|
|
| Ê×Ò³ | ¼¼ÊõÎÄÕ | Èí¼þÏÂÔØ | ²©¿Í | ÂÛ̳ | ¾«Æ·½Ì³Ì | ºÚ¿Í¶¯» | ÊÓÆµ×ÊÔ´ | ÔÚÏß·þÎñ | ºÚ¿ÍÓÎÏ· | | ||||
|
|
||||||||
|
||||||||
|
|||||
| ¾¯Ìè×îÐÂQQ.Email È䳿 | |||||
×÷Õߣºkiller ÎÄÕÂÀ´Ô´£ºxfocus µã»÷Êý£º ¸üÐÂʱ¼ä£º2004-12-17 ![]() |
|||||
|
Ò»¡¢¸ÅÊö£º ²¡¶¾Ãû³Æ£ºEmail-Worm.Win32.VB.ac Îļþ´óС£º13.279k ±àдÓïÑÔ£ºMicrosoft Visual Basic ¿ÇÀàÐÍ£ºUPX-Scrambler RC1.x -> ©OnT®oL ½üÁ½ÈÕ£¬ÖÚ¶àQQÓû§¾³£½Óµ½±ðÈË·¢À´µÄQQÓʼþ£¬ÇëСÐIJ»Òª´ò¿ª²é¿´£¬ÒÔÃâÖÐľÂí¡£ ¸ÃÈä³æÊ¹ÓÃÎı¾Í¼±êºÍ.txt.exeÀ©Õ¹Ãûαװ×ÔÉí£¬ÓÕµ¼Óû§Ö´ÐÐÈ䳿Ìå¡£ ¶þ¡¢·ÖÎö£º£¨vvvÊDZ»ÆÁ±ÎµôµÄÁ¬½Ó£© 1¡¢ È䳿ÔËÐк󣬻ᵯ³öÒ»¸öÎļþ¸ñʽÎÞЧµÄ¶Ô»°¿ò£¬ÃÔ»óÓû§£¬²¢½«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼%system%Ϊ£º C:\WINDOWS\system32\Inetdbs.exe ÎļþÊôÐÔΪ£ºRHS ͬʱ½«×ÔÉí¼ÓÈ뵽ϵͳע²á±íÆô¶¯ÏîÄ¿£º HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ¼üÃû£ºInet DataBase ¼üÖµ£º"C:\WINDOWS\System32\Inetdbs.exe" 2¡¢È»ºóÈ䳿»áµ½£ºÃÜÂë½â°Ô¡£ 3¡¢½«ÏÂÔØµÄnew.jpg¸ÄÃûΪ~DF41F8.EXE²¢Ö´ÐС£Ö´ÐкóÊͷŽ«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼£º ¿½±´ÎļþΪ£º C:\WINDOWS\system32\mstext32.dll 7KB C:\WINDOWS\system32\ÿwowexec.exe 140KB ÆäÖÐmstext32.dllÊÇRiskWare.PSWTool.Finder.a£¬Ò»¸öÓÃÀ´½øÐÐhook ²éÕÒÃÜÂëµÄdll¿â¡£ ²¢Ôö¼Ó×¢²á±íÆô¶¯Ï HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ¼üÃû£ºMSIEXEC ¼üÖµ£º"ÿwowexec.exe" ¸ÃľÂí»¹»áÔÚ×¢²á±íÖÐÔö¼ÓÈçϼüÖµ£¬ÓÃÀ´´æ´¢×ÔÉíÉèÖ㺠HKEY_CLASSES_ROOT\ZPwd_box HKEY_CLASSES_ROOT\ZPwd_box tmUpgrade_p dword:41bfabb0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box tmUpgrade_p dword:41bfabb0 4¡¢wowexec.exe »á·ÃÎʱàºÅΪ£º163com[20030606]¡¢IP£º202.108.44.153µÄ163ÐÅÏ䣬»ñÈ¡Éý¼¶ÐÅÏ¢¡£ ¶Ë¿Ú:110 Óû§:pwdboxup ÃÜÂë:shengjile ÃÜÂë½â°ÔÊÇΣº¦±È½Ï´óµÄľÂí£¬¿ÉÒÔ»ñÈ¡¸÷ÖÖ¼°Ê±Í¨Ñ¶Èí¼þ¡¢EMAIL¡¢ÍøÂçÓÎÏ·¡¢ÍøÂçÒøÐС¢IEÖÐÊäÈëµÄ¸÷ÖÖÃÜÂëµÈ¡£ 5¡¢ÔÚÖØÆô¶¯ºóInetdbs.exe»á±»ÔËÐУ¬ÔËÐкó»áÏÂÔØhttp://www.vvv.com/b.wavÎļþ£¬¸ÃÎļþΪһzip°ü¹ü£¬ÎªÈ䳿Ìå×ÔÉí¡£ÔÚ%temp%Ŀ¼ÏÂÖØÃûΪ~DF0032.ZIP,ÓÃÀ´×÷Ϊ·¢ËÍÓʼþµÄ±¸Óø½¼þ¡£ »¹»áµ½http://freehost23.vvv.com/wpzkq/MSWINSCK.OCX¿Ø¼þ±£´æµ½%system%Ŀ¼Ï£¬È·±£ÔÚijЩϵͳÉÏÄܹ»ÕýÈ··¢ËÍEMAIL£¬¸Ã¿Ø¼þΪVB ÍøÂçÖ§³Ö¿â¡£ ͬʱ»á½«¸Ã¿Ø¼þÔÚ×¢²á±íµÄMSWinsock.WinsockºÍClassid½øÐÐ×¢²á¡£ 6¡¢Inetdbs.exe »áÄ£·ÂFOXMAIL 5.0 ½øÐз¢ËÍÀ¬»øÓʼþ£º Óʼþ±êÌâΪÏÂÃæÆäÖÐÒ»ÖÖ£º ÎÒ°®Äã,ÎÒÏëÄã,Äãϲ»¶ÎÒÂð,ÖØÒª,¾øÃÜ,ÎҵļòÀú,ÇóÖ°Êé,ÇóÖ°ÐÅ,ÎÒѧ¼ÆËã»ú,ÓÐûÓпյÄÖ°Îñ,ÉúÈÕ¿ìÀÖ,ÄãºÃ¿É°®,×Ô¼öÊé,ÉêÇëÊé,Çë¼í,¾®¸ÔɽÈýÈÕÓÎ,Ì칤ÂÃÓι«Ë¾,ϵͳ²¹¶¡,ÍÆ¹ã׬Ǯ¼¼Êõ,¼¤ÇéÍòÖÖ,ÑûÇë,Ãâ·Ñ»áÔ±,Äã°®ÎÒÂð,ÄãÏëÎÒÂð,¶Ô²»Æð£¬±ðÉúÆø,µÀǸ ÄÚÈÝΪÏÂÃæÒ»ÖÖ£º ÏêÇé²é¿´¸½¼þ,ÖØÒªÎļþ,¾ÍÒª¸½¼þÖÐ,×¢Òâ²éÊÕ,Á¢¼´²é¿´,×÷Æ·,Îļþ,Îĵµ,ÏêÇé,¸½¼þÖÐ,ѹËõ°üÄÚ,ѹËõ°ü,½âѹ¼´¿É,´ò¿ªÑ¹Ëõ°ü,¿´ÁËûÓÐ 7¡¢·¢ËÍÀ¬»øÓʼþ¹ý³Ì£º 220 qs20.qq.com ESMTP QQ Mail Server HELO XPPROSP1 250 qs20.qq.com mail from: ockt@uixj.com 250 Ok rcpt to: 97986@qq.com 250 Ok DATA 354 End data with . From: ockt@uixj.com Date: Wed, 15 Dec 2004 13:59:55 +0800 X-Mailer: Foxmail 5.0 [cn] To: 97986@qq.com Subject: ÓÎÏ·±Ò·ÀµÁר¼Ò Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="=====line_63193098=====" This is a multi-part message in MIME format. --=====line_63193098===== Content-Type: text/plain; charset="GB2312" Content-Transfer-Encoding: 7bit ¸½¼þÖÐ --=====line_63193098===== Content-Type: application/octet-stream; name="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip" ... Èý¡¢½â¾ö°ì·¨£º ¸ù¾Ý·ÖÎöɾ³ý¶ÔÓ¦Îļþ£¬»Ö¸´×¢²á±í¼üÖµ¡£ ¸Ðл: benjurry ¼°Ê±ÌáÐÑ£¬²¢ÌṩÑù±¾¡£ |
|||||
| ÎÄÕ¼È룺IceRiver ÔðÈα༣ºIceRiver | |||||
| ¡¾·¢±íÆÀÂÛ¡¿¡¾¼ÓÈëÊղء¿¡¾¸æËߺÃÓÑ¡¿¡¾´òÓ¡´ËÎÄ¡¿¡¾¹Ø±Õ´°¿Ú¡¿ | |||||
¡¡ ¡¡ÍøÓÑÆÀÂÛ£º£¨Ö»ÏÔʾ×îÐÂ5Ìõ¡£ÆÀÂÛÄÚÈÝÖ»´ú±íÍøÓѹ۵㣬Óë±¾Õ¾Á¢³¡Î޹أ¡£© |
| ¹ØÓÚÎÒÃÇ - °æÈ¨ÉùÃ÷ - °ïÖú(£¿) - ¹ã¸æ·þÎñ - ÁªÏµÎÒÃÇ - ÓÑÇéÁ´½Ó - Óû§×¢²á - | Powered by ICE RIVER - STUDIO |
| » CnXHacker.CoM | © CopyRight 2002-2006, CnXHacker.CoM™, Inc. All Rights Reserved. |