返回列表 回复 发帖

poolmc.exe,photo38.JPG-www.myspace.com等恶意病毒清除解决方案

超级巡警团队监测到随着广大网友开始正常的工作,MSN蠕虫又开始扩散。它会给MSN上的好友发送名字中带有photo字样的附件。
超级巡警团队提醒广大用户不要轻易下载并运行利用MSN传播的程序。
一、病毒相关分析:
      病毒标签:
        病毒名称:Backdoor.Win32.IRCBot.gen
        病毒别名:MSN蠕虫
        病毒类型:蠕虫
        危害级别:3
        感染平台:Windows
        病毒大小:78,848(字节)
        SHA1  :c69509ab0a8108c2c48eb9589735d4be51ed26d5
        加壳类型:EXECryptor
        开发工具:VC
     病毒行为:
        1、复制自身为%System%\poolmc.exe
           生成文件:%temp%\photo*.zip
           //压缩包中文件为picture*.JPG-www.myspace.com (*代表同一随机数字)
           //压缩包中文件与poolmc.exe为同一文件
        2、连接以下域名:
           www.timbercreeksoftware.com
           www.massiverender.com
           01.cybernix.info
           下载文件:
           http://www.massiverender.com/*****/p3.exe    //与poolmc.exe为同一文件
        3、添加注册表启动项:
           [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
           "Windows Pool Setup"="poolmc.exe"
    4、下载文件:http://www.timbercreeksoftware.com/regdata/eng.txt
           文件内容如下:
           u want to see something really funny? look at this lol
           have you seen this new picture of me?
           do you like this picture of me?
           new party pictures :)
           You want to see something very funny? accept this haha
           Do you like sexyness? accept this and you will know!
           want to see my new pics? accept this
           I just found this nasty pic.. you need to see this haha
           let me introduce you to my newest friend :) accept the pic
           New myspace pics here
           New facebook pics accept ;]
           this person looks like you
           look at my new profile pic
           watch out.. this picture im sending you is so nasty!
           do I look good with this mix?
           Hello! would you like to see my new picture?
           did I send you my new pic? if not here it is :)
           this picture is so amazing I cannot believe this
           have you seen the newest iphone? its so amazing check it out
           would you like me to add our picture to facebook?
           can I add your picture to my Myspace albums?
           checkout the newest faster car.. it is incredible!
           do I look good in this picture?
           checkout my new shirt I just got :)
           This is my newest webcam.. tell me what you think of it
           I have an old picture of you...want it? here it is!
           dont freakout when you see this picture
           dont scream when you see this picture lol
           dont kill me for sending you this picture, you must see it!
           haha this picture of you is so funny!
           I'm sending you my new photo accept it
           Hi, remember this picture of you ?
           You look so sexy in this picture
           do you like dogs? look at my new dog!
           can I add this picture of us to my new blog?
           This is so hot I want it badly look!
           I got a new car!! look at the pics!
           checkout my latest acquisition hehe
           do you know this person on this picture? I think you do
           I think you will faint when you see this pic
           I was so drunk at this party.. check it out lol
           I can't believe I am in this picture look!
           haha you're gonna laugh hard when you see this
           checkout the newest fastest car
           I took this pic in my vacation:)
           this is so nasty...
           I love this watch I think im buying it
           I look so fat in this pic :(
           your mom in this picture lol
           I like this picture of you a lot
           并根据在文件中随机选择语句发送给MSN好友,同时发送压缩包文件photo*.zip  //*为随机数字




二、解决方案
    推荐方案:安装超级巡警进行全面病毒查杀。超级巡警用户请升级到最新病毒库,并进行全盘扫描。
           超级巡警下载地址:http://www.dswlab.com/d1.html

    手工清除方法:
         1、结束病毒进程。打开超级巡警,选择进程管理功能,终止poolmc.exe进程。
         2、删除病毒生成的文件。
         3、删除病毒的启动项。打开超级巡警,选择启动管理,删除名为"Windows Pool Setup"的启动项。
         4、建议用户使用超级巡警的恶意网站屏蔽功能屏蔽本文中提到的域名。
返回列表