ÄúÏÖÔÚµÄλÖ㺠ÐÇÔÆµçÄԽ̳̠>> µçÄԽ̳̠>> ÍøÂ簲ȫ >> ÕýÎÄ

services.exeµ¹¼ÆÊ±1·ÖÖӹػú

ÐÇÔÆµçÄÔ½Ì³Ì ÎÄÕÂÀ´Ô´£ºÍøÂç ×÷ÕߣºÐÇÔÆ ¸üÐÂʱ¼ä£º2006-6-20 15:38:50 µã»÷Êý ¡¾ ÓÐÎʱش𠡿

¡¡¡¡×òÌìÍíÉÏ¿ª»ú²»µ½Ò»Ð¡Ê±£¬´ò¿ªÁ˼¸¸ö²»ÖªÃûµÄÐ¡ÍøÕ¾£¬¹ýÁËÒ»»á£¬·¢ÏÖIEÊ²Ã´ÍøÕ¾¶¼´ò²»¿ªÁË£¬QQ»¹¿ÉÒÔÕý³£ÔËÐУ¡Í¬Ê±·¢ÏÖ¿ªÊ¼ÖеÄֻʣÏÂÁË¡°É趨³ÌÐò·ÃÎʺÍĬÈÏÖµºÍWindows Update¡±ÕâÁ½¸öÁË£¬´ò¿ª¿¨°Í˹»ùɱ¶¾Èí¼þ·¢Ïֺܶ๦ÄÜÒ²²»ÄÜÕý³£ÏÔʾ£¬windowsÈÎÎñ¹ÜÀíÆ÷´ò¿ªºó·¢ÏÖÐÔÄÜÕâ¸öÀ¸Ä¿Ê²Ã´Ò²²»ÄÜÏÔʾ£¬ÕâÑùµÄÎÊÌ⻹ÊǵÚÒ»´Î¼ûµ½£¬Ö»ºÃÖØÐÂÆô¶¯µçÄÔ£¬Ö»ÓÐÇ¿Ðйػú£¡
¡¡¡¡½á¹ûÈÃÈ˺ÜʧÍû£¬¿ª»úÂíÉϳöÏÖµ¹¼ÆÊ±1·ÖÖӹػú£¡
¡¡¡¡ÌáʾC:\windows\system32\services.exe ²»ÄÜÓ㬴úÂë0
¡¡¡¡ÐҺõçÄÔÉÏ×öÁËghost±¸·Ý£¡
½ñÌìÔÚÍøÉÏÕÒÁËһϹØÓÚÕâÑùµÄÎÊÌ⣬°ÑËûÃÇÕûÀíÈçÏ£º

Services.exe

ÎÒÐÂ×°µÄwin2000sp4 £¬ÔÚÉÏÍøÉý¼¶É±¶¾Èí¼þÒÔºó×÷ÁËghost ¾µÏñ±¸·Ý¡£ÔÚÉÏÍøºó³öÏÖµçÄÔËÀ»ú£¬ÖØÆôºó³öÏÖϵͳ×Ô¶¯¹Ø»ú(60Ãë)£º±¨´íΪ £ºC:/WINNT/system32/services.exe    ´íÎó´úÂë128¡£ÎÒÒÔΪÊÇϵͳ©¶´ËùÖ²¡¶¾¸ÐȾ£¬ÓÚÊÇÓÃghostÆô¶¯ÅÌÖØÐ»ָ´ÏµÍ³¡£È»ºóÓÖ¿ÉÒÔÕý³£Ê¹ÓÃÁË£¬ÉÏÍøÏÂÔØÁË2000µÄ²¹¶¡³ÌÐò¡£¹ýÁËÒ»Õó×ÓÓÖ³öÏÖÉÏÊöµÄ´íÎó£¬×Ô¶¯¹Ø»ú£¬ÎÒÔÙÓÃghost»Ö¸´£¬»¹ÊÇÉÏÍøÒ»Õó×ÓÓÖ³öÏÖͬÑùµÄ´íÎ󡣲鿴ע²á±í£¬²»ÏñÊÇÕñµ´²¨²¡¶¾¸ÐȾ£¬Óý«Ãñɱ¶¾Ò²Ã»Óá£Çë¸ßÊÖ°ï°ï棬ÎÒ¸ÃÔõô°ìÄØ£¿Ð»Ð»

 
8ÔÂ15ÈÕ,½ðɽ·´²¡¶¾Ó¦¼±´¦ÀíÖÐÐĽػñÒ»¸öÕë¶Ô΢ÈíϵͳÑÏÖØÂ©¶´½øÐÐÖ÷¶¯¹¥»÷µÄ²¡¶¾£¬²¢ÃüÃûΪZotob(Worm.Zotob.A)¡£½ðɽµÄ·´²¡¶¾×¨¼Ò˵£¬Zotob²¡¶¾ÀûÓé¶´Ö÷¶¯´«²¥£¬¶ÔÓÚ¸öÈ˵çÄÔµÄΣº¦·Ç³£´ó£¬ÆäΣº¦³Ì¶ÈÓëµ±ÄêµÄÕðµ´²¨ÏàËÆ£¬Ò»µ©±»¹¥»÷£¬Óû§µÄµçÄÔ½«»á³öÏÖ²»¶ÏÖØÆô¡¢ÏµÍ³²»Îȶ¨µÈÇé¿ö¡£²¡¶¾×÷Õß½ÐÏùɱµôÕâ¸ö²¡¶¾µÄɱ¶¾Èí¼þ½«ÓÚ24СʱÄÚ±»½Ëɱ£¡
ZotobÀûÓÃ5Ììǰ΢Èí¸Õ¸Õ¹«²¼µÄÑÏÖØÏµÍ³Â©¶´£¬Windows Plug and Play ·þÎñ©¶´ (MS05-039)£¬ ¹¥»÷TCP¶Ë¿Ú445£¬ºÍ³å»÷²¨¡¢Õðµ´²¨·½·¨ÀàËÆ£¬¹¥»÷´úÂëÏòÄ¿±êϵͳµÄ445¶Ë¿Ú·¢ËÍ©¶´´úÂ룬ʹĿ±êϵͳÔì³É»º³åÇøÒç³ö£¬Í¬Ê±ÔËÐв¡¶¾´úÂ룬½øÐд«²¥¡£  ¡¡¡¡²¡¶¾¹¥»÷Ä¿±êϵͳʱ£¬¿ÉÄÜÔì³Éϵͳ²»¶ÏÖØÆô£¬ÓëÕðµ´²¨¡¢³å»÷²¨·¢×÷µÄʱºòÀàËÆ£¬Ö»²»¹ýÔÚZotobÓ°ÏìµÄ½ø³Ì±äÁË£¬±äΪϵͳ¹Ø¼ü½ø³Ì¡°Service.exe¡±£¬ ZotobÆäʵÊÇMytobµÄ×îбäÖÖ¡£MytobÊÇǰһÕó´óËÁ·ºÀĵÄÓʼþ²¡¶¾¡£´Ë´Î±äÖÖ£¬¸üÊǼÓÈëÁË5Ììǰ²Å¹«²¼Â©¶´²¹¶¡µÄϵͳÑÏÖØÂ©¶´£¨windows Plug and Play ·þÎñ©¶´ (MS05-039) £©½øÐÐÖ÷¶¯¹¥»÷£¬Ê¹Æä´ó´óÌá¸ßÁ˲¡¶¾´«²¥µÄ¹ã¶È¡£Òò´Ë£¬Zotob³ýÁËÀûÓé¶´¹¥»÷Í⣬»¹¾ßÓÐÓʼþ´«²¥¡¢×Ô¶¯ÏÂÔØÐ²¡¶¾µÈµÈÕâЩÓëÓʼþ²¡¶¾Ëù¾ßÓеÄΣº¦£¬Ê¹Öж¾Óû§ÔâÊÜ´ò»÷¡£
²¡¶¾ÔËÐк󣬽«ÔÚϵͳĿ¼Ï´´½¨botzor.exeÎļþ,´óСΪ22528×Ö½Ú¡£ÔÚ×¢²á±íÖÐÌí¼ÓÏÂÁÐÆô¶¯Ï
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]  "WINDOWS SYSTEM" = botzor.exe ÿ; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\windows\CurrentVersion\RunService

"windows SYSTEM" = botzor.exe
ÕâÑù£¬ÔÚwindowsÆô¶¯Ê±£¬²¡¶¾¾Í¿ÉÒÔ×Ô¶¯Ö´ÐС£
¡°¼«ËÙ²¨¡±²¡¶¾Í¨¹ýTCP¶Ë¿Ú8080Á¬½ÓIRC·þÎñÆ÷£¬½ÓÊܲ¢Ö´ÐкڿÍÃüÁî¡£¿Éµ¼Ö±»¸ÐȾ¼ÆËã»ú±»ºÚ¿ÍÍêÈ«¿ØÖÆ¡£²¢ÔÚTCP¶Ë¿Ú33333¿ªÆôFTP·þÎñ£¬Ìṩ²¡¶¾ÎļþÏÂÔØ¹¦ÄÜ¡£ÀûÓÃ΢Èí¼´²å¼´Ó÷þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨MS05-039£©½øÐд«²¥¡£Èç¹û©¶´ÀûÓôúÂë³É¹¦ÔËÐУ¬½«µ¼ÖÂÔ¶³ÌÄ¿±ê¼ÆËã»ú´Óµ±Ç°±»¸ÐȾ¼ÆËã»úµÄftp·þÎñÉÏÏÂÔØ²¡¶¾³ÌÐò¡£Èç¹û©¶´´úÂëûÓгɹ¦ÔËÐУ¬Î´´ò²¹¶¡µÄÔ¶³Ì¼ÆËã»ú¿ÉÄÜ»á³öÏÖservices.exe½ø³Ì±ÀÀ£µÄÏÖÏó¡£
¸Ã²¡¶¾µÄΣº¦»¹ÔÚÓÚ£¬²¡¶¾»áÐÞ¸Ä%SystemDir%\drivers\etc\hostsÎļþ£¬ÆÁ±Î´óÁ¿¹úÍâ·´²¡¶¾ºÍ°²È«³§É̵ÄÍøÖ·¡£²¢¶Ô·´²¡¶¾³§ÉÌÌá³ö¹«¿ªÌôÕ½£ºµÚÒ»¸ö·¢Ïֵķ´²¡¶¾Èí¼þ ½«ÔÚ24СʱÄÚÔâµ½¡°½Ëɱ¡±¡££¨MSG to avs: the first av who detect this worm will be the first killed in the next 24hours!!!£©

Ó°Ïìϵͳ£º
Microsoft windows XP SP2
Microsoft windows XP SP1
Microsoft windows Server 2003 SP1
Microsoft windows Server 2003
Microsoft windows 2000SP4
Microsoft windows¼´²å¼´Óã¨PnP£©¹¦ÄÜÔÊÐí²Ù×÷ϵͳÔÚ°²×°ÐÂÓ²¼þʱÄܹ»¼ì²âµ½ÕâЩÉ豸¡£
Microsoft windows¼´²å¼´Óù¦ÄÜÖдæÔÚ»º³åÇøÒç³ö©¶´£¬³É¹¦ÀûÓÃÕâ¸ö©¶´µÄ¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£
ÆðÒòÊÇPnP·þÎñ´¦Àí°üº¬Óйý¶àÊý¾ÝµÄ»ûÐÎÏûÏ¢µÄ·½Ê½¡£ÔÚWindows 2000ÉÏ£¬ÄäÃûÓû§¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆÏûÏ¢À´ÀûÓÃÕâ¸ö©¶´£»ÔÚWindows XP Service Pack 1ÉÏ£¬Ö»ÓÐͨ¹ýÈÏÖ¤µÄÓû§²ÅÄÜ·¢ËͶñÒâÏûÏ¢£»ÔÚWindows XP Service Pack 2ºÍwindows Server 2003ÉÏ£¬¹¥»÷Õß±ØÐè±¾µØµÇ½µ½ÏµÍ³È»ºóÔËÐÐÌØÖÆµÄÓ¦ÓóÌÐò²ÅÄÜÀûÓÃÕâ¸ö©¶´¡£
¸Ã´úÂëΣº¦¼«´ó,¿ÉÒÔÔ¶³Ì»ñµÃ¼ÆËã»úµÄÈ«²¿È¨ÏÞ¶ø¸ÃµçÄÔÖ»ÒªÁ¬½Óµ½INTELNET»òÕß¾ÖÓòÍøÄÚ¼´¿É,»¹¿ÉÒÔÖÆ×÷ZotobÀàËÆ²¡¶¾,ÇëÎðʹÓøôúÂë´ÓÊ·Ƿ¨»î¶¯!
×¢ÒâÈç¹û²»²ÉÈ¡·À»¤´ëÊ©,¼´Ê¹Ê²Ã´¶¼Ã»ÓÐ×öÒ²»áÖж¾Í¬Õðµ´²¨Ò»Ñù!
ÌáÐÑ´ó¼ÒÉý¼¶É±¶¾Èí¼þ,¼°Ê±´òºÃϵͳ²¹¶¡
¸Ã´úÂëΣº¦¼«´ó,¿ÉÒÔÔ¶³Ì»ñµÃ¼ÆËã»úµÄÈ«²¿È¨ÏÞ¶ø¸ÃµçÄÔÖ»ÒªÁ¬½Óµ½INTELNET»òÕß¾ÖÓòÍøÄÚ¼´¿É,»¹¿ÉÒÔÖÆ×÷ZotobÀàËÆ²¡¶¾,ÇëÎðʹÓøôúÂë´ÓÊ·Ƿ¨»î¶¯! ¥`
×¢ÒâÈç¹û²»²ÉÈ¡·À»¤´ëÊ©,¼´Ê¹Ê²Ã´¶¼Ã»ÓÐ×öÒ²»áÖж¾Í¬Õðµ´²¨Ò»Ñù!
ÏÈ·æÌáÐÑ´ó¼ÒÉý¼¶É±¶¾Èí¼þ,¼°Ê±´òºÃϵͳ²¹¶¡
³§É̲¹¶¡£º
  Microsoft
MicrosoftÒѾ­Îª´Ë·¢²¼ÁËÒ»¸ö°²È«¹«¸æ£¨MS05-039£©ÒÔ¼°ÏàÓ¦²¹¶¡:
MS05-039£ºVulnerability in Plug and Play Could Allow Remote Code Execution and Elevation of Privilege (899588)
Á´½Ó£º[url]http://www.microsoft.com/technet/security/Bulletin/MS05-039.mspx?pf=true[/url] 0>
²¹¶¡ÏÂÔØ£º
Microsoft windows 2000 Service Pack 4 ¨C ÏÂÔØ¸üУº
[url]http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&FamilyID=E39A3D96-1C37-47D2-82EF-0AC89905C88F[/url]
Microsoft Windows XP Service Pack 1ºÍMicrosoft windows XP Service Pack 2 ¨C ÏÂÔØ¸üУº
[url]http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&FamilyID=9A3BFBDD-62EA-4DB2-88D2-415E095E207F[/url]

 
ʹÓÃÍøÂç·À»ðǽ£¬»òÊÇʹÓÃIP°²È«²ßÂÔÆÁ±Îס445¶Ë¿Ú¼´¿É£¡

 
Õâ¸öÎÊÌâ½üÆÚ³öÏֱȽ϶࣬ÎÒÕâÀïÔÝʱ»¹Ã»ÕÒµ½ºÜÓÐЧµÄ°ì·¨
Ö»ÄÜÆ¾¿ÕÌἸ¸ö½¨Ò飺
1¡£±£Ö¤É±¶¾Èí¼þµÄ¼°Ê±¸üÐÂ
2¡£±£Ö¤ÏµÍ³²¹¶¡µÄÍêÕû
3¡£¹Øµô²»³£ÓöøÓÖÓÐΣÏյķþÎñ£¬¸ù¾ÝÇé¿ö×ÔÐе÷Õû
4¡£¹ØµôһЩΣÏÕ¶Ë¿ÚÈç135 137 138 139 445µÈ¶Ë¿Ú£¨¿ÉʹÓÃһЩ·À»ðǽÀ´¶¨Ò壩
5¡£µÇ½µÄadministrators×éµÄÕʺţ¬°ÑÃÜÂë¸øÉèÖÃÉÔ¸´ÔÓЩ£¨Èõ¿ÚÁî»ò¿Õ¿ÚÁî·Ç³£ÈÝÒ×±»¹¥»÷£©

ËùÄÜ˵µÄÒ²Ö»ÓÐÕâô¶àÁË£¬Ï£ÍûÄܾ¡¿ìÕÒµ½½â¾ö°ì·¨

¿ÉÄÜÊÇϵͳ²»ÄÜÉý¼¶£¬ÖÐÁË×è»÷²¨¡£¿ì´òÉϲ¹¶¡£¬ÏÖÔÚÓеÄɱÈíÒѾ­³öרɱ¹¤¾ßÁË¡£

>>