Trend Micro Security

BKDR_PUSHDO.QQ

2013年11月7日
 解析者: Nikko Tamana   

 プラットフォーム:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 危険度:
 ダメージ度:
 感染力:
 感染確認数:
 情報漏えい:


  • マルウェアタイプ: バックドア型
  • 破壊活動の有無: なし
  • 暗号化:  
  • 感染報告の有無: はい

  概要


マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。


  詳細

ファイルサイズ 96,256 bytes
タイプ EXE
メモリ常駐 はい
発見日 2013年10月22日

侵入方法

マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

インストール

マルウェアは、感染したコンピュータ内に以下のように自身のコピーを作成します。

  • %User Profile%\{random filename}.exe

(註:%User Profile% フォルダは、Windows 2000、XP および Server 2003 の場合、通常、"C:\Documents and Settings\<ユーザ名>"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>" です。)

自動実行方法

マルウェアは、自身のコピーがWindows起動時に自動実行されるよう以下のレジストリ値を追加します。

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
{random filename} = "%User Profile%\{random filename}.exe"

他のシステム変更

マルウェアは、以下のレジストリ値を追加します。

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion
AppManagement = "{random value}"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion
{random filename} = "{random value}"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion
{random number} = "{random value}"

HKEY_CURRENT_USER\Software\WinRAR
HWID = "{random value}"

HKEY_CURRENT_USER\Software\WinRAR
Client Hash = "{random value}"

その他

マルウェアは、以下の不正なWebサイトにアクセスします。

  • {BLOCKED}ecials.com
  • {BLOCKED}nvestor.ca
  • {BLOCKED}a.com.br
  • {BLOCKED}acificrepairs.com
  • {BLOCKED}dvdexplorer.com
  • {BLOCKED}livechat.us
  • {BLOCKED}ced.com
  • {BLOCKED}lub.ru
  • {BLOCKED}e-des-druides.com
  • {BLOCKED}no.ru
  • {BLOCKED}co.nz
  • {BLOCKED}net
  • {BLOCKED}-chuoukotsu.co.jp
  • {BLOCKED}gmail-smtp-in.l.google.com
  • {BLOCKED}gmail-smtp-in.l.google.com
  • {BLOCKED}line.com
  • {BLOCKED}org.ar
  • {BLOCKED}d.com
  • {BLOCKED}linic.com
  • {BLOCKED}ercollegeprep.com
  • {BLOCKED}ervice.com
  • {BLOCKED}side.com
  • {BLOCKED}el-exporter.com
  • {BLOCKED}2aa.org
  • {BLOCKED}ocordoba.com
  • {BLOCKED}de.com
  • {BLOCKED}rmokin.com
  • {BLOCKED}o.jp
  • {BLOCKED}i.com
  • {BLOCKED}rno.com
  • {BLOCKED}isk.com.sg
  • {BLOCKED}echnologies.com
  • {BLOCKED}iansurfing.at
  • {BLOCKED}ntica-travel.com
  • {BLOCKED}a.it
  • {BLOCKED}-ime.com
  • {BLOCKED}tbul.net
  • {BLOCKED}mages.com
  • {BLOCKED}wing-conseil.com
  • {BLOCKED}challerbach.at
  • {BLOCKED}ci.com.tr
  • {BLOCKED}inc.com
  • {BLOCKED}itaramsevatrust.org
  • {BLOCKED}brug.com
  • {BLOCKED}.com
  • {BLOCKED}ryweb.com
  • {BLOCKED}trong.net
  • {BLOCKED}woodmetalworks.com
  • {BLOCKED}oft.com.au
  • {BLOCKED}printing.com
  • {BLOCKED}sraelcenter.org
  • {BLOCKED}orp.com
  • {BLOCKED}hnsbeefjerky.com
  • {BLOCKED}pmultimedia.com
  • {BLOCKED}re.com.au
  • {BLOCKED}-group.com
  • {BLOCKED}nlow.com
  • {BLOCKED}ers.co.uk
  • {BLOCKED}date.at
  • {BLOCKED}sting.com
  • {BLOCKED}uffalo.com
  • {BLOCKED}huntindia.com
  • {BLOCKED}internet.nl
  • {BLOCKED}ea.co.uk
  • {BLOCKED}tesan.com.ar
  • {BLOCKED}d.com
  • {BLOCKED}ld.com
  • {BLOCKED}ess-edge.com
  • {BLOCKED}illmedia.com
  • {BLOCKED}u.com
  • {BLOCKED}diosystems.co.za
  • {BLOCKED}a.com
  • {BLOCKED}choice.org
  • {BLOCKED}inting.com.au
  • {BLOCKED}.net
  • {BLOCKED}ikalip.com.tr
  • {BLOCKED}al-hi.net
  • {BLOCKED}alparkcairns.com
  • {BLOCKED}ngland.com
  • {BLOCKED}s.co.jp
  • {BLOCKED}latecovers.com
  • {BLOCKED}e-select.com
  • {BLOCKED}malta.com
  • {BLOCKED}tybarry.com
  • {BLOCKED}eative.com
  • {BLOCKED}hclothes.com
  • {BLOCKED}hsupplies.net
  • {BLOCKED}rprint.nl
  • {BLOCKED}ne.or.id
  • {BLOCKED}rtbrothers.com
  • {BLOCKED}aposaga.ro
  • {BLOCKED}nuans.com
  • {BLOCKED}.de
  • {BLOCKED}nsa.com
  • {BLOCKED}.net
  • {BLOCKED}roscience.com
  • {BLOCKED}mvacform.com
  • {BLOCKED}edia.com
  • {BLOCKED}-negar.com
  • {BLOCKED}ponents.com
  • {BLOCKED}
  • {BLOCKED}escueusa.com
  • {BLOCKED}tesnv.org
  • {BLOCKED}o.se
  • {BLOCKED}glitzy.com
  • {BLOCKED}taro.com
  • {BLOCKED}2.com
  • {BLOCKED}antasies.com
  • {BLOCKED}rg
  • {BLOCKED}elle.com
  • {BLOCKED}ukyaku.com
  • {BLOCKED}rming.com
  • {BLOCKED}rina-center.com
  • {BLOCKED}nto.com
  • {BLOCKED}dalia.com
  • {BLOCKED}ech.com
  • {BLOCKED}rodrigo.com.br
  • {BLOCKED}nc.com
  • {BLOCKED}an.fr
  • {BLOCKED}e-hotelier.com
  • {BLOCKED}adio1310.com
  • {BLOCKED}a.co.ro
  • {BLOCKED}japan.com
  • {BLOCKED}oup.com
  • {BLOCKED}nonline.de
  • {BLOCKED}sur.com
  • {BLOCKED}for.org
  • {BLOCKED}dadoubled.com
  • {BLOCKED}ages.com
  • {BLOCKED}spot.co.za
  • {BLOCKED}ght.net
  • {BLOCKED}rynine5.com
  • {BLOCKED}ingonlinemagazine.com
  • {BLOCKED}.com
  • {BLOCKED}motoki.com
  • {BLOCKED}cisions.com
  • {BLOCKED}ermusa.com
  • {BLOCKED}otels.com
  • {BLOCKED}-smtp-in.l.google.com
  • {BLOCKED}-smtp-in.l.google.com
  • {BLOCKED}ousing.org
  • {BLOCKED}train.coop
  • {BLOCKED}countrycom.com
  • {BLOCKED}ngfcog.com
  • {BLOCKED}e.com.br
  • {BLOCKED}en.net
  • {BLOCKED}ur-trading.com
  • {BLOCKED}ansolicitors.com
  • {BLOCKED}ultimedia.com
  • {BLOCKED}b.org
  • {BLOCKED}rost.de
  • {BLOCKED}mare.nl
  • {BLOCKED}asou.com
  • {BLOCKED}ivory.com
  • {BLOCKED}oupindia.com
  • {BLOCKED}.fr
  • {BLOCKED}eist.be
  • {BLOCKED}.com.pl
  • {BLOCKED}mtp.messagingengine.com
  • {BLOCKED}mtp.messagingengine.com
  • {BLOCKED}endentfire.us
  • {BLOCKED}tria-dohmen.hu
  • {BLOCKED}ra.si
  • {BLOCKED}ouronline.com
  • {BLOCKED}karnataka.org
  • {BLOCKED}bultarim.com.tr
  • {BLOCKED}nline.com
  • {BLOCKED}ctor.com
  • {BLOCKED}am.com
  • {BLOCKED}mate.co.jp
  • {BLOCKED}ekkei.com
  • {BLOCKED}rogerpark.com
  • {BLOCKED}liams.com.uy
  • {BLOCKED}-verne.net
  • {BLOCKED}onnect.co.za
  • {BLOCKED}ernitz.at
  • {BLOCKED}t.com
  • {BLOCKED}hokuren.com
  • {BLOCKED}i-venture.org
  • {BLOCKED}hal.com
  • {BLOCKED}bi.com
  • {BLOCKED}uipment.com
  • {BLOCKED}ountry.net
  • {BLOCKED}entre.co.th
  • {BLOCKED}hi-hp.com
  • {BLOCKED}haus.com
  • {BLOCKED}ina.com
  • {BLOCKED}atoff.ru
  • {BLOCKED}com
  • {BLOCKED}du
  • {BLOCKED}nas.com
  • {BLOCKED}net
  • {BLOCKED}rshipforum.us
  • {BLOCKED}orecast.com
  • {BLOCKED}rhymanpotter.com
  • {BLOCKED}nthemoon.com
  • {BLOCKED}list-uk.com
  • {BLOCKED}onaquatichobby.com
  • {BLOCKED}retti.com.ar
  • {BLOCKED}vortex.com
  • {BLOCKED}airmail.net
  • {BLOCKED}7.us2.mcsv.net
  • {BLOCKED}.digitalwaves.co.nz
  • {BLOCKED}.digitalwaves.co.nz
  • {BLOCKED}himp.com
  • {BLOCKED}ementplaz.com
  • {BLOCKED}-man.com
  • {BLOCKED}office.com
  • {BLOCKED}sgrimes.co.uk
  • {BLOCKED}vhaus-sued.de
  • {BLOCKED}chn.com
  • {BLOCKED}ies.org
  • {BLOCKED}es-jacquelin.com
  • {BLOCKED}roof.com
  • {BLOCKED}ava.com
  • {BLOCKED}onaires24.com
  • {BLOCKED}ech.net
  • {BLOCKED}ideo.com
  • {BLOCKED}71.ru
  • {BLOCKED}ophoto.com
  • {BLOCKED}elopes.com.br
  • {BLOCKED}s.com
  • {BLOCKED}.com
  • {BLOCKED}rg
  • {BLOCKED}cess.com
  • {BLOCKED}ttingen.de
  • {BLOCKED}ail.ru
  • {BLOCKED}ail.ru
  • {BLOCKED}ecenter.com
  • {BLOCKED}v.org
  • {BLOCKED}pictures.com
  • {BLOCKED}enementiel.com
  • {BLOCKED}gecomputing.com
  • {BLOCKED}om.pl
  • {BLOCKED}dictionary.com
  • {BLOCKED}uroya.com
  • {BLOCKED}pectra.com
  • {BLOCKED}ech.com
  • {BLOCKED}a.org
  • {BLOCKED}kes.com
  • {BLOCKED}oron.cba.pl
  • {BLOCKED}.com
  • {BLOCKED}-networks.net
  • {BLOCKED}.com
  • {BLOCKED}com
  • {BLOCKED}s.com
  • {BLOCKED}estreet.com
  • {BLOCKED}incamera.co.jp
  • {BLOCKED}lub.ru
  • {BLOCKED}mobile.com
  • {BLOCKED}-design.com
  • {BLOCKED}clubs.com
  • {BLOCKED}x.com
  • {BLOCKED}ba
  • {BLOCKED}org
  • {BLOCKED}iserpages.com
  • {BLOCKED}etonmortgage.com
  • {BLOCKED}sionit.ca
  • {BLOCKED}ictriangle.com
  • {BLOCKED}stackwarehouse.com.au
  • {BLOCKED}-chalette.com
  • {BLOCKED}linija.com
  • {BLOCKED}art.net.au
  • {BLOCKED}nuts.com
  • {BLOCKED}ccctv.com
  • {BLOCKED}oft.ru
  • {BLOCKED}ime-it.com
  • {BLOCKED}lebag.com.hk
  • {BLOCKED}.com.tr
  • {BLOCKED}semyad.com
  • {BLOCKED}.e1data.com
  • {BLOCKED}dhits.com
  • {BLOCKED}.com
  • {BLOCKED}rtland.org
  • {BLOCKED}tmcintyre.com.au
  • {BLOCKED}ns.com
  • {BLOCKED}museum.de
  • {BLOCKED}show.com.au
  • {BLOCKED}s-aviation.com
  • {BLOCKED}nfo
  • {BLOCKED}thing.com
  • {BLOCKED}.net
  • {BLOCKED}-de-yours.com
  • {BLOCKED}.org
  • {BLOCKED}proyectos.com
  • {BLOCKED}coop
  • {BLOCKED}ie
  • {BLOCKED}ty1989.com
  • {BLOCKED}e-property.com
  • {BLOCKED}orma.net
  • {BLOCKED}lectronic.com
  • {BLOCKED}v.org
  • {BLOCKED}sailscanada.com
  • {BLOCKED}wcliff.org
  • {BLOCKED}yspizza.ph
  • {BLOCKED}talkers.com
  • {BLOCKED}liteexpress.com
  • {BLOCKED}acet.com
  • {BLOCKED}c.in
  • {BLOCKED}nagementgrs.com
  • {BLOCKED}ne-lodge.com
  • {BLOCKED}o.org
  • {BLOCKED}compuserve.com
  • {BLOCKED}directcon.net
  • {BLOCKED}live.com
  • {BLOCKED}mail.yahoo.com
  • {BLOCKED}sbcglobal.yahoo.com
  • {BLOCKED}sinsurance.com
  • {BLOCKED}luent.com
  • {BLOCKED}tyolu.com
  • {BLOCKED}ioncorp.com
  • {BLOCKED}ern-park.com
  • {BLOCKED}dore.com
  • {BLOCKED}kaginggroup.com
  • {BLOCKED}m.nl
  • {BLOCKED}er.de
  • {BLOCKED}anus.hu
  • {BLOCKED}orks.com
  • {BLOCKED}ehopatcong.org
  • {BLOCKED}ddos.me
  • {BLOCKED}wildlifeart.com
  • {BLOCKED}syokohama.com
  • {BLOCKED}tives.org
  • {BLOCKED}astudios.com
  • {BLOCKED}p.com
  • {BLOCKED}.com
  • {BLOCKED}ka.com
  • {BLOCKED}tufi.com
  • {BLOCKED}tejarat.com
  • {BLOCKED}kawagumi.com
  • {BLOCKED}.com
  • {BLOCKED}ng-video.com
  • {BLOCKED}iche-intl.com
  • {BLOCKED}.com.br
  • {BLOCKED}avis.com
  • {BLOCKED}ra.co.jp
  • {BLOCKED}tofhair.com
  • {BLOCKED}tospas.com
  • {BLOCKED}ckofmymind.net
  • {BLOCKED}urkey.com
  • {BLOCKED}ipe.com
  • {BLOCKED}okan.com
  • {BLOCKED}.ro
  • {BLOCKED}earthcare.com.au
  • {BLOCKED}aire.com
  • {BLOCKED}gressiveproducers.com
  • {BLOCKED}nto.de
  • {BLOCKED}alau.com
  • {BLOCKED}an.com
  • {BLOCKED}edia.com
  • {BLOCKED}ty-works.com
  • {BLOCKED}140.org
  • {BLOCKED}a.net
  • {BLOCKED}su.org
  • {BLOCKED}dearthgroup.com
  • {BLOCKED}.edu.bo
  • {BLOCKED}iaproject.com
  • {BLOCKED}familylaw.com
  • {BLOCKED}pr.com
  • {BLOCKED}rnmuseum.org
  • {BLOCKED}ardpkg.com
  • {BLOCKED}kids.com
  • {BLOCKED}fox.ru
  • {BLOCKED}e-art.com
  • {BLOCKED}.com
  • {BLOCKED}ur.by
  • {BLOCKED}ur.by
  • {BLOCKED}i.com
  • {BLOCKED}o.za
  • {BLOCKED}etravel.com
  • {BLOCKED}om.tr
  • {BLOCKED}ek.com
  • {BLOCKED}illsstl.org
  • {BLOCKED}trommorse.com
  • {BLOCKED}-hot.com
  • {BLOCKED}rade.net
  • {BLOCKED}sussex.com
  • {BLOCKED}ouisiana.gov
  • {BLOCKED}l
  • {BLOCKED}xaminer.com
  • {BLOCKED}vant-ime.com
  • {BLOCKED}eechwoodmetalworks.com
  • {BLOCKED}igjohnsbeefjerky.com
  • {BLOCKED}usiness-edge.com
  • {BLOCKED}ygwindows.co.uk
  • {BLOCKED}xtractor.com
  • {BLOCKED}ustconnect.co.za
  • {BLOCKED}omonophoto.com
  • {BLOCKED}yfilecenter.com
  • {BLOCKED}hotoclubs.com
  • {BLOCKED}odeoshow.com.au
  • {BLOCKED}aios.net
  • {BLOCKED}olutioncorp.com
  • {BLOCKED}eknorhino.com
  • {BLOCKED}heartofhair.com
  • {BLOCKED}raderush.com
  • {BLOCKED}raderush.com
  • {BLOCKED}anguardpkg.com
  • {BLOCKED}er.com
  • {BLOCKED}iao.com
  • {BLOCKED}oshi-group.com
  • {BLOCKED}et.co.jp
  • {BLOCKED}arbatului.ro


  対応方法

対応検索エンジン: 9.300

手順 1

Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。

手順 2

このマルウェアのパス名およびファイル名を確認します。
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用いてウイルス検索を実行してください。「BKDR_PUSHDO.QQ」で検出したパス名およびファイル名を確認し、メモ等をとってください。

手順 3

Windowsをセーフモードで再起動します。

[ 詳細 ]

手順 4

このレジストリ値を削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

 
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • {random filename} = "%User Profile%\{random filename}.exe"
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
    • AppManagement = "{random value}"
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
    • {random filename} = "{random value}"
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
    • {random number} = "{random value}"
  • In HKEY_CURRENT_USER\Software\WinRAR
    • HWID = "{random value}"
  • In HKEY_CURRENT_USER\Software\WinRAR
    • Client Hash = "{random value}"

手順 5

コンピュータを通常モードで再起動し、最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、「BKDR_PUSHDO.QQ」と検出したファイルの検索を実行してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。


ご利用はいかがでしたか? アンケートにご協力ください