这是什么进程??

发布网友 发布时间:2022-03-30 00:27

我来回答

2个回答

热心网友 时间:2022-03-30 01:57

我国出现“高波”病毒新变种Worm_AgoBot

国家计算机病毒应急处理中心通过对互联网的监测,于2004年3月10日发现一个新型病毒,经分析确认该病毒为"高波"病毒的一个新变种.。该病毒是常驻内存的蠕虫病毒,可利用RPC DCOM 缓冲区溢出漏洞、IIS5/WEBDAV 缓冲区溢出漏洞和RPC Locator 漏洞进行传播,它还可以通过弱密码攻击远程系统进行主动传播以,利用mIRC软件进行远程控制和传播。

计算机病毒应急处理中心提醒广大计算机用户及时修补漏洞,升级杀毒软件和防火墙,启动"实时监控",设置较为复杂的系统密码(建议为8位以上),做好病毒的预防工作。

病毒名称:"高波"变种(Worm_AgoBot)
病毒类型:蠕虫
其它命名:WORM_AGOBOT.PY (Trend Micro)
"高波"(Worm.Agobot.3.ch) (瑞星公司)
"安哥"变种(Hack.Win32.AgoBot.zl) (金山)
Backdoor.Agobot.fo (AVP)
感染系统:WinNT/Win2000/WinXP/Win2003
病毒长度:115,738字节
病毒特征:

1、生成病毒文件

病毒运行后,在%System%文件夹下生成自身的拷贝,名称为
nvchip4.exe。
(其中,%System%在Windows 95/98/Me 下为C:\Windows\System,
在Windows NT/2000下为C:\Winnt\System32,在Windows XP下为 C:\Windows\System32)

2、修改注册表项

病毒添加注册表项,使得自身能够在系统启动时自动运行,在
HKEY_LOCAL_MACHINE \Software\Microsoft\Windows\
CurrentVersion\Run和HKEY_LOCAL_MACHINE \Software\Microsoft\Windows\CurrentVersion\RunServices下添加"nVidia Chip4 = nvchip4.exe"

3、利用DCOM RPC漏洞进行传播

病毒利用了微软的三个漏洞进行传播:
(1)DCOM RPC缓冲区溢出漏洞(Microsoft Security Bulletin MS03-026)
有关该漏洞的详细信息或下载漏洞补丁程序,请参见微软网站的相关链接:
http://www.microsoft.com/technet/security/bulletin/MS03-026. mspx
或国家计算机病毒应急处理中心的相关链接:
http://www.antivirus-china.org.cn/content/rpc.htm

(2)IIS5/WEBDAV 缓冲区溢出漏洞(Microsoft Security Bulletin MS03-001)
有关该漏洞的详细信息或下载漏洞补丁程序,请参见微软网站的相关链接:
http://www.microsoft.com/technet/security/bulletin/MS03-001.mspx

(3)RPC Locator 漏洞(Microsoft Security Bulletin MS03-007)
http://www.microsoft.com/technet/security/bulletin/MS03-007.mspx

4、利用mIRC进行远程控制和传播

病毒可以通过mIRC进行传播,并允许恶意用户远程访问被感染的系统。

5、通过弱密码攻击进行传播

病毒还可以通过破解简单的管理员及号密码,来攻击远程系统进行主动传播。病毒会使用一些用户和密码攻击远程系统,攻击成功,则会上传病毒。(使用弱密码攻击的用户和密码请参见文档末尾部分)

6、终止杀毒软件和防火墙的运行

病毒会终止一些程序的运行,其中很多都是防病毒和防火墙软件运行、升级的相关程序,从而导致计算机失去基本的防护。

7、盗取游戏的正版序例号

病毒还会盗取下列游戏的正版序例号:
BF1942
Chrome
Command & Conquer
Counter-Strike
FIFA 2002
FIFA 2003
Generals
Half-Life
Hidden and Dangerous 2
LoMaM
Nascar 2002
Nascar 2003
NFSHP2
NHL 2002
HL 2003
NOX
NWN
Project IGI 2
Red Alert
Red Alert 2
SOF2
SWoWWII
The Gladiators
Tiberian Sun
UT2003

8、其它

病毒会终止下列程序,这些程序为"冲击波"及其变种的病毒主程序:
winhlpp32.exe
tftpd.exe
dllhost.exe
winppr32.exe
mspatch.exe
penis32.exe
msblast.exe

手工清除该病毒的相关操作:

1、终止病毒进程

在Windows 9x/ME系统,同时按下CTRL+ALT+DELETE,在Windows NT/2000/XP系统中,同时按下CTRL+SHIFT+ESC,选择"任务管理器--〉进程",选中正在运行的进程"nvchip4.exe",并终止其运行。

2、注册表的恢复

点击"开始--〉运行",输入regedit,运行注册表编辑器,依次双击左侧的HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run ,并删除面板右侧的"nVidia Chip4 = nvchip4.exe"
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>RunServices ,并删除面板右侧的"nVidia Chip4 = nvchip4.exe"

3、删除病毒释放的文件

点击"开始--〉查找--〉文件和文件夹",查找文件"nvchip4.exe",并将找到的文件删除。

4、运行杀毒软件,对系统进行全面的病毒查杀

从病毒设定的发作截止日期我们看出,该病毒的运行时间主要在春节期间,这一时期很多用户会上网收发邮件,互致问候,病毒邮件就掺杂在其中迷惑用户。所以,用户一定要了解该病毒的主要特征,遇到此类邮件立即删除,千万不要打开邮件的附件,避免病毒的感染和进一步的传播。

目前,金山、瑞星和趋势公司已经上报解决方案,并对产品进行了升级,都可以有效的清除该病毒。

弱密码攻击的用户名和密码:
用户名:
Admin
admin
administrador
Administrador
Administrat
Administrateur
administrator
Administrator
admins
computer
Convidado
Coordinatore
database
Default
default
Guest
Inviter
kanri
kanri-sha
login
mysql
netbios
Ospite
OWNER
owner
Owner
server
Standard
student
teacher
Verwalter
wwwadmin

密码:
000000
00000000
111111
11111111
121212
123123
12345
123456
1234567
12345678
1234567
1234qwer
123abc
123asd
123qwe
54321
654321
88888888
abc123
admin123
alpha
asdfghjkl
changeme
enable
foobar
godblessyou
homework
ihavenopass
Internet
Login
metal
mybaby
mybox
mypass
oracle
passwd
Password
password
password123
patrick
penis
poiuytrewq
private
pussy
qwerty
qwertyuiop
red123
school
secret
secrets
super
superman
supersecret
sybase
test123
vagina
werty
xxyyzz
zxcvbnm

终止的与杀毒软件和防火墙相关的程序
AVP32.EXE
_AVPCC.EXE
_AVPM.EXE
AckWin32.EXE
ACKWIN32.EXE
ADVXDWIN.EXE
AGENTSVR.EXE
agentw.EXE
ALERTSVC.EXE
ALOGSERV.EXE
AMON9X.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
apvxdwin.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AutoTrace.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVE32.EXE
AVGCC32.EXE
Avgctrl.EXE
AVGCTRL.EXE
AVGNT.EXE
AvgServ.EXE
AVGSERV.EXE
AVGSERV9.EXE
AVGUARD.EXE
AVGW.EXE
avkpop.EXE
AvkServ.EXE
avkservice.EXE
avkwctl9.EXE
AVNT.EXE
AVP.EXE
AVP32.EXE
AVPCC.EXE
AVPDOS32.EXE
avpm.EXE
AVPM.EXE
AVPTC32.EXE
AVPUPD.EXE
Avsched32.EXE
AvSynMgr.AVSYNMGR.EXE
AVWIN95.EXE
AVWINNT.EXE
AVWUPD32.EXE
AVWUPSRV.EXE
AVXMONITOR9X.EXE
AVXMONITORNT.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
blackd.EXE
BLACKD.EXE
BlackICE.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
ccApp.EXE
ccEvtMgr.EXE
ccPxySvc.EXE
CDP.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET32.EXE
Claw95.EXE
Claw95cf.EXE
CLAW95CF.EXE
CLEAN.EXE
cleaner.EXE
CLEANER.EXE
cleaner3.EXE
CLEANER3.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMON016.EXE
CONNECTIONMONITOR.EXE
cpd.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CTRL.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
defalert.EXE
defscangui.EXE
DEFWATCH.EXE
DEPUTY.EXE
DOORS.EXE
DPF.EXE
DPFSETUP.EXE
DRWATSON.EXE
DRWEB32.EXE
DVP95.EXE
DVP95_0.EXE
ECENGINE.EXE
EFPEADM.EXE
ENT.EXE
ESAFE.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
ESPWATCH.EXE
ETRUSTCIPE.EXE
EVPN.EXE
EXANTIVIRUS-CNET.EXE
EXE.AVXW.EXE
EXPERT.EXE
F-AGNT95.EXE
fameh32.EXE
FAST.EXE
fch32.EXE
fih32.EXE
FINDVIRU.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
fnrb32.EXE
FPROT.EXE
F-PROT.EXE
F-PROT95.EXE
FP-WIN.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
fsaa.EXE
FSAV.EXE
fsav32.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
fsgk32.EXE
fsm32.EXE
fsma32.EXE
fsmb32.EXE
f-stopw.EXE
F-STOPW.EXE
gbmenu.EXE
GBMENU.EXE
gbpoll.EXE
GBPOLL.EXE
GENERICS.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
iamapp.EXE
IAMAPP.EXE
iamserv.EXE
IAMSERV.EXE
IAMSTATS.EXE
IBMASN.EXE
IBMAVSP.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFACE.EXE
IFW2000.EXE
IOMON98.EXE
IPARMOR.EXE
IRIS.EXE
ISRV95.EXE
JAMMER.EXE
JEDI.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KAVPF.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDNETMON.EXE
LDPRO.EXE
LDPROMENU.EXE
LDSCAN.EXE
LOCALNET.EXE
LOCKDOWN.EXE
lockdown2000.EXE
LOCKDOWN2000.EXE
LOOKOUT.EXE
LSETUP.EXE
LUALL.EXE
LUAU.EXE
LUCOMSERVER.EXE
LUINIT.EXE
LUSPT.EXE
MCAGENT.EXE
MCMNHDLR.EXE
Mcshield.EXE
MCTOOL.EXE
MCUPDATE.EXE
MCVSRTE.EXE
MCVSSHLD.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGAVRTCL.EXE
MGAVRTE.EXE
MGHTML.EXE
MGUI.EXE
MINILOG.EXE
Monitor.EXE
MONITOR.EXE
MOOLIVE.EXE
MPFAGENT.EXE
MPFSERVICE.EXE
MPFTRAY.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
MWATCH.EXE
N32SCANW.EXE
NAV Auto-Protect.NAV80TRY.EXE
NAVAP.navapsvc.EXE
NAVAPSVC.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVENGNAVEX15.NAVLU32.EXE
NAVLU32.EXE
NAVNT.EXE
NAVSTUB.EXE
Navw32.EXE
NAVW32.EXE
NAVWNT.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NeoWatchLog.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NETUTILS.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NOD32.EXE
NORMIST.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
notstart.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
npscheck.EXE
NPSSVC.EXE
NSCHED32.EXE
ntrtscan.EXE
NTVDM.EXE
NTXconfig.EXE
Nui.EXE
Nupgrade.EXE
NVARCH16.EXE
NVC95.EXE
nvsvc32.EXE
NWINST4.EXE
NWService.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVCL.EXE
pavproxy.EXE
PAVPROXY.EXE
PAVSCHED.EXE
PAVW.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
pccntmon.EXE
pccwin97.EXE
PCCWIN98.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
pcscan.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PERSWF.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POP3TRAP.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PORTMONITOR.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCESSMONITOR.EXE
PROCEXPLORERV1.0.EXE
PROGRAMAUDITOR.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
rapapp.EXE
RAV7.EXE
RAV7WIN.EXE
RAV8WIN32ENG.EXE
REALMON.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
rtvscan.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
sbserv.EXE
SBSERV.EXE
SCAN32.EXE
SCAN95.EXE
SCANPM.EXE
SCRSCAN.EXE
SD.EXE
SERV95.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
Sphinx.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SWEEP95.EXE
SweepNet.SWEEPSRV.SYS.SWNETSUP.EXE
SymProxySvc.EXE
SYMPROXYSVC.EXE
SYMTRAY.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TBSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
vbcmserv.EXE
VBCMSERV.EXE
VbCons.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VET32.EXE
Vet95.EXE
VET95.EXE
VetTray.EXE
VETTRAY.EXE
VFSETUP.EXE
VIR-HELP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC32.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCAN40.EXE
VSCENU6.02D30.EXE
VSCHED.EXE
VSECOMR.EXE
vshwin32.EXE
VSISETUP.EXE
VSMAIN.EXE
vsmon.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WEBTRAP.EXE
WFINDV32.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WIMMUN32.EXE
WINRECON.EXE
WNT.EXE
WrAdmin.EXE
WRADMIN.EXE
WrCtrl.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
zapro.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
zonealarm.EXE
ZONEALARM.EXE

国家计算机病毒应急处理中心
计算机病毒防治产品检验中心
网 址:http://www.antivirus-China.org.cn
电 话:022-66211488/662114/66211490
传 真:022-66211487
电子邮件:security@tj.cnuninet.net

热心网友 时间:2022-03-30 03:15

没见过这个进程,如果不是你安装的其他程序,那就是木马,一般常见软件没有这个进程的。

声明声明:本网页内容为用户发布,旨在传播知识,不代表本网认同其观点,若有侵权等问题请及时与本网联系,我们将在第一时间删除处理。E-MAIL:11247931@qq.com