---------------------------------- teYqiu【天下无毒】原创文章,转载请标明。http://hi.baidu.com/teyqiu 百度知道反病毒知识专家崔衍渠 授权。 『转载请保留此申明!』 ----------------------------------
本文的眼:IFEO劫持 比比皆是...
实战案例
问题:某同事WL,今天告诉我他的卡巴斯基启动不了,CAD也起不来。过去一看,发现很多EXE点击无反应,即使改成.com后缀也不行。一下就想到了 IFEO劫持,打开注册表一看(还好丫的没屏蔽regedit.exe),蔚为壮观,稍微有些名气的都挂了...如卡巴、瑞星、360safe等,hijackthis.exe也不能幸免。。
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR] "Debugger"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO\\CFEDAC5E.dat"
既然普通的删除工具不管用,只有祭出 XDELBOX, CMD下:C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSINFO用ATTRIB看到有两个 SHR 属性的文件,CFEDAC5E.dll和CFEDAC5E.dat。
操作部分:使用XDELBOX先填入这两个(CFEDAC5E.dll和CFEDAC5E.dat),立即重启后删除,发现 SRENG [1] [2] 下一页 |