NORTON AntiBot是賽門鐵客所出的一款輔助程式,利用行為方式來監控惡意程式做出判斷,進而攔截和移除。


作業系統:windows xp sp3

測試軟體:NORTON AntiBot 1.1.851

病毒:隨身碟病毒一隻


USB病毒一隻

nortonantibot00.jpg



NORTON ANTIBOT 主畫面

nortonantibot05.jpg


運行病毒後NORTON ANTIBOT 出現偵測到新威脅,選擇Quarantine後會出現是否同意移除

nortonantibot01.jpg


威脅移除畫面(不過需要幾分鐘的時間,有點久)

nortonantibot03.jpg


移除後要重新開機

nortonantibot04.jpg


這是這隻隨身碟的病毒autorun的內容

nortonantibot06.jpg

 

 

病毒運作的分析by Norman


 [ DetectionInfo ]
   * Sandbox name: AutoRun.WF.dropper
   * Signature name: W32/Packed_FSG.D
   * Compressed: YES
   * TLS hooks: YES
   * Executable type: Application
   * Executable file structure: OK
   * Filetype: PE_I386

 [ General information ]
   * File might be compressed.
   * Decompressing Unk3!FSG?.
   * File length:        32489 bytes.
   * MD5 hash: e5dc743c8dff551ae85d271aa4f609

ea.

 [ Changes to filesystem ]
   * Deletes file C:\Program Files\Common Files\System\yyjnldu.exe.
   * Deletes file C:\Program Files\Common Files\Microsoft Shared\xnxlufi.exe.
   * Deletes directory C:\Program Files\Common Files\System\yyjnldu.exe.
   * Deletes directory C:\Program Files\Common Files\Microsoft Shared\xnxlufi.exe.
   * Creates file C:\Program Files\Common Files\System\yyjnldu.exe.
   * Creates file C:\Program Files\Common Files\Microsoft Shared\xnxlufi.exe.

 [ Changes to registry ]
   * Accesses Registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options".
   * Accesses Registry key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
   * Deletes value "mhlclyg" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
   * Deletes value "nhbivui" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".

 [ Process/window information ]
   * Attempts to access service "wscsvc".
   * Attempts to access service "helpsvc".
   * Attempts to access service "wuauserv".
   * Attempts to access service "SharedAccess".

 [ Signature Scanning ]
   * C:\Program Files\Common Files\System\yyjnldu.exe (32489 bytes) : AutoRun.WF.
   * C:\Program Files\Common Files\Microsoft Shared\xnxlufi.exe (32489 bytes) : AutoRun.WF.



(C) 2004-2006 Norman ASA. All Rights Reserved.

The material presented is distributed by Norman ASA as an information source only.

心得:
目前好像只有英文版,但操作方式非常的簡單,也沒有什麼複雜的設定方式,所占資源也不大,非常適合新手來使用,當作輔助程式,也可以搭配其它沒有hips功能的防毒使用,重要的是並不代表它可以防止所有的惡意威脅。
補充:最近又測了幾隻隨身碟病毒kxxo系列常見的變種病毒,Norton AntiBot的攔截率蠻高的,應該跟其病毒本身行為模式都差不多吧。

arrow
arrow
    全站熱搜

    NO VIRUS 發表在 痞客邦 留言(2) 人氣()