病毒名称(中文):
魔兽晕眩盗号者107664
病毒别名:
威胁级别:
★☆☆☆☆
病毒类型:
偷密码的木马
病毒长度:
107664
影响系统:
Win9xWinMeWinNTWin2000WinXPWin2003
病毒行为:
这是一个针对网络游戏《魔兽世界》的盗号木马。它通过篡改注册表中的相关数据实现启动,并强行关闭部分常见安全软件的进程,以便接下来可以顺利盗取游戏账号。
盗号木马,盗取系统上的网络游戏《魔兽世界》的帐号信息.
通过注册表AppInit_DLLs启动,同时向该值写入大量病毒dll.
结束某些安全软件进程.
病毒运行释放以下病毒文件:
%systemroot%\system32\eohsom.cfg
%systemroot%\system32\eohsom.dll
%systemroot%\system32\drivers\mselk.sys
枚举系统所有进程,结束进程名为"Wow.exe"进程.(结束正在运行的网络游戏《魔兽世界》的游戏进程)
删除系统上"%systemroot%\system32\mseion.sys"和"%systemroot%\system32\drivers\mselk.sys"两个文件.(存在则删除)
加载病毒文件"%systemroot%\system32\eohsom.dll".
判定病毒文件当前注入的进程是否为以下进程,如是则结束进程:
360Tray.exe
360Safe.exe
killer_Gdwli32.exe
QQDoctor.exe
QQDoctorMain.exe
AntiArp.exe
查找窗口类名"Q360SafeMainClass"和"360AntiarpClass",找到则结束进程.
病毒会获取"Wow.exe"进程的文件路径,读取该路径下的"launcher2.ini"文件,如发现该文件中包含字符"wowchina.com",则对该进程盗号操作,把盗取所得的帐号信息发送至指定的接收网址.
病毒创建注册表:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msert
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msertStartdword:00000002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msertImagePathhex(2):73,79,73,74,65,6d,33,32,5c,64,72,69,76,65,72,73,5c,6d,73,65,6c,6b,2e,73,79,73,00,
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msertDisplayName"msert"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msertDescription"msert"
病毒修改注册表:
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows
Value:"AppInit_DLLs"
BeforeData:""
AfterData:"bauhgnem.dll,eohsom.dll,fyom.dll,sauhad.dll,ijougiemnaw.dll,taijoad.dll,lnaixnauhqq.dll,idtj.dll,vhqq.dll,atgnehz.dll,rsqq.dll,tsqc.dll,vauyiqvlnaix.dll,wQ.dll,fmxh.dll,cty.dll,pahzij.dll,jz.dll,bz.dll,pyomielnux.dll,mhtd.dll,qnefnaib.dll,ej.dll,uixauh.dll,hjiq.dll,kiluw.dll,dsfg.dll,yqhs.dll,oaijihzeuyouhz.dll,jemnaw.dll,cuhad.dll,laixuhz.dll,rfhx.dll,mnauygniqaixnaij.dll,oqnauhc.dll,xjxr.dll,utiemnaw.dll,sve.dll,wininat.dll,gnolnait.dll,zadnew.dll,htwx.dll,knaixnauhuoyizqq.dll,duygnef.dll,gmx.dll,nadgnohiac.dll,agzg.dll,qlihzouhgnfe.dll,bchib.dll,tzm.dll,xhtd.dll,QQ.dll,sfhx.dll,gnaixnauhqq.dll,3auhad.dll,oadnew.dll,iemnaw.dll,qcsct.dll,oadgnohiac.dll,iqnauhc.dll,aixauh.dll,ddtj.dll,nuygnef.dll,uohsom.dll,gnefnaib.dll,ijiq.dll,hjxr.dll,naijoad.dll,naixuhz.dll,nahzij.dll,fmxh.dll,zqhs.dll,jsfg.dll,utgnehz.dll,uyom.dll,wtiemnaw.dll,uyomielnux.dll,vlihzouhgnfe.dll,2ty.dll,nauhgnem.dll,auhad.dll,rj.dll,hz.dll,naijihzeuyouhz.dll,xhqq.dll,jmx.dll,dgzg.dll,gsqq.dll,fz.dll,gnaixnauhuoyizqq.dll,gnolnait.dll,jsqc.dll,dqncj.dll,eve.dll,2nauygniqaixnaij.dll,niluw.dll,ijougiemnaw.dll,wtwx.dll,jghf.dll,msd.dll,asj.dll,her.dll,awf.dll"