Ransom.MSIL.THANOS.THABGBA
Trojan-Ransom.Thanos (Ikarus), HEUR:Trojan-Ransom.MSIL.Encoder.gen (Kaspersky)
Windows

恶意软件类型:
Ransomware
有破坏性?:
没有
加密?:
是的
In the Wild:
是的
概要
它以其他恶意软件释放的文件或用户访问恶意网站时不知不觉下载的文件的形式到达系统。它开始执行然后再删除。
技术详细信息
新病毒详细信息
它以文件的形式出现在系统中,可能是其他恶意软件投放的,或者是用户在访问恶意网站时无意中下载的。
它可能是由下列恶意软件植入:
安装
它添加下列互斥条目,确保一次只会运行一个副本:
- e660f428-738e-469e-93fc-20803ca8aa37
自启动技术
它将下列文件植入 Windows 用户启动文件夹,以便在系统每次启动时自动执行:
- %User Startup%\mystartup.lnk
(注意: %User Startup% 是当前用户的启动文件夹,通常位于 C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup (Windows NT)、C:\Documents and Settings\{User name}\Start Menu\Programs\Startup (Windows 2003(32-bit)、XP、2000(32-bit)) 和 C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit))。)
其他系统修改
它会创建以下注册表项以禁用安全相关的应用程序:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender\Real-Time Protection
DisableBehaviorMonitoring = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender
DisableAntiSpyware = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender\Real-Time Protection
DisableOnAccessProtection = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows Defender\Real-Time Protection
DisableScanOnRealtimeEnable = 1
其他详细信息
该程序执行以下操作:
- It terminates the following processes if found using the following commands:
- "taskkill.exe" /IM mspub.exe /F
- "taskkill.exe" /IM onenote.exe /F
- "taskkill.exe" /IM agntsvc.exe /F
- "taskkill.exe" /IM PccNTMon.exe /F
- "taskkill.exe" /IM synctime.exe /F
- "taskkill.exe" /IM thebat.exe /F
- "taskkill.exe" /IM excel.exe /F
- "taskkill.exe" /IM msaccess.exe /F
- "taskkill.exe" /IM steam.exe /F
- "taskkill.exe" /IM firefoxconfig.exe /F
- "taskkill.exe" /IM CNTAoSMgr.exe /F
- "taskkill.exe" /IM dbeng50.exe /F
- "taskkill.exe" /IM sqlwriter.exe /F
- "taskkill.exe" /IM infopath.exe /F
- "taskkill.exe" /IM mspub.exe /F
- "taskkill.exe" /IM Ntrtscan.exe /F
- "taskkill.exe" /IM outlook.exe /F
- "taskkill.exe" /IM mydesktopservice.exe /F
- "taskkill.exe" /IM encsvc.exe /F
- "taskkill.exe" /IM tbirdconfig.exe /F
- "taskkill.exe" /IM mbamtray.exe /F
- "taskkill.exe" /IM mydesktopqos.exe /F
- "taskkill.exe" /IM thebat64.exe /F
- "taskkill.exe" /IM zoolz.exe /F
- "taskkill.exe" /IM tmlisten.exe /F
- "taskkill.exe" /IM sqlservr.exe /F
- "taskkill.exe" /IM winword.exe /F
- "taskkill.exe" /IM visio.exe /F
- "taskkill.exe" /IM mydesktopqos.exe /F
- "taskkill.exe" /IM mydesktopservice.exe /F
- "taskkill.exe" /IM mysqld.exe /F
- "taskkill.exe" /IM isqlplussvc.exe /F
- "taskkill.exe" /IM msftesql.exe /F
- "taskkill.exe" /IM sqbcoreservice.exe /F
- "taskkill.exe" /IM ocomm.exe /F
- "taskkill.exe" IM thunderbird.exe /F
- "taskkill.exe" /IM mysqld-nt.exe /F
- "taskkill.exe" /IM dbsnmp.exe /F
- "taskkill.exe" /IM powerpnt.exe /F
- "taskkill.exe" /IM xfssvccon.exe /F
- "taskkill.exe" /IM wordpad.exe /F
- "taskkill.exe" /IM mysqld-opt.exe /F
- "taskkill.exe" /IM ocautoupds.exe /F
- It terminates all running processes unless the following strings are found in the process name:
- chrome
- opera
- msedge
- iexplore
- firefox
- explorer
- wininit
- winlogon
- SearchApp
- SearchIndexer
- SearchUI
- It checks if the following programs are running. If they are, the said programs are terminated, and the main ransomware program will terminate as well:
- http analyzer stand-alone
- fiddler
- effetech http sniffer
- firesheep
- IEWatch Professional
- wireshark portable
- sysinternals tcpview
- dumpcap
- wireshark
- ollydbg
- x64dbg
- x32dbg
- dnspy
- dnspy-x86
- de4dot
- ilspy
- dotpeek
- dotpeek64
- ida64
- RDG Packer Detector
- CFF Explorer
- PEiD
- protection_id
- LordPE
- pe-sieve
- MegaDumper
- UnConfuserEx
- Universal_Fixer
- NoFuserEx
- NetworkMiner
- NetworkTrafficView
- HTTPNetworkSniffer
- tcpdump
- intercepter
- intercepter-NG
- It deletes the following registry subkeys to delete shadow copies:
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- vssadmin.exe
- vssadmin.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- wmic.exe
- wmic.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- wbadmin.exe
- wbadmin.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- bcdedit.exe
- bcdedit.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- powershell.exe
- powershell.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- diskshadow.exe
- diskshadow.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- net.exe
- net.exe
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- The malware disables the following using powershell console:
- "DisableRealtimeMonitoring"
- "DisableBehaviorMonitoring"
- "DisableBlockAtFirstSeen"
- "DisableIOAVProtection"
- "DisablePrivacyMode"
- "SignatureDisableUpdateOnStartupWithoutEngine"
- "DisableArchiveScanning"
- "DisableIntrusionPreventionSystem"
- "DisableScriptScanning"
- "SubmitSamplesConsent"
- "MAPSReporting"
- "HighThreatDefaultAction"
- "ModerateThreatDefaultAction"
- "LowThreatDefaultAction"
- "SevereThreatDefaultAction"
解决方案
Step 2
对于Windows ME和XP用户,在扫描前,请确认已禁用系统还原功能,才可全面扫描计算机。
Step 3
请注意,在执行此恶意软件/间谍软件/灰色软件期间,并非所有文件、文件夹、注册表项和条目都安装在您的计算机上。这可能是由于安装不完整或其他操作系统条件造成的。如果找不到相同的文件/文件夹/注册表信息,请继续下一步。
Step 4
重启进入安全模式
Step 5
删除该注册表值
注意事项:错误编辑Windows注册表会导致不可挽回的系统故障。只有在您掌握后或在系统管理员的帮助下才能完成这步。或者,请先阅读Microsoft文章,然后再修改计算机注册表。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
- DisableAntiSpyware=1
- DisableAntiSpyware=1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- DisableBehaviorMonitoring=1
- DisableBehaviorMonitoring=1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- DisableOnAccessProtection=1
- DisableOnAccessProtection=1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- DisableScanOnRealtimeEnable=1
- DisableScanOnRealtimeEnable=1
Step 6
搜索和删除这些文件
- %User Temp%\RESTORE_FILES_INFO.txt
- %User Startup%\mystartup.lnk
- %User Temp%\RESTORE_FILES_INFO.txt
- %User Startup%\mystartup.lnk
Step 7
重启进入正常模式,使用亚信安全产品扫描计算机,检测Ransom.MSIL.THANOS.THABGBA文件 如果检测到的文件已被亚信安全产品清除、删除或隔离,则无需采取进一步措施。可以选择直接删除隔离的文件。请参阅知识库页面了解详细信息。
Step 8
使用亚信安全产品扫描计算机,并删除检测到的Ransom.MSIL.THANOS.THABGBA文件 如果检测到的文件已被亚信安全产品清除、删除或隔离,则无需采取进一步措施。可以选择直接删除隔离的文件。请参阅知识库页面了解详细信息。
Step 9
从备份中还原被加密的文件。