命名對照
江民防毒 TrojanSpy.Delf.aud
瑞星Trojan.PSW.Win32.ZhengTu.yku
金山毒霸 Win32.Troj.OnlineGames.yi.81920
a-squared Trojan-PSW.Win32.OnLineGames.ejq
AntiVir TR/PSW.OnlineGames.ejq
行為分析
修改註冊表:
增加啟動項目
HKEY_LOCAL_MACHINE\SOF.TWARE\Microsoft\Windows\CurrentVersion\
Explorer\ShellExecuteHooks ""
Type: REG_SZ
Data: rsztcpm.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
CurrentVersion\Windows "AppInit_DLLs"
Old type: REG_SZ
New type: REG_SZ
Old data:
New data: rsztcpm.dll
關閉系統自動升級
HKEY_LOCAL_MACHINE\SOF.TWARE\Policies\Microsoft\Windows\
WindowsUpdate\AU "AUOptions"
Type: REG_DWORD
Data: 01, 00, 00, 00
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\
WindowsUpdate\AU "NoAutoUpdate"
Type: REG_DWORD
Data: 01, 00, 00, 00
關閉WINDOWS防火牆
HKEY_LOCAL_MACHINE\SYSTEM\.ControlSet001\Services\SharedAccess\
Parameters\FirewallPolicy\StandardProfile "EnableFirewall"
Type: REG_DWORD
Data: 00, 00, 00, 00
釋放檔案:
c:\WINDOWS\Fonts\gezeand.fon
Date: 10-16-20.07 6:44 PM
Size: 93 bytes
c:\WINDOWS\system32\rsztafg.dll
Date: 10-16-2007 6:44 PM
Size: 53 bytes
c:\WINDOWS\system32\rsztcpm.dll
Date: 8-4-2004 6:44 PM
Size: 23,122 bytes
c:\WINDOWS\system32\rsztcsp.exe
Date: 10-16-2007 6:42 PM
Size: 15,366 bytes
解決方案:
c:\WINDOWS\Fonts.\gezeand.fon
c:\WINDOWS\system32\rsztafg.dll
c:\WINDOWS\system32\rsztcpm.dll
c:\WINDOWS\system32\rsztcsp.exe
—刪除註冊表—
HKEY_LOCAL_MACHINE\SY.STEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU "AUOptions"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU "NoAutoUpdate"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
{rsztcpm.dll} []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
ShellExecuteHooks]
{}{C:\WINDOWS\system32\rsztcpm.dll} []