¡¡
   » Ê×Ò³ » µçÄÔ_ÊýÂë » ·´²¡¶¾ » ÏµÍ³×ÜÊÇ×Ô¶¯ÖØÆô¶¯

ϵͳ×ÜÊÇ×Ô¶¯ÖØÆô¶¯

ÏÔʾϵͳcÅÌ/windows/system32/services.exeÒâÍâÖÕÖ¹,״̬ÂëÊÇ-1073741819,½ÓמͿªÊ¼µ¹Êý×Ô¶¯ÖØÐÂÆô¶¯ÁË,ÒªÔõô½â¾ö?ÎÒÓÿ¨°Í˹»ù,windowsľÂíÇåµÀ·òɱ¹ýľÂíÁË,ÓÐʱºò¿ª±ðµÄ³ÌÐòûÊÂ,¿ÉÓеÄʱºòÒ»¿ªqq¾Í»áµ¯³öÉÏÃæµÄ¶Ô»°¿ò ÎÊÌâ²¹³ä£ºÎÒÔÚ×¢²á±íÏÂÃæÃ»ÓÐÕÒµ½WINDOWS SYSTEM = botzor.exe
Õâ¸ö¼ü,ÊDz»ÊÇ˵Ã÷²¢Ã»ÓÐÖÐÕâ¸ö²¡¶¾ÄØ?


×è»÷²¨£¿
services - services.exe - ½ø³ÌÐÅÏ¢
½ø³ÌÎļþ£º services »òÕß services.exe
½ø³ÌÃû³Æ£º Windows Service Controller

ÃèÊö£º
services.exeÊÇ΢ÈíWindows²Ù×÷ϵͳµÄÒ»²¿·Ö¡£ÓÃÓÚ¹ÜÀíÆô¶¯ºÍÍ£Ö¹·þÎñ¡£¸Ã½ø³ÌÒ²»á´¦ÀíÔÚ¼ÆËã»úÆô¶¯ºÍ¹Ø»úʱÔËÐеķþÎñ¡£Õâ¸ö³ÌÐò¶ÔÄãϵͳµÄÕý³£ÔËÐÐÊǷdz£ÖØÒªµÄ¡£×¢Ò⣺servicesÒ²¿ÉÄÜÊÇW32.Randex.R(´¢´æÔÚ%systemroot%\system32\Ŀ¼)ºÍSober.P (´¢´æÔÚ%systemroot%\Connection Wizard\Status\Ŀ¼)ľÂí¡£¸ÃľÂíÔÊÐí¹¥»÷Õß·ÃÎÊÄãµÄ¼ÆËã»ú£¬ÇÔÈ¡ÃÜÂëºÍ¸öÈËÊý¾Ý¡£¸Ã½ø³ÌµÄ°²È«µÈ¼¶Êǽ¨ÒéÁ¢¼´É¾³ý¡£




1¡¢ ÔÚÈÎÎñ¹ÜÀíÆ÷ÀïÃæ½áÊøbotzor.exe½ø³Ì
2¡¢ ÔËÐÐREGEDIT£¬´ò¿ª×¢²á±í±à¼­Æ÷£¬É¾³ý²¡¶¾ÔÚ×¢²á±íÖÐÌí¼ÓµÄÆô¶¯Ïî
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
WINDOWS SYSTEM = botzor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
WINDOWS SYSTEM = botzor.exe

3¡¢½«²¡¶¾ÔÚϵͳĿ¼Ï´´½¨botzor.exeÎļþɾ³ý,´óСΪ22528×Ö½Ú¡£
רɱ¹¤¾ß: ûý
¯ê
µã»÷ä¯ÀÀ¸ÃÎļþ
8ÔÂ15ÈÕ,½ðɽ·´²¡¶¾Ó¦¼±´¦ÀíÖÐÐĽػñÒ»¸öÕë¶Ô΢ÈíϵͳÑÏÖØÂ©¶´½øÐÐÖ÷¶¯¹¥»÷µÄ²¡¶¾£¬²¢ÃüÃûΪZotob(Worm.Zotob.A)¡£½ðɽµÄ·´²¡¶¾×¨¼Ò˵£¬Zotob²¡¶¾ÀûÓé¶´Ö÷¶¯´«²¥£¬¶ÔÓÚ¸öÈ˵çÄÔµÄΣº¦·Ç³£´ó£¬ÆäΣº¦³Ì¶ÈÓëµ±ÄêµÄÕðµ´²¨ÏàËÆ£¬Ò»µ©±»¹¥»÷£¬Óû§µÄµçÄÔ½«»á³öÏÖ²»¶ÏÖØÆô¡¢ÏµÍ³²»Îȶ¨µÈÇé¿ö¡£²¡¶¾×÷Õß½ÐÏùɱµôÕâ¸ö²¡¶¾µÄɱ¶¾Èí¼þ½«ÓÚ24СʱÄÚ±»½Ëɱ£¡
ZotobÀûÓÃ5Ììǰ΢Èí¸Õ¸Õ¹«²¼µÄÑÏÖØÏµÍ³Â©¶´£¬Windows Plug and Play ·þÎñ©¶´ (MS05-039)£¬ ¹¥»÷TCP¶Ë¿Ú445£¬ºÍ³å»÷²¨¡¢Õðµ´²¨·½·¨ÀàËÆ£¬¹¥»÷´úÂëÏòÄ¿±êϵͳµÄ445¶Ë¿Ú·¢ËÍ©¶´´úÂ룬ʹĿ±êϵͳÔì³É»º³åÇøÒç³ö£¬Í¬Ê±ÔËÐв¡¶¾´úÂ룬½øÐд«²¥¡£
²¡¶¾¹¥»÷Ä¿±êϵͳʱ£¬¿ÉÄÜÔì³Éϵͳ²»¶ÏÖØÆô£¨Èçͼʾ£©£¬ÓëÕðµ´²¨¡¢³å»÷²¨·¢×÷µÄʱºòÀàËÆ£¬Ö»²»¹ýÔÚZotobÓ°ÏìµÄ½ø³Ì±äÁË£¬±äΪϵͳ¹Ø¼ü½ø³Ì¡°Service.exe¡±£¬ ZotobÆäʵÊÇMytobµÄ×îбäÖÖ¡£MytobÊÇǰһÕó´óËÁ·ºÀĵÄÓʼþ²¡¶¾¡£´Ë´Î±äÖÖ£¬¸üÊǼÓÈëÁË5Ììǰ²Å¹«²¼Â©¶´²¹¶¡µÄϵͳÑÏÖØÂ©¶´£¨Windows Plug and Play ·þÎñ©¶´ (MS05-039) £©½øÐÐÖ÷¶¯¹¥»÷£¬Ê¹Æä´ó´óÌá¸ßÁ˲¡¶¾´«²¥µÄ¹ã¶È¡£Òò´Ë£¬Zotob³ýÁËÀûÓé¶´¹¥»÷Í⣬»¹¾ßÓÐÓʼþ´«²¥¡¢×Ô¶¯ÏÂÔØÐ²¡¶¾µÈµÈÕâЩÓëÓʼþ²¡¶¾Ëù¾ßÓеÄΣº¦£¬Ê¹Öж¾Óû§ÔâÊÜ´ò»÷¡£

²¡¶¾ÔËÐк󣬽«ÔÚϵͳĿ¼Ï´´½¨botzor.exeÎļþ,´óСΪ22528×Ö½Ú¡£ÔÚ×¢²á±íÖÐÌí¼ÓÏÂÁÐÆô¶¯Ï
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] WINDOWS SYSTEM = botzor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] WINDOWS SYSTEM = botzor.exe

ÕâÑù£¬ÔÚWindowsÆô¶¯Ê±£¬²¡¶¾¾Í¿ÉÒÔ×Ô¶¯Ö´ÐС£

¡°¼«ËÙ²¨¡±²¡¶¾Í¨¹ýTCP¶Ë¿Ú8080Á¬½ÓIRC·þÎñÆ÷£¬½ÓÊܲ¢Ö´ÐкڿÍÃüÁî¡£¿Éµ¼Ö±»¸ÐȾ¼ÆËã»ú±»ºÚ¿ÍÍêÈ«¿ØÖÆ¡£²¢ÔÚTCP¶Ë¿Ú33333¿ªÆôFTP·þÎñ£¬Ìṩ²¡¶¾ÎļþÏÂÔØ¹¦ÄÜ¡£ÀûÓÃ΢Èí¼´²å¼´Ó÷þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨MS05-039£©½øÐд«²¥¡£Èç¹û©¶´ÀûÓôúÂë³É¹¦ÔËÐУ¬½«µ¼ÖÂÔ¶³ÌÄ¿±ê¼ÆËã»ú´Óµ±Ç°±»¸ÐȾ¼ÆËã»úµÄFTP·þÎñÉÏÏÂÔØ²¡¶¾³ÌÐò¡£Èç¹û©¶´´úÂëûÓгɹ¦ÔËÐУ¬Î´´ò²¹¶¡µÄÔ¶³Ì¼ÆËã»ú¿ÉÄÜ»á³öÏÖservices.exe½ø³Ì±ÀÀ£µÄÏÖÏó¡£ £¿t…ô§Ä
¸Ã²¡¶¾µÄΣº¦»¹ÔÚÓÚ£¬²¡¶¾»áÐÞ¸Ä%SystemDir%\drivers\etc\hostsÎļþ£¬ÆÁ±Î´óÁ¿¹úÍâ·´²¡¶¾ºÍ°²È«³§É̵ÄÍøÖ·¡£²¢¶Ô·´²¡¶¾³§ÉÌÌá³ö¹«¿ªÌôÕ½£ºµÚÒ»¸ö·¢Ïֵķ´²¡¶¾Èí¼þ ½«ÔÚ24СʱÄÚÔâµ½¡°½Ëɱ¡±¡££¨MSG to avs: the first av who detect this worm will be the first killed in the next 24hours!!!£©
¹ØÓÚMS05-039:
Microsoft Windows¼´²å¼´Óûº³åÇøÒç³ö©¶´£¨MS05-039£©
Ó°Ïìϵͳ£º
Microsoft Windows XP SP2
Microsoft Windows XP SP1
Microsoft Windows Server 2003 SP1£¿¢˜
Microsoft Windows Server 2003
Microsoft Windows 2000SP4
Microsoft Windows¼´²å¼´Óã¨PnP£©¹¦ÄÜÔÊÐí²Ù×÷ϵͳÔÚ°²×°ÐÂÓ²¼þʱÄܹ»¼ì²âµ½ÕâЩÉ豸¡£
Microsoft Windows¼´²å¼´Óù¦ÄÜÖдæÔÚ»º³åÇøÒç³ö©¶´£¬³É¹¦ÀûÓÃÕâ¸ö©¶´µÄ¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£

ÆðÒòÊÇPnP·þÎñ´¦Àí°üº¬Óйý¶àÊý¾ÝµÄ»ûÐÎÏûÏ¢µÄ·½Ê½¡£ÔÚWindows 2000ÉÏ£¬ÄäÃûÓû§¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆÏûÏ¢À´ÀûÓÃÕâ¸ö©¶´£»ÔÚWindows XP Service Pack 1ÉÏ£¬Ö»ÓÐͨ¹ýÈÏÖ¤µÄÓû§²ÅÄÜ·¢ËͶñÒâÏûÏ¢£»ÔÚWindows XP Service Pack 2ºÍWindows Server 2003ÉÏ£¬¹¥»÷Õß±ØÐè±¾µØµÇ½µ½ÏµÍ³È»ºóÔËÐÐÌØÖÆµÄÓ¦ÓóÌÐò²ÅÄÜÀûÓÃÕâ¸ö©¶´¡£
¸Ã´úÂëΣº¦¼«´ó,¿ÉÒÔÔ¶³Ì»ñµÃ¼ÆËã»úµÄÈ«²¿È¨ÏÞ¶ø¸ÃµçÄÔÖ»ÒªÁ¬½Óµ½INTELNET»òÕß¾ÖÓòÍøÄÚ¼´¿É,»¹¿ÉÒÔÖÆ×÷ZotobÀàËÆ²¡¶¾,ÇëÎðʹÓøôúÂë´ÓÊ·Ƿ¨»î¶¯!
×¢ÒâÈç¹û²»²ÉÈ¡·À»¤´ëÊ©,¼´Ê¹Ê²Ã´¶¼Ã»ÓÐ×öÒ²»áÖж¾Í¬Õðµ´²¨Ò»Ñù!
ÌáÐÑ´ó¼ÒÉý¼¶É±¶¾Èí¼þ,¼°Ê±´òºÃϵͳ²¹¶¡
¸Ã´úÂëΣº¦¼«´ó,¿ÉÒÔÔ¶³Ì»ñµÃ¼ÆËã»úµÄÈ«²¿È¨ÏÞ¶ø¸ÃµçÄÔÖ»ÒªÁ¬½Óµ½INTELNET»òÕß¾ÖÓòÍøÄÚ¼´¿É,»¹¿ÉÒÔÖÆ×÷ZotobÀàËÆ²¡¶¾,ÇëÎðʹÓøôúÂë´ÓÊ·Ƿ¨»î¶¯!
×¢ÒâÈç¹û²»²ÉÈ¡·À»¤´ëÊ©,¼´Ê¹Ê²Ã´¶¼Ã»ÓÐ×öÒ²»áÖж¾Í¬Õðµ´²¨Ò»Ñù!

ÏÈ·æÌáÐÑ´ó¼ÒÉý¼¶É±¶¾Èí¼þ,¼°Ê±´òºÃϵͳ²¹¶¡
³§É̲¹¶¡£º
Microsoft

MicrosoftÒѾ­Îª´Ë·¢²¼ÁËÒ»¸ö°²È«¹«¸æ£¨MS05-039£©ÒÔ¼°ÏàÓ¦²¹¶¡:
MS05-039£ºVulnerability in Plug and Play Could Allow Remote Code Execution and Elevation of Privilege (899588)
Á´½Ó£ºhttp://www.microsoft.com/technet/security/Bulletin/MS05-039.mspx£¿pf=true
²¹¶¡ÏÂÔØ£º
Microsoft Windows 2000 Service Pack 4 ¨C ÏÂÔØ¸üУº
http://www.microsoft.com/downloads/details.aspx£¿displaylang=zh-cn&FamilyID=E39A3D96-1C37-47D2-82EF-0AC89905C88F
Microsoft Windows XP Service Pack 1ºÍMicrosoft Windows XP Service Pack 2 ¨C ÏÂÔØ¸üУº
http://www.microsoft.com/downloads/details.aspx£¿displaylang=zh-cn&FamilyID=9A3BFBDD-62EA-4DB2-88D2-415E095E207F
²¡¶¾·ÖÎö±¨¸æ.

²¡¶¾ÆÀ¹À
1£®²¡¶¾Ó¢ÎÄÃû£ºWorm.Zotob
2£®²¡¶¾ÀàÐÍ£ºÈ䳿²¡¶¾ ÿ
3£®²¡¶¾Î£Ïյȼ¶£º¡ï¡ï¡ï¡î
4£®²¡¶¾´«²¥Í¾¾¶£ºÍøÂç
5£®²¡¶¾ÒÀÀµÏµÍ³£ºWIN 2000/XP/2003
¶þ¡¢²¡¶¾ÆÆ»µ
1£®Ôì³ÉϵͳƵ·±ÖØÆô
µ±²¡¶¾¹¥»÷ʧ°ÜµÄʱºò£¬»áÔì³ÉϵͳƵ·±ÖØÆô¡£

2¡¢¸øÏµÍ³¿ªÉèºóÃÅ
3¡¢ÐÞ¸ÄϵͳÎļþ£¬Ê¹Óû§µÄɱ¶¾Èí¼þ²»ÄÜÉý¼¶¡£
Èý¡¢¼¼Êõ·ÖÎö
Ò»µ©Ö´ÐÐ,²¡¶¾½«Ö´ÐÐÒÔϲÙ×÷:
1. ²¡¶¾Æô¶¯ºó£¬»á½«×Ô¼º¸´ÖƵ½ÏµÍ³Ä¿Â¼ÖУ¬²¡¶¾ÎļþÃûΪ¡°botzor.exe¡±¡£

2¡¢ÔÚ×¢²á±íÖÐÌí¼ÓÏÂÁÐÆô¶¯Ï
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Currentversion\Run
WINDOWS SYSTEM = botzor.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Currentversion\RunServices
WINDOWS SYSTEM = botzor.exe; ¬×
3¡¢ÔÚ¸ÐȾµÄʱºò£¬²¡¶¾ÀûÓÃIPɨÃèµÄ·½Ê½ÔÚÍøÂçÖÐѰÕÒ¾ßÓЩ¶´µÄϵͳ£¬·¢ÏÖºó¾Í»á¶Ôϵͳ½øÐй¥»÷£¬Á¬½ÓϵͳµÄ445¶Ë¿Ú£¬²¢Ö²ÈëϵͳÖÐÒ»¸öÔ¶³ÌSHELL£¬´ËÔ¶³ÌSHELLÊÍ·ÅÒ»¸öÎļþ 2PAC.TXT£¬´ËÎļþÖаüº¬ÓÐÒ»¶ÎFTPÃüÁî½Å±¾£¬¹¦ÄÜÊÇÀûÓÃFTP´ÓÔ¶³Ì½«²¡¶¾ÎļþÏÂÔØµ½±¾µØ¡£
4¡¢Èç¹û¹¥»÷ʧ°Ü£¬ÔòÔì³ÉÏµÍ³ÖØÆô¡£
5¡¢ÐÞ¸ÄϵͳµÄhostÎļþ£¬Ìí¼ÓÈçÏÂÄÚÈÝ£º


http://www.fcbu.com/article/pc/xl/cl14107.shtm
¿ÉÄÜÄãµÄ»úÆ÷Àï³ÌÐò±»±ðÈ˶ñÒâÀ¦°óÁ˱ðµÄ´úÂëËùµ¼ÖÂ.
֨װQQ»òÊÇÖØ×°ÏµÍ³
¿¨°ÍÊDz»ÄÜɱľÂíµÄ¡£¡£
µ½ÕâÀï¿´¿´£ºhttp://forum.ikaka.com/topic.asp?board=28&artid=6999439&page=3
²»Öª¶ÔÄãÊÇ·ñÓÐÓÃ

 Ïà¹ØÎÊÌâ
¡¤ÏµÍ³×ÜÊÇ×Ô¶¯ÖØÆô¶¯
¡¤¿ª»úÌáʾCÅÌϵÄztdll.dllÖÐÓС±trojan/psw.lineage.ve\"...
¡¤Downloader.Small.brbÊÇʲô²¡¶¾°¡¡£ÎÒɱ²»ÁË¡£¸ßÊÖ°ïæ¡£
¡¤Òª½ðɽ¶¾°Ô2006Ãâ·ÑÉý¼¶µÄÅóÓÑÁôÏÂe_mail£¬Ö»Îª½»ÅóÓÑ
¡¤DÅÌË«»÷´ò²»¿ª,ÈðÐÇɱ¶¾Èí¼þ¸öÈË·À»ðǽ´ò²»¿ª,Ð¶ÔØºó֨װ...
¡¤Ewido²¡¶¾É¨ÃèÎÊÌâ
¡¤²¡¶¾²»»áËÀ»Ò¸´È¼°É
¡¤EwidoɨÃèÎÊÌâ
¡¤ÓÃÈðÐÇÔÚÏßɱ¶¾£¬¼¸ºõÿÌ춼ɱ³ötrojan.dlµÈľÂí²¡¶¾£¬Îª...
¡¤ÎªÊ²÷áÎÒÓÿ¨°Í˹»ù²éÁËһϻӲÅ̺óËùÓÐÓ¦ÓóÌÐò¶¼²»...
¡¤WINDOWSϵÄTEMPÀïµÄ²¡¶¾
¡¤ÓйØ[¿¨¿¨ÉÏÍø°²È«ÖúÊÖ]µÄʹÓÃÒÉÎÊ```
¡¤WINDOWSϵÄTEMPÀïµÄ²¡¶¾£¨Ã»·ÖÁ˶Բ»Æð£©
¡¤ÃÜÂëÍüÁË
¡¤É¾³ýKV-Back.virµÄºó¹ûÊÇʲô£¿

 ¡¶ÏµÍ³×ÜÊÇ×Ô¶¯ÖØÆô¶¯¡·´ð°¸ÊÕ¼¯Ê±¼ä£º2006-08-24 20:02:58



©2007 µçÄÔ¼¼ÊõÎÊ´ð¼