²é¿´: 732  |  »Ø¸´: 5
µ±Ç°Ö÷ÌâÒѾ­´æµµ¡£
µ±Ç°Ö»ÏÔʾÂú×ãÖ¸¶¨Ìõ¼þµÄ»ØÌû£¬µã»÷ÕâÀï²é¿´±¾»°ÌâµÄËùÓлØÌû

dbm1

Í­³æ (³õÈëÎÄ̳)

[½»Á÷] ¡¾·ÖÏí¡¿Õðµ´²¨²¡¶¾²¹¶¡£¡£¡for xp¡¾ÒÑËÑË÷ÎÞÖØ¸´¡¿

ÎÒ¹ú·¢ÏÖÐÂÐÍ¡°Õðµ´²¨¡±£¨Worm_Sasser£©

¡¡
   ¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄͨ¹ý¶Ô»¥ÁªÍøµÄ¼à²â£¬ÓÚ2004Äê5ÔÂ1ÈÕ·¢ÏÖÒ»ÖÖÀûÓÃ΢Èí½üÆÚ¹«²¼Â©¶´µÄÐÂÈ䳿²¡¶¾£¬ÎÒÃǽ«ÆäÃüÃûΪ¡°Õðµ´²¨¡±È䳿²¡¶¾£¬²¢Òѽӵ½½­ËÕ¡¢ÄþÏÄ¡¢±±¾©¡¢ºÚÁú½­¡¢ÁÉÄþºÍ¹ã¶«µÈµØÇøÓû§±¨¸æ¡£

   ¸Ã²¡¶¾ÀûÓÃÁËWindows LSASSµÄÒ»¸öÒÑ֪©¶´(MS04-011)£¬Õâ¸öÒ»¸ö»º³åÒç³ö©¶´£¬ºó¹ûÊÇʹԶ³Ì¹¥»÷ÕßÍêÈ«¿ØÖÆÊܸÐȾϵͳ¡£

  ²¡¶¾Ãû³Æ£º "Õðµ´²¨"²¡¶¾ Worm_Sasser
  ÆäËüÓ¢ÎÄÃüÃû£ºÔÝÎÞ
  ¸ÐȾϵͳ£ºWinNT/Win2000/WinXP/Win2003
  ²¡¶¾³¤¶È£º15872×Ö½Ú
¡¡²¡¶¾ÌØÕ÷£º

¡¡1¡¢Éú³É²¡¶¾Îļþ
¡¡¡¡¡¡¡¡
        ²¡¶¾ÔËÐкó£¬ÔÚ%Windows£¥Ä¿Â¼ÏÂÉú³É×ÔÉíµÄ¿½±´£¬Ãû³ÆÎªavserve.exe£¬Îļþ³¤¶ÈΪ15872×Ö½Ú£¬ºÍÔÚ%System%Ŀ¼ÏÂÉú³ÉÆäËü²¡¶¾Îļþ

ÀýÈç:

c:\win.log  : IPµØÖ·Áбí

c:\WINNT\avserve.exe  : È䳿²¡¶¾Îļþ±¾Éí

c:\WINNT\system32\11113_up.exe : ¿ÉÄÜÉú³ÉµÄÈ䳿Îļþ±¾Éí

c:\WINNT\system32\16843_up.exe : ¿ÉÄÜÉú³ÉµÄÈ䳿Îļþ±¾Éí


    2¡¢ÐÞ¸Ä×¢²á±íÏî
   
        ²¡¶¾´´½¨×¢²á±íÏʹµÃ×ÔÉíÄܹ»ÔÚϵͳÆô¶¯Ê±×Ô¶¯ÔËÐУ¬ÔÚ
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows  
    \CurrentVersion\RunÏ´´½¨
    "avserve"=¡±c:\WINNT\avserve.exe¡±

    3¡¢Í¨¹ýϵͳ©¶´Ö÷¶¯½øÐд«²¥

     ²¡¶¾Ö÷¶¯½øÐÐɨÃ裬µ±·¢ÏÖÍøÂçÖдæÔÚ΢ÈíSSL°²È«Â©¶´Ê±£¬½øÐй¥»÷£¬È»ºóÔÚÊܹ¥»÷µÄϵͳÖÐÉú³ÉÃûΪcmd.ftpµÄftp½Å±¾³ÌÐò£¬Í¨¹ýTCP¶Ë¿Ú5554ÏÂÔØÈ䳿²¡¶¾¡£

  4¡¢Î£º¦ÐÔ

ÊܸÐȾµÄϵͳ¿ÉÄÜËÀ»ú»òÕßÔì³ÉÖØÐÂÆô¶¯£¬Í¬Ê±ÓÉÓÚ²¡¶¾É¨ÃèA Àà»òBÀà×ÓÍøµØÖ·£¬Ä¿±ê¶Ë¿ÚÊÇTCP 445»á¶ÔÍøÂçÐÔÄÜÓÐÒ»¶¨Ó°Ï죬ÓÈÆä¾ÖÓòÍø¿ÉÄÜÔì³É̱»¾¡£²¢¿ÉÒÔÔÚTCP 9996¶Ë¿Ú´´½¨Ô¶³ÌShell¡£¸Ã²¡¶¾ÔÚ´«²¥ºÍÆÆ»µÐÎʽÉÏÓë¡°³å»÷²¨¡±²¡¶¾ÏàÀàËÆ¡£


     Çå³ý¸Ã²¡¶¾µÄÏà¹Ø½¨Ò飺
     
     1¡¢°²È«Ä£Ê½Æô¶¯      
      ¡¡¡¡ÖØÐÂÆô¶¯ÏµÍ³Í¬Ê±°´Ï°´F8¼ü£¬½øÈëϵͳ°²È«Ä£Ê½

  2¡¢×¢²á±íµÄ»Ö¸´

¡¡¡¡¡¡¡¡¡¡µã»÷"¿ªÊ¼--¡µÔËÐÐ"£¬ÊäÈëregedit,ÔËÐÐ×¢²á±í±à¼­Æ÷£¬ÒÀ´ÎË«
¡¡¡¡¡¡»÷×ó²àµÄHKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
¡¡¡¡¡¡CurrentVersion>Run £¬²¢É¾³ýÃæ°åÓÒ²àµÄ"avserve"="c:\winnt\avserve.exe"

¡¡3¡¢É¾³ý²¡¶¾ÊͷŵÄÎļþ

¡¡¡¡¡¡¡¡¡¡µã»÷"¿ªÊ¼--¡µ²éÕÒ--¡µÎļþºÍÎļþ¼Ð"£¬²éÕÒÎÄ¡¡¡¡¡¡
      ¼þ"avserve.exe"ºÍ"*_up.exe"£¬²¢½«ÕÒµ½µÄÎļþɾ³ý¡£

  4¡¢°²×°ÏµÍ³²¹¶¡³ÌÐò

µ½ÒÔÏÂ΢ÈíÍøÕ¾ÏÂÔØ°²×°²¹¶¡³ÌÐò£º

http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

»òÕßÔڣɣÅä¯ÀÀÆ÷µÄ¹¤¾ß£­>Windows UpdateÉý¼¶ÏµÍ³¡£

  5¡¢ÖØÐÂÅäÖ÷À»ðǽ

  ÖØÐÂÅäÖñ߽ç·À»ðǽ»ò¸öÈË·À»ðǽ¹Ø±ÕTCP¶Ë¿Ú5554ºÍ9996


ÖÐÎÄxp²¹¶¡ÏÂÔØ£ºhttp://download.microsoft.com/do ... B835732-x86-CHS.EXE

[ Last edited by ratio on 2008-11-30 at 14:43 ]
»Ø¸´´ËÂ¥
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

zzzzzza21

Í­³æ (СÓÐÃûÆø)

1

²Å·¢ÏÖ°¡ ÎҵĵçÄÔ5Ììǰ¾ÍÖÐÁË Ö§³ÖÏ ´ó¼ÒҪעÒâ°¡
3Â¥2004-05-03 22:05:35
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
²é¿´È«²¿ 6 ¸ö»Ø´ð

mummy

Ìú³æ (³õÈëÎÄ̳)

1

лл£¡£¡
ÎÒÖж¾°´ÕÕÉÏÊö·½·¨É±µôÁË£º£©
5Â¥2004-05-04 01:47:33
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
×î¾ßÈËÆøÈÈÌûÍÆ¼ö [²é¿´È«²¿] ×÷Õß »Ø/¿´ ×îºó·¢±í
[¿¼ÑÐ] 317Çóµ÷¼Á +3 Éê×ÓÉêÉê 2026-03-19 6/300 2026-03-19 14:16 by Éê×ÓÉêÉê
[¿¼ÑÐ] »¯Ñ§Çóµ÷¼Á +3 ÁÙÔó¾³llllll 2026-03-17 4/200 2026-03-19 13:59 by houyaoxu
[¿¼ÑÐ] 311Çóµ÷¼Á +4 ¶¬Ê®Èý 2026-03-18 4/200 2026-03-18 21:47 by ¾¡Ë´Ò¢1
[¿¼ÑÐ] Ò»Ö¾Ô¸Öйúº£Ñó´óѧ£¬ÉúÎïѧ£¬301·Ö£¬Çóµ÷¼Á +4 1ËïÎò¿Õ 2026-03-17 4/200 2026-03-18 17:59 by fivewind
[¿¼ÑÐ] 297Çóµ÷¼Á +8 Ï·¾«µ¤µ¤µ¤ 2026-03-17 8/400 2026-03-18 14:30 by laoshidan
[¿¼ÑÐ] 0854£¬¼ÆËã»úÀàÕÐÊÕµ÷¼Á +3 ºúÀ±ÌÀ·ÅÌÇ 2026-03-15 6/300 2026-03-18 12:09 by Éϰ¶Éϰ¶¡­¡­..
[¿¼ÑÐ] ÉúÎïѧ071000 329·ÖÇóµ÷¼Á +3 ÎÒ°®ÉúÎïÉúÎﰮΠ2026-03-17 3/150 2026-03-18 10:12 by macy2011
[¿¼ÑÐ] 290Çóµ÷¼Á +6 ¿×Ö¾ºÆ 2026-03-12 11/550 2026-03-17 14:41 by ÖÜÖÛÖÛ77
[¿¼ÑÐ] 302Çóµ÷¼Á +4 С¼Öͬѧ123 2026-03-15 8/400 2026-03-17 10:33 by С¼Öͬѧ123
[¿¼ÑÐ] 11408 Ò»Ö¾Ô¸Î÷µç£¬277·ÖÇóµ÷¼Á +3 zhouzhen654 2026-03-16 3/150 2026-03-17 07:03 by laoshidan
[¿¼ÑÐ] 304Çóµ÷¼Á +5 ËØÄê¼ÀÓï 2026-03-15 5/250 2026-03-16 17:00 by ÎҵĴ¬Îҵĺ£
[¿¼ÑÐ] 070300»¯Ñ§Ñ§Ë¶Çóµ÷¼Á +6 Ì«Ïë½ø²½ÁË0608 2026-03-16 6/300 2026-03-16 16:13 by kykm678
[¿¼ÑÐ] Ò»Ö¾Ô¸»ªÖÐʦ·¶071000£¬325Çóµ÷¼Á +6 RuitingC 2026-03-12 6/300 2026-03-16 14:50 by ¿Éµ­²»¿ÉÍü
[¿¼ÑÐ] 0703»¯Ñ§µ÷¼Á 290·ÖÓпÆÑо­Àú£¬ÂÛÎÄÔÚͶ +7 ÄåÄågk 2026-03-14 7/350 2026-03-16 10:12 by houyaoxu
[¿¼ÑÐ] 327Çóµ÷¼Á +6 ʰ¹âÈÎȾ 2026-03-15 11/550 2026-03-15 22:47 by ʰ¹âÈÎȾ
[¿¼ÑÐ] 289Çóµ÷¼Á +4 ÕâôÃû×ÖÕ¦Ñù 2026-03-14 6/300 2026-03-14 18:58 by userper
[¿¼ÑÐ] Ò»Ö¾Ô¸¹þ¹¤´ó²ÄÁÏ324·ÖÇóµ÷¼Á +5 ãÆÐñ¶« 2026-03-14 5/250 2026-03-14 14:53 by ľ¹Ï¸à
[¿¼ÑÐ] 330Çóµ÷¼Á +3 ?½´¸øµ÷¼Á¹òÁË 2026-03-13 3/150 2026-03-14 10:13 by JourneyLucky
[¿¼ÑÐ] 0856²ÄÁÏÓ뻯¹¤301Çóµ÷¼Á +5 ÞÈÊø¹â 2026-03-13 5/250 2026-03-13 22:00 by ÐÇ¿ÕÐÇÔÂ
[¿¼ÑÐ] 311Çóµ÷¼Á +3 ¶¬Ê®Èý 2026-03-13 3/150 2026-03-13 20:41 by JourneyLucky
ÐÅÏ¢Ìáʾ
ÇëÌî´¦ÀíÒâ¼û