TrojanHunter vs. the Parasitic Beast Trojan
Trojan Hunter大战寄宿型木马“野兽” The Beast - Employing Modern Stealth Techniques “野兽”,采用新型隐藏方式的木马 The Beast is a relatively new trojan which in recent versions has used more advanced techniques to make itself undetectable from trojan and virus scanners. The latest technique employed makes the trojan parasitic, because it injects its code into other processes running on the system. For this purpose, the trojan uses a DLL file named dxgns.dll.
野兽是近来采用更多高级隐藏技术以使得自身无法被防病毒&防木马软件侦测到的新型木马。因为其将自身代码注入到系统其他进程,该木马具有了寄生性,为了达到该目的,该木马用到了一个名为dxgns.dll的dll文件。 To study this trojan, let's see what happens when it is run on a typical Windows XP Home system. A quick analysis after starting the trojan reveals that it injects itself into the following two processes: winlogon.exe and explorer.exe. These two processes are always present on a Windows XP system (in fact they are present on any NT-based system), which is why the trojan injects itself into those processes. You can see from the screenshots below that the injected trojan library is running inside the infected processes.
为了研究该木马,我们来看看它是如何在常见的xp系统上运行的。快速分析后我们发现,该木马把自身进程注入到这两个进程中:winlogon.exe和explorer.exe。这两个进程是xp系统中的常见进程(事实上,在所有NT内核的系统中都可以看到这两个进程),这也是为什么该木马要把自己注入这两个进程的原因。我们来看下面的截图
Process Injection - A Dangerous New Trend
Recent trojans have begun using process injection to a greater extent. Several factors make this technique dangerous:
The trojan is not visible in traditional process viewers, including Windows Task Manager
Most trojan and virus scanners have a very hard time detecting the running trojan code
The trojan code is very difficult to unload
进程注入:一个危险的趋势
新近的木马越来越多的用到进程注入的方式,许多事实表明,该技术具有很大的危险性: 木马进程是隐藏的,无法被诸如windwos任务管理器等进程查看器发现 绝大多数反病毒&反木马软件很难发现运行的木马代码 木马的代码很难被清除 How TrojanHunter Cleans the Trojan
TrojanHunter is the only trojan scanner on the market that is able to clean parasitic trojans. Other scanners will leave the user stranded or might even incorrectly kill the legitimate host processes, with devastating effects as a result (terminating winlogon.exe will crash the operating system). TrojanHunter cleans parasitic trojans by actually working inside the infected process to kill all trojan threads and then unload the loaded trojan libraries. After this, the trojan library can safely be cleaned by TrojanHunter as with any other trojan file, while the previsouly infected process can continue executing as if nothing had happened.
The screenshot below shows TrojanHunter diasbling the Beast trojan. Note that no reboot is necessary. Other trojan scanners would either not have detected the trojan, or, if detected, wouldn't have been able to clean the trojan - leaving the user with little choice but to reformat or hire an expensive computer technician to remove the trojan from the system.
Trojan Hunter如何清除该木马 Trojan Hunter是市面上唯一可以清除寄生型木马的反木马软件。(PS:王婆卖瓜,自卖自夸),其他反木马软件在处理寄生型木马的时候可能会使使用者感到无助甚至会不正确的结束宿主进程,从而带来破坏性的后果(结束winlogon.exe会导致系统崩溃),而Trojan Hunter可以在分析被感染进程的信息后,清除木马注入的代码,从而安全的删除该木马,保证先前被感染的进程别来无恙。 下面的截图展示了Trojan Hunter如何废掉了beast木马,请注意,重新启动是必须的。其他反病毒软件无法侦测,或者即使能够侦测,也无法完美清除该木马,导致用户无奈的格式化或掏腰包请专业技术人员来清除该木马(超级王婆!)
[ 本帖最后由 柳如斯 于 2008-12-29 11:23 编辑 ] |