VIRUS GIẢ TẬP TIN ẢNH


1.Giới thiệu


- Gần đây, trên các thiết bị lưu trữ di động xuất hiện một con sâu máy tính mới(worm) giả dạng là một tập tin ảnh và đứng bên cạnh một tập tin autorun.inf có nội dung đáng ngờ.


webtretho


webtretho


2.Cách sâu “bò” vào máy tính


- Nếu người dung tò mò double-click vào con sâu tự động nhân bản vào mỗi thư mục gốc và các thư mục hệ thống.



%DriveLetter%\winfile.jpg


%DriveLetter%\autorun.inf


- Khi virus thực thi, nó sẽ tải về máy tính nạn nhân một con Trojan backdoor có tên là winxp.exe để tấn công máy tính người dùng từ xa. Sau đó, nó thêm các key trong registry để khởi động Trojan winxp.exe khởi động cùng Window


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"CTFMON" = "%System%\wscript.exe /E:vbs %System%\winjpg.jpg"


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"CTFMON" = "%System%\wscript.exe /E:vbs %System%\winjpg.jpg"


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"abu salem" = "43 00 3A 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 57 00 53 00 5C 00 73 00 79 00 73 00 74 00 65 00 6D 00 33 00 32 00 5C 00 77 00 69 00 6E 00 78 00 70 00 2E 00 65 00 78 00 65 00"



- Virus thay đổi key trong registry để có thể hoạt động ngầm mà người dùng không hề hay biết


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwwinxp.exe"Debugger" = "%System%\winxp.exe"


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSConfig.exe"Debugger" = "%System%\wscript.exe /E:vbs %System%\winjpg.jpg"


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe"Debugger" = "\winxp.exe"


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe"Debugger" = "%System%\wscript.exe /E:vbs %System%\winjpg.jpg"


- Cuối cùng, nó đổi thêm một vài key làm giảm tính bảo mật của hệ thống


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings"Enabled" = "1"


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center"AntiVirusOverride" = "1"


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL"CheckedValue" = "1"


HKEY_USERS\S-1-5-21-1110976373-127614085-1323839693-500\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"NoDriveTypeAutoRun" = "0"



3.Kết luận


- Mức độ nguy hiểm tiềm năng của con sâu này rất lớn. Chính vì vậy, người dùng nên xóa các tập tin ảnh có nguồn gốc không rõ ràng. Thường xuyên cập nhật danh sách virus mới và quét thiết bị lưu trữ trước khi sử dụng


(tham khảo bài viết của chuyên gia bảo mật David Curra)