中华网数码

设为书签Ctrl+D将本页面保存为书签,全面了解最新资讯,方便快捷。
业 界/ 互联网/ 行 业/ 通 信/ 数 码/ 手 机/ 平 板/ 笔记本/ 相 机
当前位置: 数码 > 滚动新闻 >

winlogon.exe怎么解决?解决方法及查杀流程

winlogon.exe怎么解决?解决方法及查杀流程
2020-11-30 14:45:24 来源:45IT

这只鸽子提示:中招后,贴日志求助的日子即将结束!做好系统基础安全防护是每个用户的当务之急。“基础安全防护”绝不仅仅是打几个补丁的问题。熟悉一两个性能好的安全软件的使用也是必要的。否则,中招后,你自己就着急吧!

这只鸽子的要害是c:\windows\winlogon.dll。

如果用SSM禁止c:\windows\winlogon.dll加载运行,则这只鸽子的文件全部可见。

这是Movgear.exe中捆绑的一只灰鸽子(Movgear.exe样本来自安全12公里)。winlogon.exeMD5值为:2de9f62c2b405e16cb66773747cf0f2d。

一、自Movgear.exe中提取winlogon.exe并将其植入系统后,autoruns、HijackThis、SREng日志中均无任何异常发现。

winlogon.exe释放的文件有:

1、c:\windows\winlogon.exe

2、c:\windows\winlogon.dll

3、c:\windows\winlogonKey.dll

这两个dll插入IE浏览器进程。

即使不打开IE浏览器,IceSword的进程列表中依然可见iexplore.exe。

c:\windows\winlogonKey.dll动态跟踪所有应用程序进程(一旦开启,立即插入。)

注意:即使显示隐藏文件,用WINDOWS的资源管理器也看不到灰鸽子释放的这三个文件。用IceSword才能看到。

二、注册表改动包括:

1、在HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

添加:winlogon.exe(指向c:\windows\winlogon.exe)

2、在HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping

添加:

"{92780B25-18CC-41C8-B9BE-3C9C571A8263}"=dword:00002002

"{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}"=dword:00002002

"{FB5F1910-F110-11d2-BB9E-00C04F795683}"=dword:00002001

3、在HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Connection Wizard

添加:"Completed"=hex:01,00,00,00

4、在HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser

添加:

"ITBarLayout"=hex:11,00,00,00,5c,00,00,00,00,00,00,00,34,00,00,00,1f,00,00,00,56,\

00,00,00,01,00,00,00,20,07,00,00,a0,0f,00,00,05,00,00,00,62,05,\

00,00,26,00,00,00,02,00,00,00,21,07,00,00,a0,0f,00,00,04,00,00,\

00,21,01,00,00,a0,0f,00,00,03,00,00,00,20,03,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"=hex:81,45,e0,01,ee,4e,d0,11,bf,e9,00,aa,00,5b,43,83,10,00,00,00,00,\

00,00,00,01,e0,32,f4,01,00,00,00

"{0E5CBF21-D15F-11D0-8301-00AA005B4383}"=hex:21,bf,5c,0e,5f,d1,d0,11,83,01,00,aa,00,5b,43,83,22,00,1c,00,08,\

00,00,00,06,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,\

00,00,4c,00,00,00,01,14,02,00,00,00,00,00,c0,00,00,00,00,00,00,\

46,81,00,00,00,10,00,00,00,a0,8f,ff,ba,9d,d4,c6,01,00,9e,02,bb,\

9d,d4,c6,01,a0,8f,ff,ba,9d,d4,c6,01,00,00,00,00,00,00,00,00,01,\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,5d,01,14,00,1f,50,\

e0,4f,d0,20,ea,3a,69,10,a2,d8,08,00,2b,30,30,9d,19,00,2f,43,3a,\

5c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,5c,\

00,31,00,00,00,00,00,3a,31,09,3c,10,00,44,4f,43,55,4d,45,7e,31,\

00,00,44,00,03,00,04,00,ef,be,3a,31,9c,36,2a,35,f7,29,14,00,00,\

00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,73,00,20,00,\

61,00,6e,00,64,00,20,00,53,00,65,00,74,00,74,00,69,00,6e,00,67,\

00,73,00,00,00,18,00,4c,00,31,00,00,00,00,00,2a,35,cb,2e,16,00,\

4e,45,54,57,4f,52,7e,31,00,00,34,00,03,00,04,00,ef,be,3a,31,11,\

39,2a,35,cb,2e,14,00,00,00,4e,00,65,00,74,00,77,00,6f,00,72,00,\

6b,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,18,00,56,\

00,31,00,00,00,00,00,2a,35,cb,2e,11,00,46,41,56,4f,52,49,7e,31,\

00,00,3e,00,03,00,04,00,ef,be,2a,35,cb,2e,2a,35,cb,2e,14,00,28,\

00,46,00,61,00,76,00,6f,00,72,00,69,00,74,00,65,00,73,00,00,00,\

40,73,68,65,6c,6c,33,32,2e,64,6c,6c,2c,2d,31,32,36,39,33,00,18,\

00,30,00,35,00,00,00,00,00,2a,35,f1,2e,10,00,fe,94,a5,63,00,00,\

1c,00,03,00,04,00,ef,be,2a,35,f1,2e,2a,35,f1,2e,14,00,00,00,fe,\

94,a5,63,00,00,14,00,00,00,60,00,00,00,03,00,00,a0,58,00,00,00,\

00,00,00,00,6c,69,6e,62,61,6f,68,65,00,00,00,00,00,00,00,00,1e,\

8c,63,4d,34,72,b3,48,8a,de,83,67,8f,38,be,10,b1,a9,fd,89,90,40,\

db,11,b2,29,00,d0,59,c0,b8,59,1e,8c,63,4d,34,72,b3,48,8a,de,83,\

67,8f,38,be,10,b1,a9,fd,89,90,40,db,11,b2,29,00,d0,59,c0,b8,59,\

00,00,00,00

5、在HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState

添加:"Settings"=hex:0c,00,02,00,0a,01,ef,75,60,00,00,00

6、在HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\

添加:

{0055C089-8582-441B-A0BF-17B458C2A3A8}

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

{92780B25-18CC-41C8-B9BE-3C9C571A8263}

{AE7CD045-E861-484F-8273-0445EE161910}

{DEDEB80D-FA35-45D9-9460-4983E5A8AFE6}

{FB5F1910-F110-11D2-BB9E-00C04F795683}

7、在HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\链接

添加:"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00

三、进行上述观察后,重启系统。

重启后,卡巴斯基报警(我的卡巴斯基为启动加载):发现灰鸽子。但卡巴斯基仅仅将c:\windows\winlogon.dll删除;c:\windows\winlogon.exe和c:\windows\winlogonKey.dll卡巴斯基并不报毒。汗!!卡巴斯基越来越不争气了另外发现其winlogonKey.log文件。

四、查杀流程:

1、打开注册表编辑器,展开HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

删除灰鸽子的服务项:winlogon.exe

2、重启系统。用IceSword找到并删除鸽子释放的那三个文件。

4、清理注册表(删除鸽子添加的注册表项)。

10月31日更新

查杀方法..

安全模式下操作.

删除文件

C:\Downloads

C:\WINDOWS\system32\AddrConfig.bin

C:\WINDOWS\system32\oobe\data

C:\WINDOWS\system32\wbem\ddes

C:\WINDOWS\system32\wbem\kbd101ab.dll

C:\WINDOWS\system32\wbem\SysOption.bin

C:\WINDOWS\system32\wbem\winlogon.exe

删除注册表

HKCR\CLSID\{881F6F06-4620-4070-AD05-BD77D4C56661}

HKCR\Interface\{468262B9-8400-4A49-B2E5-CE8550EB1347}

HKCR\TypeLib\{F63B08CD-3645-474F-8872-BA4293251FF9}\1.0

HKCR\VCFIWZDY32.VCFIWZDY

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\System32\WBEM\winlogon.exe

HKCU\Software\Microsoft\MediaPlayer\Player\Extensions

重启回正常模式即可..

责任编辑:kj005

文章投诉热线:156 0057 2229 投诉邮箱:29132 36@qq.com
关键词:

北斗三号核心器件国产化率达到100%,80%新入网手机已支持

2020-11-27 10:52:58北斗三号核心器件国产化率达到100%,80%新入网手机已支持

目前中国移动建成开通5G基站38.5万个

2020-11-26 13:58:44目前中国移动建成开通5G基站38.5万个

戴尔发布第三财季财报:净利润同比增长60%

2020-11-26 10:28:03戴尔发布第三财季财报:净利润同比增长60%

2020年第三季度财报:小米手机出货量4660万部 同比增长45.3%

2020-11-25 10:00:292020年第三季度财报:小米手机出货量4660万部 同比增长45.3%

Q3小米大涨34.9%冲上全球第三 华为位列第二

2020-11-24 10:10:39Q3小米大涨34.9%冲上全球第三 华为位列第二

长江存储已位列全球闪存第七 产能占比已经达到全球1%

2020-11-20 10:00:20长江存储已位列全球闪存第七 产能占比已经达到全球1%

相关新闻