免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 8623 | 回复: 3
打印 上一主题 下一主题

关于iexplore.exe [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2003-03-07 16:26 |只看该作者 |倒序浏览
那天bingbing提到iexplore.exe,我当时还真以为把iexplore.exe错看成iexplorer.exe了,今天同事的norton发现iexplore.exe有病毒,仔细看了一下才发现原来IE就是iexplore.exe,真是笨死了.

发现带病毒的文件是\winnt\system32\iexplore.exe, 而不是\program files\internet explorer\iexplore.exe, 并且防毒软件对它既不能清除也不能隔离, 所以处理办法是:
1.搜索注册表中有关system32\iexplore.exe字符串的项并删除.
2.在安全模式下删除\winnt\system32\iexplore.exe文件.

论坛徽章:
0
2 [报告]
发表于 2003-03-07 17:52 |只看该作者

关于iexplore.exe

链接: http://www.der-keiler.de/Mailing-Lists/securityfocus/incidents/2001-10/0151.html

Trojan Program Thread
From: Mike Peterson (slidefx@yahoo.com)
Date: 10/19/01

Previous message: Alfred Huger: "Recovered copy of the ssh exploit binary or source"
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]

--------------------------------------------------------------------------------


Message-ID: <20011019190326.63559.qmail@web13108.mail.yahoo.com>;
Date: Fri, 19 Oct 2001 12:03:26 -0700 (PDT)
From: Mike Peterson <slidefx@yahoo.com>;
Subject: Trojan Program Thread
To: incidents@securityfocus.com

It looks like the mystery Trojan is Mini Oblivion by
the Rat Pack. I have passed the iexplore.exe to
Symantec.


General Description was that
iexplore.exe was placed in c:\winnt\system32
Five registry keys were found
HKEY_LOCAL_MACHINE....Windows\CurrentVersion\Run\Default
Web browser "C:\winnt\system32\iexplore.exe"
HKEY_LOCAL_MACHINE....Windows\CurrentVersion\RunServices\Default
web browser "C:\winnt\system32\iexplore.exe"
HKEY_LOCAL_MACHINE....WindowsNT\CurrentVersion\Winlogon\Shell
"explorer.exe iexplore.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows
NT\CurrentVersion\Windows\Run "iexpIore.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows
NT\CurrentVersion\Windows\Load "iexpIore.exe"


Thanks for everyone who responded.


Web Page for Mini Oblivion
http://www.sinred.com/trojans/minioblivion.shtml
(Not written by me)


>; Does anyone have information on a IRC Trojan with
>; the
>; following characteristics.
>;
>; Opens IRC channels on 6667 and connects to some IRC
>; channel on 6668.
>;
>; It sets a registry key
>;
>;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Default
>; web browser = "c:\winnt\system32\iexplore.exe"
>;
>; And changes the shell
>;
>;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Shel
>; l
>; changes it from "Explorer.exe" to "Explorer.exe
>; iexplore.exe"
>;
>; I found a 9 KB file named iexplore.exe in
>; c:\winnt\system32 and also found the iexplore.exe
>; process running.



__________________________________________________

论坛徽章:
0
3 [报告]
发表于 2003-03-07 19:59 |只看该作者

关于iexplore.exe

谢谢楼~~
可是我还是什么都没找到ing~~

论坛徽章:
0
4 [报告]
发表于 2003-03-09 00:02 |只看该作者

关于iexplore.exe

试了一下午,也不知道怎么清除它, 安全模式下把它删除,正常模式就自己就再次出现,好象从其它地方复制过来的一样, 但又实在找不到它在哪里,注册表里也找不到. 郁闷……
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP