Problems raised and symptoms: Recently encountered this web site (4255.biz), inadvertently it's recruit, and then whenever access to other sites, will be downloaded from 4255.biz data, and other sites can not download the complete, not normal access, depressed for a long time, especially with the framework of the site simply can not come out.
(This picture is for Norton's poison and processing results)
Analysis: (This analysis content is c.i.s.r.t. Blog Small mo Excerpt)
When you open the Web page, you can see three malicious URLs:
001.htm use is the ms07-017 loophole of the net horse;
002.htm use is the ms06-014 loophole of the net horse;
003.htm Downloads ccc.html (In fact, a CHM document).
The purpose of all three is to run the virus itself. Virus size 15,620 bytes, upack shell, MD5 value for B1e2f5ec9e3b42e8142b3335625f2579,kaspersky detection for VIRUS.WIN32.DELF.BL
Step one: Patch the Vulnerability (MS06-014 and ms07-017 vulnerabilities). Their download address:
ms06-014 Vulnerability Patch Download address: http://www.microsoft.com/china/technet/security/bulletin/MS06-014.mspx
ms07-017 Vulnerability Patch Download address: http://www.microsoft.com/china/technet/security/bulletin/MS07-017.mspx
If the above connection can not download the installation, may not download the installation of piracy, it is recommended to use 360 security guards for download installation. Under
Step two: Turn off System Restore, use 360 security guards to clean IE temporary files, system temporary files (malicious software/plug-ins are also cleaned out).
Step three: Use the Trojan Horse force the removal tool to delete the following files:
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.