Trojan Horse Detection Method, Device, Electronic Device and Computer Readable Storage Medium

By decompiling and decrypting Trojans, the problem of difficult to detect shelling or local variable storage Trojans in the existing technology is solved, and more accurate Trojan positioning and checking are achieved, improving computer security and anti-virus software detection and killing capabilities.

CN113868655BActive Publication Date: 2025-07-11BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111152178.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-29
Publication Date
2025-07-11
Estimated Expiration
2041-09-29

AI Technical Summary

Technical Problem

现有技术难以有效查杀通过加壳或局部变量存储方式实现免杀的木马。

Method used

By decompiling the target Trojan, determining its functional data address and decryption algorithm, using the key to decrypt the encrypted Trojan and then checking and killing.

Benefits of technology

It improves the ability to detect and kill without killing Trojans, enhances the security of the computer and the static scanning ability of anti-virus software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113868655B_ABST
    Figure CN113868655B_ABST
Patent Text Reader

Abstract

The present application provides a Trojan horse killing method, device, electronic device and computer-readable storage medium. Among them, the method includes: executing one or more Trojan horses processed in a specified manner in an anti-virus environment; obtaining the target Trojan horse among the one or more Trojan horses that have not been killed; performing decompilation processing on the target Trojan horse to determine the function data address of the target Trojan horse; determining the decryption algorithm and the first key of the function data according to the function data address; decrypting the encrypted target Trojan horse according to the decryption algorithm and the first key; and killing the decrypted target Trojan horse. It can improve the ability to kill Trojan horses.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer security technology. Specifically, it relates to a method, device, electronic device, and computer-readable storage medium for detecting and killing Trojans. Background Art

[0002] A Trojan is a malicious computer program that affects computer security. However, some existing Trojans can achieve anti-detection by means such as shelling or storing the plaintext binary data of the Trojan in the form of local variables. At present, some means can be used to detect and kill the above anti-detection Trojans, but there are still some Trojans that cannot be located and killed. Summary of the Invention

[0003] The purpose of this application is to provide a method, device, electronic device, and computer-readable storage medium for detecting and killing Trojans, which can solve the problem of improving the ability to detect and kill anti-detection Trojans.

[0004] In a first aspect, an embodiment of this application provides a method for detecting and killing Trojans, including:

[0005] Obtain a target Trojan that has not been detected and killed;

[0006] Perform decompilation processing on the target Trojan to determine the functional data address of the target Trojan;

[0007] According to the functional data address, determine the decryption algorithm and the first key of the functional data;

[0008] Decrypt the encrypted target Trojan according to the decryption algorithm and the first key;

[0009] Detect and kill the decrypted target Trojan.

[0010] In an optional implementation manner, the performing decompilation processing on the target Trojan to determine the functional data address of the target Trojan includes:

[0011] Perform decompilation processing on the target Trojan to determine the file loading method of the target Trojan;

[0012] Determine the functional data address of the target Trojan according to the loading method.

[0013] In an optional implementation manner, the performing decompilation processing on the target Trojan to determine the file loading method of the target Trojan includes:

[0014] Perform decompilation processing on the target Trojan to determine the entry point method of the target Trojan;

[0015] Determine the loading method of the file of the target Trojan according to the entry point method.

[0016] In the above embodiment, the entry point method is found through decompilation to further determine the loading method of the file of the target Trojan, so as to realize more accurate positioning of the Trojan.

[0017] In an alternative embodiment, the decrypting the encrypted target Trojan according to the decryption algorithm and the first key includes:

[0018] Determine the storage location of the encrypted target Trojan according to the decryption algorithm and the first key operating on the data source;

[0019] Obtain the encrypted Trojan in the storage location;

[0020] Decrypt the encrypted Trojan using the decryption algorithm and the first key.

[0021] In an alternative embodiment, the obtaining the target Trojan not detected includes:

[0022] In the anti-virus environment, execute one or more Trojans processed in a specified manner;

[0023] Obtain the target Trojan not detected in the one or more Trojans.

[0024] In the above embodiment, by running the Trojans processed in a specified manner in the anti-virus environment, the Trojans with high anti-detection ability can be screened out, and based on the Trojans with high anti-detection ability, the above decompilation process is used to achieve more accurate killing.

[0025] In an alternative embodiment, the target Trojan is constructed in the following manner:

[0026] Obtain the plaintext Trojan;

[0027] Obtain the target encryption algorithm from the preset encryption algorithms, and encrypt the plaintext Trojan using the target encryption algorithm and the second key to obtain the ciphertext Trojan;

[0028] Store the ciphertext Trojan, the decryption algorithm corresponding to the target encryption algorithm, and the second key into a template file to determine the target Trojan file.

[0029] In the above embodiment, by actively designing Trojan anti-detection means, corresponding countermeasures are further designed based on the anti-detection means, so as to further improve the static scanning ability of the anti-virus software and.

[0030] In an alternative embodiment, the method further includes:

[0031] Update the current antivirus software according to the process of detecting and killing the target Trojan horse.

[0032] In the above implementation, by updating the antivirus software, the detection and killing ability of the antivirus software can be gradually improved, so as to further improve the security of the computer protected by the antivirus software.

[0033] In a second aspect, an embodiment of the present application provides a Trojan horse detection and killing device, including:

[0034] An acquisition module, configured to acquire a target Trojan horse that has not been detected and killed;

[0035] A first determination module, configured to perform decompilation processing on the target Trojan horse to determine the function data address of the target Trojan horse;

[0036] A second determination module, configured to determine a decryption algorithm and a first key of the function data according to the function data address;

[0037] A decryption module, configured to decrypt the encrypted target Trojan horse according to the decryption algorithm and the first key;

[0038] A detection and killing module, configured to detect and kill the decrypted target Trojan horse.

[0039] In a third aspect, an embodiment of the present application provides an electronic device, including: a processor and a memory, where the memory stores machine-readable instructions executable by the processor, and when the electronic device runs, the machine-readable instructions are executed by the processor to execute the steps of the above method.

[0040] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, the steps of the above method are executed.

[0041] The beneficial effects of the embodiments of the present application are as follows: By decompiling the Trojan horse, based on the execution process of the Trojan horse, the hidden means of the Trojan horse are reversely inferred, and by analyzing information such as the decryption algorithm used by the Trojan horse and the location of the encrypted Trojan horse, etc., the encrypted Trojan horse can be decrypted to achieve the positioning and detection and killing of the Trojan horse, which can improve the security of the computer and the detection and killing ability of the computer. Description of the Drawings

[0042] To more clearly illustrate the technical solutions of the embodiments of the present application, the accompanying drawings required for the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0043] Figure 1 It is a block diagram of the electronic device provided by the embodiment of the present application;

[0044] Figure 2 It is a flowchart of the Trojan horse killing method provided by the embodiment of the present application;

[0045] Figure 3 It is another part of the flowchart of the Trojan horse killing method provided by the embodiment of the present application;

[0046] Figure 4 It is a schematic diagram of the functional modules of the Trojan horse killing device provided by the embodiment of the present application. Detailed implementation manners

[0047] Next, the technical solutions in the embodiments of the present application will be described in conjunction with the accompanying drawings in the embodiments of the present application.

[0048] It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0049] .NET is a free, cross-platform, open-source developer platform for building various types of applications. Currently, more and more Trojan horses are written using.NET. Given that.NET programs are easily decompiled into source code, it is easy for antivirus software to discover the characteristics of Trojan horses using the decompiled code and thus identify them.

[0050] Based on the above situation, the inventors of the present application have studied and learned that some means are used to process existing Trojan horses in an attempt to avoid Trojan horse detection. One of the means is to use the method of shelling to protect and avoid Trojan horse detection. For example, using the open-source ConfuserEx shelling program to protect.NET Trojan horses can obfuscate the code therein, thereby achieving the purpose of avoiding Trojan horse detection. Another means is to save the binary file of the.NET Trojan horse in an array in the form of local variables and use the reflection technology in.NET to load the data in the array, thereby achieving the purpose of avoiding Trojan horse detection.

[0051] The trojan horse anti-detection achieved by the above two means can be detected and killed in the following ways: For the method of anti-detection of.NET trojan horses using a shelling tool, anti-virus software generally has a shell detection function and can identify the used shell. Since the protection modes such as process obfuscation used are relatively fixed, a corresponding de-obfuscation tool can be developed to restore the.NET trojan horse, thereby achieving static detection and killing. For the case where the plaintext binary data of the.NET trojan horse is saved in an array in the form of local variables, by analyzing the anti-detected file, analyzing the code part that loads the binary data through reflection, and extracting the data in the local variable array, the original data of the.NET trojan horse can be restored, thereby achieving static detection and killing.

[0052] However, the anti-detection means of trojan horses may be continuously updated. The embodiments of the present application provide a means to actively design ways that may lead to trojan horse anti-detection, so as to provide countermeasures against the actively studied trojan horse anti-detection methods, thereby improving the static analysis ability of anti-virus software. The trojan horse detection and killing method provided by the present application will be described below through several embodiments.

[0053] To facilitate the understanding of this embodiment, the electronic device that executes the trojan horse detection and killing method disclosed in the embodiments of the present application will be introduced in detail first.

[0054] As Figure 1 shown, it is a block diagram of the electronic device. The electronic device 100 may include a memory 111 and a processor 113. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the electronic device 100. For example, the electronic device 100 may also include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 shown.

[0055] The above-mentioned memory 111 and processor 113 are electrically connected directly or indirectly to each other to achieve data transmission or interaction. For example, these components may be electrically connected to each other through one or more communication buses or signal lines. The above-mentioned processor 113 is used to execute the executable module stored in the memory.

[0056] Among them, the memory 111 can be, but is not limited to, Random Access Memory (RAM), Read Only Memory (ROM), Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electric Erasable Programmable Read-Only Memory (EEPROM), etc. Among them, the memory 111 is used to store programs. After receiving an execution instruction, the processor 113 executes the program. The method executed by the electronic device 100 defined by the process disclosed in any embodiment of this application can be applied to or implemented by the processor 113.

[0057] The above-mentioned processor 113 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor 113 can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a digital signal processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0058] Optionally, the electronic device 100 can be a terminal device. For example, the terminal device can be a personal computer (PC), a tablet computer, a smart phone, a personal digital assistant (PDA), etc. The electronic device 100 can also be a server, and the server can be a network server, etc.

[0059] The electronic device 100 in this embodiment can be used to execute each step in the various methods provided in the embodiments of this application. The implementation process of the Trojan horse killing method will be described in detail through several embodiments below.

[0060] Please refer to Figure 2, is the flowchart of the Trojan horse killing method provided by the embodiments of the present application. The following will Figure 2 elaborate in detail on the specific process shown.

[0061] Step 210, obtain the target Trojan horse that has not been killed.

[0062] In this embodiment, the target Trojan horse that has not been killed can be a Trojan horse different from the above-mentioned shelled Trojan horse or the Trojan horse whose binary data is stored in local variables.

[0063] Exemplarily, the above-mentioned target Trojan horse can be a Trojan horse encrypted using an encryption algorithm.

[0064] Among them, the encryption algorithm can be a symmetric encryption algorithm or an asymmetric encryption algorithm.

[0065] Exemplarily, the Trojan horse killing method in the embodiments of the present application is used in the debugging and training stage of the anti-virus software. By designing various types of Trojan horses to run in the anti-virus environment, the Trojan horses that cannot be killed currently are determined, and then the Trojan horses that cannot be killed are further killed to achieve the anti-virus ability of training the anti-virus software.

[0066] When the Trojan horse killing method in this embodiment is used in the debugging and training stage of the anti-virus software, step 210 may include step 211 and step 212.

[0067] Step 211, in the anti-virus environment, execute one or more Trojan horses processed in a specified manner.

[0068] Exemplarily, the above-mentioned specified processing method can be to encrypt the original Trojan horse through an encryption algorithm; it can also be to protect the.NET Trojan horse with the open-source ConfuserEx shelling program; it can also be to save the binary file of the.NET Trojan horse in an array in the form of local variables.

[0069] Step 212, obtain the target Trojan horse that has not been killed among the one or more Trojan horses.

[0070] Among them, if a Trojan horse is not killed, it means that the anti-detection means used by the Trojan horse is different from the existing known anti-detection means, and new killing means need to be adopted for killing.

[0071] Step 220, perform decompilation processing on the target Trojan horse to determine the functional data address of the target Trojan horse.

[0072] Exemplarily, the functional data address can be the binary data address of the target Trojan horse.

[0073] In this embodiment, through decompilation, the entry point method can be determined to further determine the method acting on the binary data address.

[0074] In this embodiment, the target Trojan can be decompiled first to determine the loading method of the file of the target Trojan; the functional data address of the target Trojan is determined according to the loading method.

[0075] Exemplarily, the above loading method can be obtained in the following way: the target Trojan is decompiled first to determine the entry point method of the target Trojan; the loading method of the file of the target Trojan is determined according to the entry point method.

[0076] Exemplarily, the method of calling the dynamic loading assembly can be determined according to this entry point method. For example, the method of calling the dynamic loading assembly can be the Load method of Assembly.

[0077] Step 230, according to the functional data address, determine the decryption algorithm and the first key of the functional data.

[0078] Exemplarily, after determining the functional data address, the decryption algorithm and the first key for operating the functional data in the functional data address can be determined by decompilation.

[0079] The decryption algorithm can be RSA decryption algorithm, AES (Advanced Encryption Standard, Chinese name: Advanced Encryption Standard) decryption algorithm, XOR decryption algorithm, RC4 decryption algorithm, etc.

[0080] Exemplarily, the first key can be the key for encrypting the plaintext target Trojan.

[0081] Step 240, decrypt the encrypted target Trojan according to the decryption algorithm and the first key.

[0082] Exemplarily, the above step 240 may include: determining the storage location of the encrypted target Trojan according to the decryption algorithm and the first key operating on the data source; obtaining the encrypted Trojan in the storage location; using the decryption algorithm and the first key to decrypt the encrypted Trojan.

[0083] In one example, the GetManifestResourceStream function can be determined according to the address of the input data of the decryption algorithm; further, the storage location of the encrypted target Trojan can be found through the GetManifestResourceStream function.

[0084] In another example, the GetField function can be determined based on the address of the input data of the decryption algorithm. Further, the storage location of the encrypted target Trojan can be found through the GetField function.

[0085] Step 250: Scan and kill the decrypted target Trojan.

[0086] Through the above process, by decompiling the Trojan, based on the execution process of the Trojan, the hiding means of the Trojan are reversely speculated. By analyzing information such as the encryption algorithm used by the Trojan and the location of the encrypted Trojan, the encrypted Trojan can be decrypted to achieve the positioning and killing of the Trojan, which can improve the security of the computer and the killing ability of the computer.

[0087] In this embodiment, possible Trojan anti-detection methods can be actively designed to study the killing means of anti-virus software based on the Trojan that has been processed for Trojan anti-detection designed.

[0088] In this embodiment, as Figure 3 shown, the above-mentioned target Trojan can be constructed in the following manner.

[0089] Step 310: Obtain the plaintext Trojan.

[0090] Step 320: Obtain the target encryption algorithm from the preset encryption algorithms, and use the target encryption algorithm and the second key to encrypt the plaintext Trojan to obtain the ciphertext Trojan.

[0091] In order to store the plaintext Trojan, the plaintext Trojan can be encrypted through an encryption algorithm to hide the Trojan. Further, in order to increase the difficulty of detecting and killing the Trojan, multiple encryption algorithms for encrypting the plaintext Trojan are also designed to improve the anti-detection ability of the designed Trojan. By improving the anti-detection ability of the Trojan, countermeasures can be designed based on the Trojan with high anti-detection ability to further improve the anti-virus ability of the anti-virus software.

[0092] Exemplarily, the preset encryption algorithm can be a symmetric encryption algorithm or an asymmetric encryption algorithm.

[0093] Optionally, the preset encryption algorithm can include one or more encryption algorithms. The preset encryption algorithm can be one or more of the RSA encryption algorithm, the AES (Advanced Encryption Standard) encryption algorithm, the XOR encryption algorithm, and the RC4 encryption algorithm.

[0094] If the preset encryption algorithms include multiple encryption algorithms, when determining the target encryption algorithm, one algorithm can be randomly selected from the multiple preset encryption algorithms to encrypt the plaintext password.

[0095] If the preset encryption algorithms include multiple encryption algorithms, a specified number of target encryption algorithms can be determined from the multiple encryption algorithms. The specified number can be values such as 1, 2, 3, etc. When the specified number is greater than one, the plaintext Trojan can be encrypted in multiple rounds in sequence.

[0096] Exemplarily, the second key can be a randomly generated key. Optionally, the length of the second key can be 256 bits, or it can also be 128 bits. The key length can also be one byte.

[0097] Among them, the second key can be the same as the first key. Further, only when the first key and the second key are the same can the killing of the target Trojan be achieved.

[0098] Step 330, store the encrypted Trojan, the decryption algorithm corresponding to the target encryption algorithm, and the second key into a template file to determine the target Trojan file.

[0099] Exemplarily, the storage location of the encrypted Trojan can be a hosted resource, a field in a class, etc.

[0100] When the target Trojan needs to be run, the target Trojan file can be read through a running program, the key in the target Trojan file can be obtained, and the encrypted Trojan can be decrypted with this key to obtain the plaintext Trojan, and then the plaintext Trojan can be executed.

[0101] Exemplarily, the plaintext Trojan can be executed by using the method of reflection.

[0102] Through the above design method, the anti-detection ability of the Trojan can be higher, and thus based on the design of killing the Trojan with higher anti-detection ability, the killing ability of the anti-virus software can also be higher.

[0103] Next, through several specific examples, the anti-detection process of the Trojan provided by the embodiments of the present application, as well as the running and killing processes of the Trojan after anti-detection processing, will be described.

[0104] In one example, the target Trojan can be the KeyBase Trojan, and the KeyBase Trojan uses the startup folder or the registry startup item to achieve persistence.

[0105] The steps for anti - detection of the KeyBase Trojan are as follows: Read the KeyBase Trojan file; Select the AES encryption algorithm for encrypting the KeyBase Trojan file from the preset encryption algorithms; Generate a random encryption key; Use the encryption key and the AES encryption algorithm to encrypt the KeyBase Trojan file; Finally, read the template file, write the AES decryption algorithm and the encryption key into the template, inject the encryption key into the template file, and store the encrypted Trojan in the template file. For example, the storage location of the encrypted Trojan can be a managed resource.

[0106] The following steps can be used to execute the KeyBase Trojan after anti - detection processing: The assembly execution module reads the encryption key in the template file; Reads the encrypted Trojan from the managed resource and decrypts the encrypted Trojan using the decryption algorithm corresponding to the current encryption algorithm; Calls the Load method of Assembly to load the decrypted Trojan; Obtains the entry - point method of the loaded assembly and calls the Invoke function of the entry - point method to execute the KeyBase Trojan.

[0107] For the KeyBase Trojan processed using the above anti - detection process, the following process can be used to achieve detection: Read the KeyBase Trojan that has not been detected; Decompile the KeyBase Trojan; Find the entry - point method and search for the Load method of Assembly near the Load method of Assembly at the entry - point; According to the Load method of Assembly, find the address of the loaded binary data; According to the address of the loaded binary data, determine the decryption algorithm and key of the binary data that operates on the binary data address; According to the input data address of the decryption algorithm here, the GetManifestResourceStream function can be determined, so as to find the storage location of the encrypted Trojan; Then, read the encrypted KeyBase Trojan in the managed resource; Finally, use the decryption algorithm and key to decrypt the KeyBase Trojan; Save the decrypted Trojan as the file before encryption, thus achieving static detection.

[0108] In another instance, the target Trojan can be the Prodecryptor Trojan, which is a type of ransomware.

[0109] The steps for anti-detection of the Prodecryptor Trojan are as follows: Read the Prodecryptor Trojan file; Select the XOR encryption algorithm from the preset encryption algorithms; Generate a random key; Encrypt the Prodecryptor Trojan file using the XOR algorithm; Read the template file, inject the XOR algorithm into the template file, inject the encryption key into the template file, and store the encrypted Trojan in the template file; Among them, the encrypted Trojan can be stored in a field in the class.

[0110] The execution process of the encrypted Prodecryptor Trojan can be as follows: Read the key; Read the encrypted Prodecryptor Trojan from the field in the class; Decrypt the encrypted Prodecryptor Trojan using the XOR decryption algorithm; Call the Load method of Assembly to load the decrypted Prodecryptor Trojan; Obtain the entry point method of the loaded assembly, and call the Invoke function of the entry point method to execute the decrypted Prodecryptor Trojan.

[0111] For the Prodecryptor Trojan processed using the above anti-detection process, the following process can be adopted to achieve detection: Read the anti-detected Prodecryptor Trojan; Decompile the Prodecryptor Trojan; Determine the entry point method, and determine the Load method of Assembly based on this entry point method; Based on the Load method of Assembly, find the address of the loaded binary data; Based on the address of the loaded binary data, find the XOR decryption algorithm and the key; Based on the input data address of the XOR algorithm, continue to find the GetField function, so as to find the storage location of the encrypted Prodecryptor Trojan; Read the encrypted Prodecryptor Trojan from the field; Use the XOR decryption algorithm and the key to decrypt the encrypted Prodecryptor Trojan; Save the decrypted encrypted Prodecryptor Trojan as the file before encryption, so as to achieve static detection.

[0112] The Trojan detection method in this embodiment may further include: Step 260, update the current anti-virus software according to the detection process of the target Trojan.

[0113] Exemplarily, the anti-virus process of the anti-virus software can be determined according to Steps 210 to 250, and the current anti-virus software can be updated.

[0114] The method in this embodiment can be applied to a server that provides antivirus software-related servers. After the server updates the antivirus software, it can send an update prompt message to the terminal device communicatively connected to the server, so that after receiving the update request from the terminal device, it can send the updated antivirus software to the terminal device for the terminal device to update the antivirus software.

[0115] Exemplarily, the trojan horse killing method in the embodiments of the present application can also be used in the usage stage of antivirus software in a computer to kill the trojan horses existing in the computer.

[0116] Steps 210 to 250 in this embodiment can be executed when one of the modules in the antivirus software running on a computer runs.

[0117] Through the method in the embodiments of the present application, when designing a trojan horse that evades detection, one of the encryption algorithms can be selected to encrypt the.NET trojan horse, which can increase the difficulty of writing a general decryption tool. Further, when designing a trojan horse that evades detection, the encrypted trojan horse can be stored in managed resources in a.NET program, storage locations such as fields in a class, etc., which increases the difficulty of extracting the encrypted data. Design an antivirus software based on a trojan horse that evades detection with higher difficulty, thereby improving the antivirus ability of the antivirus software.

[0118] Further, in the embodiments of the present application, by dynamically loading the binary data address, further finding the decryption algorithm and key for operating the binary data, and according to the decryption algorithm, key, and data source of the operation, further finding the storage location of the encrypted trojan horse, the killing of a trojan horse with high anti-detection ability can be realized.

[0119] Based on the same inventive concept, the embodiments of the present application also provide a trojan horse killing device corresponding to the trojan horse killing method. Since the principle of solving problems by the device in the embodiments of the present application is similar to that of the foregoing trojan horse killing method embodiments, the implementation of the device in this embodiment can refer to the description in the method embodiments above, and the repeated parts will not be elaborated.

[0120] Please refer to Figure 4 , which is a schematic diagram of the functional modules of the trojan horse killing device provided by the embodiments of the present application. Each module in the trojan horse killing device in this embodiment is used to execute each step in the above method embodiment. The trojan horse killing device includes: an acquisition module 310, a first determination module 320, a second determination module 330, a decryption module 340, and a killing module 350. The content of each module is as follows:

[0121] The acquisition module 310 is used to acquire a target trojan horse that has not been killed;

[0122] The first determination module 320 is configured to perform decompilation processing on the target Trojan to determine the functional data address of the target Trojan.

[0123] The second determination module 330 is configured to determine the decryption algorithm and the first key of the functional data according to the functional data address.

[0124] The decryption module 340 is configured to decrypt the encrypted target Trojan according to the decryption algorithm and the first key.

[0125] The killing module 350 is configured to kill the decrypted target Trojan.

[0126] In a possible implementation manner, the first determination module 320 includes a method determination unit and an address determination unit.

[0127] The method determination unit is configured to perform decompilation processing on the target Trojan to determine the loading method of the file of the target Trojan.

[0128] The address determination unit is configured to determine the functional data address of the target Trojan according to the loading method.

[0129] In a possible implementation manner, the method determination unit is configured to:

[0130] Perform decompilation processing on the target Trojan to determine the entry point method of the target Trojan;

[0131] Determine the loading method of the file of the target Trojan according to the entry point method.

[0132] In a possible implementation manner, the decryption module is configured to:

[0133] Determine the storage location of the encrypted target Trojan according to the decryption algorithm and the first key operation data source;

[0134] Obtain the encrypted Trojan in the storage location;

[0135] Decrypt the encrypted Trojan using the decryption algorithm and the first key.

[0136] In a possible implementation manner, the killing module is configured to:

[0137] Execute one or more Trojans processed in a specified manner in a virus killing environment;

[0138] Obtain the target Trojan that has not been killed among the one or more Trojans.

[0139] In a possible implementation manner, the target Trojan is constructed in the following manner:

[0140] Obtain the plaintext Trojan horse;

[0141] Obtain a target encryption algorithm from a preset encryption algorithm, and use the target encryption algorithm and a second key to encrypt the plaintext Trojan horse to obtain a ciphertext Trojan horse;

[0142] Store the ciphertext Trojan horse, the decryption algorithm corresponding to the target encryption algorithm, and the second key in a template file to determine a target Trojan file.

[0143] In a possible implementation manner, the Trojan horse killing device provided by the embodiments of the present application may further include:

[0144] An update module, configured to update the current antivirus software according to the killing process of the target Trojan horse.

[0145] In addition, the embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the Trojan horse killing method described in the above method embodiments.

[0146] The computer program product of the Trojan horse killing method provided by the embodiments of the present application includes a computer-readable storage medium storing program codes. The instructions included in the program codes can be used to execute the steps of the Trojan horse killing method described in the above method embodiments. For details, refer to the above method embodiments, which will not be elaborated here.

[0147] In several embodiments provided by the present application, it should be understood that the disclosed device and method can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of the device, method, and computer program product according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code includes one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0148] In addition, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0149] If the above-mentioned function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes. It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprises", "comprising", or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or device. Without further limitation, the elements defined by the statement "comprising..." do not exclude the presence of additional identical elements in the process, method, article, or device comprising the said elements.

[0150] The foregoing are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0151] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all of them should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A Trojan horse killing method, characterized in that, Including: In a virus-killing environment, execute one or more Trojans processed in a specified manner; Obtain the target Trojan that has not been detected and killed among the one or more Trojans; Perform decompilation processing on the target Trojan to determine the functional data address of the target Trojan; According to the functional data address, determine the decryption algorithm and the first key of the functional data; According to the decryption algorithm and the first key, decrypt the encrypted target Trojan; Perform detection and killing on the decrypted target Trojan; Wherein, the target Trojan is constructed in the following manner: obtain a plaintext Trojan; obtain a target encryption algorithm from a preset encryption algorithm, and use the target encryption algorithm and a second key to perform encryption processing on the plaintext Trojan to obtain a ciphertext Trojan; store the ciphertext Trojan, the decryption algorithm corresponding to the target encryption algorithm, and the second key in a template file to determine a target Trojan file; Update the current anti-virus software according to the detection and killing process of the target Trojan, wherein the detection and killing process determines the anti-virus software detection and killing process according to the above detection and killing steps.

2. The method according to claim 1, wherein The performing decompilation processing on the target Trojan to determine the functional data address of the target Trojan includes: Perform decompilation processing on the target Trojan to determine the loading method of the file of the target Trojan; According to the loading method, determine the functional data address of the target Trojan.

3. The method according to claim 2, wherein The performing decompilation processing on the target Trojan to determine the loading method of the file of the target Trojan includes: Perform decompilation processing on the target Trojan to determine the entry point method of the target Trojan; According to the entry point method, determine the loading method of the file of the target Trojan.

4. The method according to claim 1, characterized in that, The decrypting the encrypted target Trojan according to the decryption algorithm and the first key includes: According to the decryption algorithm and the first key operation data source, determine the storage location of the encrypted target Trojan; Obtain the encrypted Trojan in the storage location; Use the decryption algorithm and the first key to decrypt the encrypted Trojan.

5. A Trojan horse killing device, characterized in that, Including: An obtaining module, configured to execute one or more Trojans processed in a specified manner in a virus-killing environment; obtain the target Trojan that has not been detected and killed among the one or more Trojans; A first determining module, configured to perform decompilation processing on the target Trojan to determine the functional data address of the target Trojan; A second determining module, configured to determine the decryption algorithm and the first key of the functional data according to the functional data address; A decrypting module, configured to decrypt the encrypted target Trojan according to the decryption algorithm and the first key; A detecting and killing module, configured to perform detection and killing on the decrypted target Trojan; Wherein, the target Trojan is constructed in the following manner: obtain a plaintext Trojan; obtain a target encryption algorithm from a preset encryption algorithm, and use the target encryption algorithm and a second key to perform encryption processing on the plaintext Trojan to obtain a ciphertext Trojan; store the ciphertext Trojan, the decryption algorithm corresponding to the target encryption algorithm, and the second key in a template file to determine a target Trojan file; An update module, configured to update the current antivirus software according to the killing process of the target Trojan horse; wherein, the killing process determines the antivirus software killing process according to the above killing steps.

6. An electronic device, characterized in that, It includes: A processor and a memory, where the memory stores machine-readable instructions executable by the processor. When the electronic device runs, the machine-readable instructions are executed by the processor to perform the steps of the method according to any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is run by the processor, it performs the steps of the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Target program processing method, processing device and cloud service equipment

    CN102831343A