Netexpert FAQ 网络分析专家学习建议入口 @netexpert成员申请指南
netexpert积分规则的说明 Netis招贤纳士(2008年11月22日更新)
发新话题
打印

backdoor.berbew.n病毒请教

backdoor.berbew.n病毒请教

前段时间,单位局域网整个网络中病毒(98没事),在个人客户机上安装的金山网彪显示服务器在传送大量的震荡波病毒过来.服务器操作系统是xp,服务器开机如果断开网络使用,一切正常.但一联网,c盘下面windows32下面的一个cjicaj.exe的文件就会访问网络,这个文件版本0.0.0 .但用查找命令找寻不到这个文件,这个时候cpu使用率就一直100%,上网也上不起,偶尔还会出现还有60秒的自动关机.用震荡波专杀工具查杀到一个.最后又用诺顿查到十多个毒,其中在cjicaj.exe这个文件上查到一个backdoor.berbew.n 的病毒,诺顿不能杀只能隔离,在隔离区里将这个文件删除,这个时候打了补丁,安了防火墙,上网正常.但局域网内部的病毒没有查杀.请问这个病毒是不是震荡波.这个时候是星期五,到星期六上网ok.星期天的时候有人把服务器系统重新格式化,把诺顿也格了,然后没打震荡波补丁,没安防火墙,星期一把内部网接通,内部可以上.今天星期二,服务器又不能上了,这个时候cpu使用率不再是100%,但仍不时要60秒重起,重用诺顿装起,升级后断网查毒,又在c盘下面windows32下面的fob.exe和xxxxx.exe找到这个backdoor.berbew.n病毒,隔离后重起又显示需要关机,把隔离的文件删除重起后再查就没找到了.上网正常.补丁打了很多个,但不知道是不是针对这个backdoor.berbew.n请教各位大虾,了解这个病毒吗?对这个病毒最好的解决方法是什么,小弟在此万分感谢了

TOP

"backdoor.berbew.n"是一个木马程序,它能够窃取密码,降低IE的安全性设置,并打开后门让远程攻击者获取未授权的访问权限。
手动清除:
除了用Norton进行病毒扫描,删除病毒文件外,还要修复注册表
Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad


In the right pane, delete the values:

"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
"[6 random characters]" = "{7D3D8457-D853-43D1-069A-CD62C9EB6465}"


Navigate to and delete the following keys:

HKEY_CLASSES_ROOT\CLSID\(79FEACFF-FFCE-815E-A900-316290B5B738}
HKEY_CLASSES_ROOT\CLSID\{FA036593-9D63-4219-FFBA-EFD0D828B737}


Navigate to and delete the following keys:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\"KKQHOOK" = "0x18"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ndisrd


Exit the Registry Editor.

最后恢复IE的安全等级
To reset the security settings in Internet Explorer:

Open Internet Explorer.

Click Tools> Internet Options > Security

Reset the security levels

Click Apply

Click OK

Exit Internet Explorer

详细信息请见Norton网站:http://securityresponse.symantec ... kdoor.berbew.n.html

TOP

Backdoor.Berbew.N is a Trojan horse program that steals cached passwords from a compromised computer. The Trojan also opens a back door allowing a remote attacker to have unauthorized access to the compromised computer, and may lower security settings in Internet Explorer.


Removal Instrctions:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Berbew.N.
Delete the value that was added to the registry.
Reset the security levels in Internet Explorer.

For specific details on each of these steps, read the following instructions.

1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:
"How to disable or enable Windows Me System Restore"
"How to turn off or turn on Windows XP System Restore"

Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, re-enable System Restore by following the instructions in the aforementioned documents.

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article, "Antivirus Tools Cannot Clean Infected Files in the _Restore Folder," Article ID: Q263455.


2. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the Virus Definitions (LiveUpdate).
Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater).

The Intelligent Updater virus definitions are available: Read "How to update virus definition files using the Intelligent Updater" for detailed instructions.


3. To scan for and delete the infected files
Start your Symantec antivirus program and make sure that it is configured to scan all the files.
For Norton AntiVirus consumer products: Read the document, "How to configure Norton AntiVirus to scan all files."
For Symantec AntiVirus Enterprise products: Read the document, "How to verify that a Symantec Corporate antivirus product is set to scan all files."
Run a full system scan.
If any files are detected as infected with Backdoor.Berbew.N, click Delete.

Note: If your Symantec antivirus product reports that it cannot delete an infected file, Windows may be using the file. To fix this, run the scan in Safe mode. For instructions, read the document, "How to start the computer in Safe Mode." Once you have restarted in Safe mode, run the scan again.

(After the files are deleted, you can leave the computer in Safe mode and proceed with section 4. When that is done, restart the computer in Normal mode.)


4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad


In the right pane, delete the values:

"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
"[6 random characters]" = "{7D3D8457-D853-43D1-069A-CD62C9EB6465}"


Navigate to and delete the following keys:

HKEY_CLASSES_ROOT\CLSID\(79FEACFF-FFCE-815E-A900-316290B5B738}
HKEY_CLASSES_ROOT\CLSID\{FA036593-9D63-4219-FFBA-EFD0D828B737}


Navigate to and delete the following keys:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\"KKQHOOK" = "0x18"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ndisrd


Exit the Registry Editor.


5. To reset the security settings in Internet Explorer:

Open Internet Explorer.

Click Tools> Internet Options > Security

Reset the security levels

Click Apply

Click OK

Exit Internet Explorer

TOP

TOP

发新话题
版块跳转