Question and Symptom: I recently encountered this website (iis5.biz) and accidentally tried it. When I access other websites, I will download data from ipv5.biz, other websites cannot be downloaded completely and cannot be accessed normally. It has been depressing for a long time, especially for websites with frameworks.
(This figure shows the Norton report and processing result)
Analysis: (The analysis content is extracted from the C. I. S. R. T. Blog)
After opening the webpage, You can see three malicious urls:
001.htm is used to MS07-017 vulnerability network horse;
002.htm is used to MS06-014 vulnerability network horse;
003.htmwill download ccc.html (actually a CHM document ).
The purpose of these three methods is to run the virus itself. Virus size: 15,620 bytes, upack shelling, MD5 value: b1e2f5ec9e3b42e8142b3335625f2579, Kaspersky Detection: virus. win32.delf. Bl
Generated after running
% WINDOWS % \ System \ logo_1.exe
% WINDOWS % \ System \ mciwace. inc
% WINDOWS % \ System \ mciwace. DRV
Will download a non-EXE document:
Http://35623.com/upwina.exe
Solution:
Step 1: patch the Vulnerability (MS06-014 and MS07-017 vulnerabilities ). Their:
MS06-014 vulnerability patch: http://www.microsoft.com/china/technet/security/bulletin/MS06-014.mspx
MS07-017 vulnerability patch: http://www.microsoft.com/china/technet/security/bulletin/MS07-017.mspx
If the above connection cannot be downloaded and installed (it may be pirated and cannot be downloaded and installed, we recommend that you use 360 security guard to download and install it. Lower
Step 2: Disable System Restoration and use 360 security guard to clear temporary ie files and temporary system files (remove malicious software/plug-ins as needed ).
Step 3: Use the fair Trojan force-delete tool to delete the following files:
Code:
WINDOWS \ SYSTEM \ logo_1.exe
WINDOWS \ SYSTEM \ mciwace. inc
WINDOWS \ SYSTEM \ mciwace. DRV
WINDOWS \ SYSTEM \ ieframe. dll
Step 4: Use anti-virus software of the latest virus database to thoroughly scan and kill Hard Disks
For LAN users, it is recommended to download antiarp (arpfirewall) for processing.