXE; NSPSVC.EXE;
      MKSADMINCONSOLE.EXE; MKSUPDATE.EXE; MKSPC.EXE; MKSFWALL.EXE;
      MKSVIRMONSVC.EXE; MKS_SCAN.EXE; MKS_MAIL.EXE; MKSREGMON.EXE;
      KAVPFW.EXE; KASMAIN.EXE; KAV32.EXE; KPFWSVC.EXE; KISSVC.EXE;
      KWATCH.EXE; KPFW32.EXE; KAVSTART.EXE; KVSRVXP.EXE; KVOL.EXE; KVXP.KXP;
      KVMONXP.KXP; CAVASM.EXE; CMAIN.EXE; ARCABIT.CORE.LOGGINGSERVICE.EXE;
      ARCABIT.CORE.CONFIGURATOR2.EXE; TASKSCHEDULER.EXE; UPDATE.EXE;
      NETMONSV.EXE; FILEMONSV.EXE; ABREGMON.EXE.EXE; ARCACHECK.EXE;
      ARCAVIR.EXE; AVMENU.EXE; A2HIJACKFREE.EXE; A2SERVICE.EXE; A2START.EXE;
      A2SCAN.EXE; A2GUARD.EXE; VRFWSVC.EXE; HFACSVC.EXE; VRMONSVC.EXE;
      HPCSVC.EXE; HSVCMOD.EXE; VRMONNT.EXE; MKSTRAY.EXE; VBA32ADS.EXE;
      VBA32LDR.EXE; FILELOCKSETUP.EXE; TSCFCOMMANDER.EXE; TMPROXY.EXE;
      TMPFW.EXE; TMBMSRV.EXE; UFNAVI.EXE; UFSEAGNT.EXE; TISSPWIZ.EXE;
      SFCTLCOM.EXE; TNBUTIL.EXE; DEFWATCH.EXE; RTVSCAN.EXE; SBAMSVC.EXE;
      SBAMUI.EXE; SBAMTRAY.EXE; SAVADMINSERVICE.EXE; SAVSERVICE.EXE;
      SCFSERVICE.EXE; SCFMANAGER.EXE; RAVTASK.EXE; CCENTER.EXE; ULIBCFG.EXE;
      RAVLITE.EXE; PCTAV.EXEPCTAVSVC.EXEPXCONSOLE.EXEPXAGENT.EXERAV.EXE;
      PCTSAUXS.EXE; PCTSTRAY.EXE; PCTSSVC.EXE; PCTSGUI.EXE; AVGAS.EXE;
      PAVBCKPT.EXE; WEBPROXY.EXE; PAVSRV51.EXESRVLOAD.EXE; PSIMSVC.EXE;
      PSHOST.EXE; AVENGINE.EXE; PSKMSSVC.EXE; PAVPRSRV.EXE; PAVFNSVR.EXE;
      PSCTRLS.EXE; TPSRV.EXE; NOD32M2.EXE; NOD32CC.EXE; NOD32.EXE;
      NMAIN.EXE; NOD32KUI.EXE; MSASCUI.EXE; MSMPENG.EXE; MCUPDATE.EXE;
      MCSHIELD.EXE; MCVSSHLD.EXE; MCVSRTE.EXE; MCAGENT.EXE; KAVSVC.EXE;
      KAV.EXE; K7TSMNGR.EXE; K7SPMSRC.EXE; K7RTSCAN.EXE; K7PSSRVC.EXE;
      K7FWSRVC.EXE; K7EMLPXY.EXE; K7TSECURITY.EXE; K7SYSTRY.EXE;
      VIRUSUTILITIES.EXE; GUARDXSERVICE.EXE; GUARDXKICKOFF.EXE; AVKWCTL.EXE;
      AVKTUNERSERVICE.EXE; AVKSERVICE.EXE; GDFWSVC.EXE; AVKPROXY.EXE;
      GDFIRE~1.EXE; AVKTRAY.EXE; GDFIREWALLTRAY.EXE; FSAUA.EXE;
      NOD32KRN.EXE; FSMA32.EXE; FSDFWD.EXE; FSGK32ST.EXE; FSM32.EXE;
      FPWIN.EXE; FPAVSERVER.EXE; FPROTTRAY.EXE; INICIO.EXE; UMXPOL.EXE;
      UMXFWHLP.EXE; UMXAGENT.EXE; UMXCFG.EXE; PPCLTPRIV.EXE; SVCPRS32.EXE;
      ITMRTSVC.EXE; CCPROVSP.EXE; MDMCLS32.EXE; CAGLOBALLIGHT.EXE;
      CAPFUPGRADE.EXE; CAPFASEM.EXE; CAFW.EXE; CFGMNG32.EXE; CCTRAY.EXE;
      CLAMTRAY.EXE; CLAMWIN.EXE; ALSVC.EXE; ALMON.EXE; DRWEBSCD.EXE;
      SPIDERML.EXE; DRWEB32W.EXE; ACS.EXE; STRTSVC.EXE; OP_MON.EXE;
      SENSOR.EXE; QHFW332.EXE; CATEYE.EXE; ONLNSVC.EXE; EMLPROUI.EXE;
      UPSCHD.EXE; SCANMSG.EXE; SCANWSCS.EXE; EMLPROXY.EXE; ONLINENT.EXE;
      ASWCLNR.EXE; BDAGENT.EXE; VSSERV.EXE; LIVESRV.EXE; XCOMMSVR.EXE;
      UISCAN.EXE; BDSS.EXE; AVGUI.EXE; AVGUPD.EXE; AVGSCANX.EXE; AVGEMC.EXE;
      AVGUPSVC.EXE; AVGAMSVR.EXE; AVGWDSVC.EXE; ASHWEBSV.EXE; ASHMAISV.EXE;
      ASWUPDSV.EXE; ASHSERV.EXE; ASHDISP.EXE; AVCENTER.EXE; SCHED.EXE;
      AVIRARKD.EXE; AVGNT.EXE; AVGUARD.EXE; AHNSDSV.EXE; ACAIS.EXE;
      ACALS.EXE; ACAEGMGR.EXE; ACAAS.EXE; QOELOADER.EXE; APVXDWIN.EXE;
      QUHLPSVC.EXE; 123.EXE; RAVP.EXEMBAM.EXE123.COM; UNLOCKER1.8.7.EXE;
      UNIEXTRACT.EXE; SYSANALYZER_SETUP.EXE; STARTDRECK.EXE; SPF.EXE;
      REGX2.EXE; REGSHOT.EXE; REGSCANNER.EXE; REGISTRAR_LITE.EXE;
      REGCOOL.EXE; REGALYZ.EXE; PROJECTWHOISINSTALLER.EXE; PROCMON.EXE;
      CUREIT.EXE; FIXBAGLE.EXE; PGSETUP.EXE; OBJMONSETUP.EXE; NETALYZ.EXE;
      KILLBOX.EXE; INSTALLWATCHPRO25.EXE; AVENGER.EXE; IEFIX.EXE;
      HOSTSFILEREADER.EXE; FIXPATH.EXE; FILEFIND.EXE; FILEALYZ.EXE;
      EULALYZERSETUP.EXE; A2HIJACKFREESETUP.EXE; DLLCOMPARE.EXE;
      CPROCESS.EXE; CPORTS.EXE; ASVIEWER.EXE; APT.EXE; APM.EXE;
      SPYBOTSD.EXE; TEATIMER.EXE; SPYBOTSD160.EXE; PROCESSMONITOR.EXE;
      PROCDUMP.EXE; PG2.EXE; LORDPE.EXE; ICESWORD.EXE; REANIMATOR.EXE;
      ROOTKITNO.EXE; RKD.EXE; HACKMON.EXE; UNHACKME.EXE;
      ROOTKIT_DETECTIVE.EXE; AVGARKT.EXE; FSB.EXE; FSBL.EXE;
      ROOTKITREVEALER.EXE; PSKILL.EXE; TASKMON.EXE; TASKLIST.EXE;
      TASKMAN.EXE; PROCEXP.EXE; MSNFIX.EXE; HIJACKTHIS_V2.EXE;
      HIJACKTHIS.EXE; HIJACKTHIS_SFX.EXE; HJTSETUP.EXE; HJTINSTALL.EXE;
      OLLYDBG.EXE; NETSTAT.EXE; PORTMONITOR.EXE; PORTDETECTIVE.EXE;
      FPORT.EXE; APORTS.EXE; PAVARK.EXE; DARKSPY105.EXE; HELIOS.EXE;
      ROOTKITBUSTER.EXE; ROOTALYZER.EXE; BC5CA6A.EXE; SEEM.EXE;
      DELAYDELFILE.EXE; DUBATOOL_AV_KILLER.EXE; SUPERKILLER.EXE;
      KAKASETUPV6.EXE; BUSCAREG.EXE; MSNCLEANER.EXE; SRESTORE.EXE;
      BOOTSAFE.EXE; SUPERANTISPYWARE.EXE; CCLEANER.EXE;
      REGUNLOCKER.EXETSNTEVAL.EXEXP_TASKMGRENAB.EXE; CF9409.EXE; GMER.EXE;
      CATCHME.EXE; SDFIX.EXE; COMBOFIX.EXE; SRENGPS.EXE; AUTORUNS.EXE;
      TASKKILL.EXE; REGEDIT.EXE; REG.EXE; MYPHOTOKILLER.EXE;
      KILLAUTOPLUS.EXE; FOLDERCURE.EXE; REGEDIT.SCR; REGEDIT.COM; MMC.EXE;
      TCPVIEW.EXE; LISTO.EXE; GUARD.EXE; NTVDM.EXE; COMMAND.COM;
      COMBOFIX.COM; COMBOFIX.SCR; COMBOFIX.BAT; REGMON.EXE;
      OTMOVEIT.EXEMBAM-SETUP.EXE; JAJA.EXE; AVZ.EXE; MBAM.EXE;
      MBAM-SETUP.EXE; PENCLEAN.EXE; ELISTA.EXE; HJ.EXE;
      WINDOWS-KB890930-V2.2.EXE; MRTSTUB.EXE; MRT.EXE; HIJACK-THIS.EXE;
      VIRUS.EXE; SAFEBOOTKEYREPAIR.EXEOTMOVEIT3.EXEHOSTSXPERT.EXEDAFT.EXE;
      ATF-CLEANER.EXE; COMPAQ_PROPIETARIO.EXE; SRENGLDR.EXE; HOOKANLZ.EXE


 文件详细信息 运行时压缩程序:
为了提高检测难度以及减小文件,它已使用运行时压缩程序进行压缩。

Beschrijving ingevoegd door Petre Galan op woensdag 26 mei 2010
Beschrijving bijgewerkt door Petre Galan op woensdag 26 mei 2010

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.