Webpage Browsing is infected with viruses, and Webpage Browsing is infected with Trojans. Do you believe this? Someone used this technology to launch attacks about half a year ago! Malicious Code So far, there are no virus firewalls that can effectively prevent malicious code attacks. Most of them cannot even be found.
PC news this year's 25 th Edition D4 introduced a website called gohip, which can modify the default web site of the browser and direct it to the gohip website. In fact, this is quite polite. If you go to a website called "Wan Hua Gu", you will feel gohip is "benevolent.
1. Personal Experience
No alert is reported when you enter the website when you open a variety of virus firewalls, And the mouse slows down immediately. When you leave the website, countless new IE Windows suddenly pop up, close all windows with "Alt + F4" immediately, and then press WIN 98 to report an error. Pressing "CTRL + ALT + DEL" does not respond.ProgramBut a blue screen or crash immediately appeared. Restart the machine and the following message appears: "Welcome to Wanhua Valley. If you are in the" Wanhua virus ", contact QQ: 4040465." click "OK" to go to win 98, however, the desktop is empty. Click the "Start" menu and you will find that "shutdown" and "run" are all gone. The problem persists when you restart the machine again.
Ii. Solution
If you are not careful, you can use the following three methods to solve the problem:
Method 1:
1. When disk A is started, find the C: directory in the DOS environment (Note: The sysbckup directory is a hidden attribute. You should first use the attrib command to remove the hidden attribute). You can find rb000.cab ~ Rb004.cab: these five files are the most recent five registry backup files. Copy them from rb004.cab.
2. Decompress rb004.cab on another machine and copy the four files to C: to overwrite the original files.
3. Start the computer in safe mode, run msconfig, find ha. HTA in the "Start" tab, and remove "√" in front of the multiple selection boxes.
4. Restart the machine. Everything is OK.
Method 2: Use the scanreg/restore registry in DOS, and then delete ha. HTA from the Startup Group.
Method 3: Use the "Super Rabbit" system software or "Windows optimization master" to restore the system.
Super Rabbit can restore the permission settings for Windows. Open the IE icon on the shortcut bar (because the system has locked "Resource Manager", you can also run the "Search" function ).
Enter the target disk in the IE Address Bar, for example, "E: u8221,find the Super Rabbit, and open “ms98.exe ". First, click "Advanced hide" in the tool options, remove the hook before "C:" in the hidden disk bar, and then click "desktop and icon ", add a check in front of the "display icon on the desktop" option. After saving, click "security and multi-user" to remove the text in the "title to be displayed at startup" and "information to be displayed at startup" columns. Click "ie 4/5" in the tool options, remove the text in the "ie title" column, and save the text. OK!
In particular, when the page is opened, it automatically changes the browser's hosts page. Therefore, you must modify the hosts page of the browser after changing to Windows Settings, otherwise, the web page will be displayed next time.
Iii. Preventive measures:
1. Do not go to sites you do not know easily.
2. Disable ActiveX plug-ins, controls, and Java scripts in iesettings. In the IE window, click "Tools> Internet Options", select the "Security" tab in the pop-up dialog box, and then click "Custom Level, the "Security Settings" dialog box is displayed. Select "Disable" for all ActiveX plug-ins, controls, and Java-related items. In Win 2000, disable the Remote Registry Service in the service. You can click "Administrative Tools> services> Remote Registry Service (Allow Remote registry operation)" to disable this option.
3. Since "Wan Hua Gu" destroys our system by modifying the registry, we can lock the registry and disable the modification of the registry to prevent it.
The locking method is as follows:
(1.exe run the registration table editor regedit.exe;
.
The unlock method is as follows:
Use NotePad to edit a. reg file with any name, such as unlock. Reg. The content is as follows:
Regedit4
[HKEY_CURRENT_USER] "disableregistrytools" = DWORD: 00000000
Save the disk and exit. To use the Registry Editor, double-click "unlock. Reg. Note that there must be a blank line after "regedit4", and there must be no space between "4" and "T" in "regedit4"; otherwise, the previous achievements will be abandoned!
4. for all users, you can upgrade to the latest kvw3000 virus database and enable the kvw3000 virus firewall when accessing the internet to prevent such malicious webpage attacks (Note: The virus database must be a virus database after January 1, June 28 ).
Editor's note: in the previous period, we introduced the "Wanhua Valley" virus attack and defense war. In fact, there are still many similar websites on the Internet. As long as there are websites with new viruses, we have the obligation to inform everyone. If you have a network security article, please send a xiongjie@cpcw.com mailbox, we will be the fastest practicalArticlePublished.
1. Personal Experience
When you enter the trojan webpage, the mouse turns into an hourglass shape. It seems that a program is running. Open the task manager of the computer and check that there is another wincmd.exe process. The process file is C \ winnt \ wincmd.exe in Win2000 and C \ windows \ wincmd.exe in Win98.
Run the Registry Editor regedit and find wincfg.exeunder "HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ currentverion \ run.pdf". In the original example, the register will be registered in the startup Item of the registration table. In this example, wincmd.exe will be automatically run every time. ()
Note: You can set the startup key and registration file name of the Trojan by yourself. The registration file name is also the name in the runtime. Therefore, the results may be different.
Run Kingsoft drug overlord, the report found that "backdoor bnlite”, Oh, the original MoMA bnliteservice end was renamed as winw..exe. Although this Trojan server program is not large (only 6.5 k), it has many functions: ICQ reporting, remote server deletion, port setting and running name, upload and download ...... If you get this trojan, the trojan control end can use this Trojan to create a hidden FTP server on your computer, and others will have the maximum permission to access your computer! In this way, it will be very easy to control your computer!
How does a trojan download it to a computer that browses the home page and runs it? Continue is downloaded and running! It seems that this is irrelevant to ActiveX. In the custom security level list, all the objects with the specified file downloaded are forbidden. Then, you can view the webpage. In this case, winwinmtr .exe will not download any more.
Ii. Problem Discovery
Let's take a look at how wincmd.exe downloads to the viewer's computer. Right-click the page and choose ViewSource code", Suspicious statements are found at the end of the webpage code:
<IFRAME src = wincfg. eml width = 1 Height = 1>
Have you noticed "wincfg. eml? Everyone knows that EML is in the mail format. What do EML files need on webpages? Suspicious! In the IE browser, enter: http // response! Since the problem lies in this file, of course you have to find a way to get this file. Attackers can download the file and click the mouse to execute wincmd.exe again!
Open wincfg. eml and find the key content as follows:
Content-Type audio/X-WAV name={win}.exe"★The file name is defined here as wincmd.exe
Content-transfer-encoding base64★The code format is base64.
Content-id <The-CID>★This is the beginning of the Code.
Tvqqaamaaaaeaaaa // 8aal ...... Delete the following section★This is the base64 encoded content of wincmd.exe.
"★. This base64-formatted file will be compiled and run as a wincmd.exe file when you browse the Web page. This is why Trojans are generated when you browse the Web page! So far, I understand that, in fact, the so-called trojan in Web browsing is only a case where web creators use the vulnerabilities in Microsoft's IE browser to launch attacks, to put it bluntly, the mimemultipurpose Internet Mail Extentions and multi-purpose Internet Mail Extension protocol headers are used to launch attacks.
3. Truth and truth
Now, let's go back and see what the trojan is. In fact, the wincfg.exefile is equivalent to the attachment of the mail. We can see from the code in Our column that the attacker defines the type of WinSock .exe as audio/X-WAV, because the mail type is audio/Trojan (Trojan) and is executed. In Win2000, even if you click the downloaded wincfg with the mouse. eml, or copy and paste the file, will cause wincfg. the attachment in EML is running. Microsoft's vulnerability is really harmful. It seems that the old attackers tried to cheat the target and execute modified Trojan Horse and other backdoor programs! How simple and easy it is to take advantage of the big vulnerability Microsoft has created! The only condition is that the target uses ie5.0 or a later version. How many Internet Explorer users are there? Look at your friends and you will know the answer!
Iv. Solution
1. Click Start> Run. In the displayed dialog box, enter regedit and press Enter. Then, expand the Registry to "HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ run”to Delete wincmd.exe;
2. Delete the wincmd.exe file in the system directory of your computer;
3. Restart the machine and everything is OK!
5. Preventive measures
1. IE and Outlook users.
1. in IE's "Tools> Internet Options> Security Level of the Internet region", change the security level from "medium" to "high ".
2. Click "Custom Level". In the displayed window, disable the "script execution for ActiveX controls marked as secure script execution", "activity script", and "File Download" functions.
3. Disable all ActiveX Control and plug-ins.
4. Set the resource manager to "always display extension ".
5. You are not allowed to use the resource manager on the web.
6. Cancel the extension property setting "download and confirm to open.
2. Don't be tempted by strangers to open the URL provided by others. If you really want to see it, you can download the page through some download tools, and then use Notepad and other text editing tools to open and view the code.
3. Microsoft has provided a patch for the vulnerability. Go to the URL listed below and check it out!