| Ê×Ò³ | ¼¼ÊõÎÄÕ | Èí¼þÏÂÔØ | ²©¿Í | ÂÛ̳ | ¾«Æ·½Ì³Ì | ºÚ¿Í¶¯»­ | ÊÓÆµ×ÊÔ´ | ÔÚÏß·þÎñ | ºÚ¿ÍÓÎÏ· | 

ÄúÏÖÔÚµÄλÖ㺠ÖйúXºÚ¿ÍС×é >> ¼¼ÊõÎÄÕ >> ÐÂÎÅÖÐÐÄ >> ²¡¶¾¹«¸æ >> ÎÄÕÂÕýÎÄ Óû§µÇ¼ ÐÂÓû§×¢²á
  ¾¯Ìè×îÐÂQQ.Email È䳿    ÈÈ     ¡ï¡ï¡ï ¡¾×ÖÌ壺С ´ó¡¿
¾¯Ìè×îÐÂQQ.Email È䳿
×÷Õߣºkiller    ÎÄÕÂÀ´Ô´£ºxfocus    µã»÷Êý£º    ¸üÐÂʱ¼ä£º2004-12-17    

Ò»¡¢¸ÅÊö£º

²¡¶¾Ãû³Æ£ºEmail-Worm.Win32.VB.ac
Îļþ´óС£º13.279k
±àдÓïÑÔ£ºMicrosoft Visual Basic
¿ÇÀàÐÍ£ºUPX-Scrambler RC1.x -> ©OnT®oL


½üÁ½ÈÕ£¬ÖÚ¶àQQÓû§¾­³£½Óµ½±ðÈË·¢À´µÄQQÓʼþ£¬ÇëСÐIJ»Òª´ò¿ª²é¿´£¬ÒÔÃâÖÐľÂí¡£
¸ÃÈä³æÊ¹ÓÃÎı¾Í¼±êºÍ.txt.exeÀ©Õ¹Ãûαװ×ÔÉí£¬ÓÕµ¼Óû§Ö´ÐÐÈ䳿Ìå¡£


¶þ¡¢·ÖÎö£º£¨vvvÊDZ»ÆÁ±ÎµôµÄÁ¬½Ó£©

  1¡¢ È䳿ÔËÐк󣬻ᵯ³öÒ»¸öÎļþ¸ñʽÎÞЧµÄ¶Ô»°¿ò£¬ÃÔ»óÓû§£¬²¢½«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼%system%Ϊ£º
  
     C:\WINDOWS\system32\Inetdbs.exe ÎļþÊôÐÔΪ£ºRHS
     
     Í¬Ê±½«×ÔÉí¼ÓÈ뵽ϵͳע²á±íÆô¶¯ÏîÄ¿£º
     HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
     
     ¼üÃû£ºInet DataBase ¼üÖµ£º"C:\WINDOWS\System32\Inetdbs.exe"
  
  2¡¢È»ºóÈ䳿»áµ½£ºÃÜÂë½â°Ô¡£

  3¡¢½«ÏÂÔØµÄnew.jpg¸ÄÃûΪ~DF41F8.EXE²¢Ö´ÐС£Ö´ÐкóÊͷŽ«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼£º
  
     ¿½±´ÎļþΪ£º
     C:\WINDOWS\system32\mstext32.dll    7KB        
     C:\WINDOWS\system32\ÿwowexec.exe    140KB
     
     ÆäÖÐmstext32.dllÊÇRiskWare.PSWTool.Finder.a£¬Ò»¸öÓÃÀ´½øÐÐhook ²éÕÒÃÜÂëµÄdll¿â¡£
   
     ²¢Ôö¼Ó×¢²á±íÆô¶¯Ï
     
     HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
     ¼üÃû£ºMSIEXEC    ¼üÖµ£º"ÿwowexec.exe"
     
     ¸ÃľÂí»¹»áÔÚ×¢²á±íÖÐÔö¼ÓÈçϼüÖµ£¬ÓÃÀ´´æ´¢×ÔÉíÉèÖãº
     
     HKEY_CLASSES_ROOT\ZPwd_box        
         HKEY_CLASSES_ROOT\ZPwd_box    tmUpgrade_p    dword:41bfabb0
         HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box        
         HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box    tmUpgrade_p    dword:41bfabb0

   4¡¢wowexec.exe »á·ÃÎʱàºÅΪ£º163com[20030606]¡¢IP£º202.108.44.153µÄ163ÐÅÏ䣬»ñÈ¡Éý¼¶ÐÅÏ¢¡£
   
      ¶Ë¿Ú:110
      Óû§:pwdboxup
      ÃÜÂë:shengjile
      
      ÃÜÂë½â°ÔÊÇΣº¦±È½Ï´óµÄľÂí£¬¿ÉÒÔ»ñÈ¡¸÷ÖÖ¼°Ê±Í¨Ñ¶Èí¼þ¡¢EMAIL¡¢ÍøÂçÓÎÏ·¡¢ÍøÂçÒøÐС¢IEÖÐÊäÈëµÄ¸÷ÖÖÃÜÂëµÈ¡£
      
      
   5¡¢ÔÚÖØÆô¶¯ºóInetdbs.exe»á±»ÔËÐУ¬ÔËÐкó»áÏÂÔØhttp://www.vvv.com/b.wavÎļþ£¬¸ÃÎļþΪһzip°ü¹ü£¬ÎªÈ䳿Ìå×ÔÉí¡£ÔÚ%temp%Ŀ¼ÏÂÖØÃûΪ~DF0032.ZIP,ÓÃÀ´×÷Ϊ·¢ËÍÓʼþµÄ±¸Óø½¼þ¡£
      »¹»áµ½http://freehost23.vvv.com/wpzkq/MSWINSCK.OCX¿Ø¼þ±£´æµ½%system%Ŀ¼Ï£¬È·±£ÔÚijЩϵͳÉÏÄܹ»ÕýÈ··¢ËÍEMAIL£¬¸Ã¿Ø¼þΪVB ÍøÂçÖ§³Ö¿â¡£
      Í¬Ê±»á½«¸Ã¿Ø¼þÔÚ×¢²á±íµÄMSWinsock.WinsockºÍClassid½øÐÐ×¢²á¡£
      
      
   6¡¢Inetdbs.exe »áÄ£·ÂFOXMAIL 5.0 ½øÐз¢ËÍÀ¬»øÓʼþ£º
   
      Óʼþ±êÌâΪÏÂÃæÆäÖÐÒ»ÖÖ£º
      
      ÎÒ°®Äã,ÎÒÏëÄã,Äãϲ»¶ÎÒÂð,ÖØÒª,¾øÃÜ,ÎҵļòÀú,ÇóÖ°Êé,ÇóÖ°ÐÅ,ÎÒѧ¼ÆËã»ú,ÓÐûÓпյÄÖ°Îñ,ÉúÈÕ¿ìÀÖ,ÄãºÃ¿É°®,×Ô¼öÊé,ÉêÇëÊé,Çë¼í,¾®¸ÔɽÈýÈÕÓÎ,Ì칤ÂÃÓι«Ë¾,ϵͳ²¹¶¡,ÍÆ¹ã׬Ǯ¼¼Êõ,¼¤ÇéÍòÖÖ,ÑûÇë,Ãâ·Ñ»áÔ±,Äã°®ÎÒÂð,ÄãÏëÎÒÂð,¶Ô²»Æð£¬±ðÉúÆø,µÀǸ
      
      
      ÄÚÈÝΪÏÂÃæÒ»ÖÖ£º
      
      ÏêÇé²é¿´¸½¼þ,ÖØÒªÎļþ,¾ÍÒª¸½¼þÖÐ,×¢Òâ²éÊÕ,Á¢¼´²é¿´,×÷Æ·,Îļþ,Îĵµ,ÏêÇé,¸½¼þÖÐ,ѹËõ°üÄÚ,ѹËõ°ü,½âѹ¼´¿É,´ò¿ªÑ¹Ëõ°ü,¿´ÁËûÓÐ
   
   7¡¢·¢ËÍÀ¬»øÓʼþ¹ý³Ì£º
   
220 qs20.qq.com ESMTP QQ Mail Server
HELO XPPROSP1
250 qs20.qq.com
mail from: ockt@uixj.com
250 Ok
rcpt to: 97986@qq.com
250 Ok
DATA
354 End data with .
From: ockt@uixj.com
Date: Wed, 15 Dec 2004 13:59:55 +0800
X-Mailer: Foxmail 5.0 [cn]
To: 97986@qq.com
Subject: ÓÎÏ·±Ò·ÀµÁר¼Ò
Mime-Version: 1.0
Content-Type: multipart/mixed;
    boundary="=====line_63193098====="


This is a multi-part message in MIME format.

--=====line_63193098=====
Content-Type: text/plain;
    charset="GB2312"
Content-Transfer-Encoding: 7bit

¸½¼þÖÐ
--=====line_63193098=====
Content-Type: application/octet-stream;
    name="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
    filename="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip"

...


   
   
Èý¡¢½â¾ö°ì·¨£º


   ¸ù¾Ý·ÖÎöɾ³ý¶ÔÓ¦Îļþ£¬»Ö¸´×¢²á±í¼üÖµ¡£
    
    


¸Ðл: benjurry ¼°Ê±ÌáÐÑ£¬²¢ÌṩÑù±¾¡£

ÎÄÕ¼È룺IceRiver    ÔðÈα༭£ºIceRiver 
  • ÉÏһƪÎÄÕ£º

  • ÏÂһƪÎÄÕ£º
  • ¡¾·¢±íÆÀÂÛ¡¿¡¾¼ÓÈëÊղء¿¡¾¸æËߺÃÓÑ¡¿¡¾´òÓ¡´ËÎÄ¡¿¡¾¹Ø±Õ´°¿Ú¡¿
    ×îÐÂÈȵã ×îÐÂÍÆ¼ö Ïà¹ØÎÄÕÂ
    SkypeÓû§Ð뾯ÌèÐÂWindowsÈä
    SkypeÌáÐÑÓû§¾¯ÌèÐÂP2PÈ䳿
    Ãܱ£¿¨²»ÔÙ°²È« ¾¯ÌèWOWÐÂʽ
    Alexa×îÐÂͳ¼ÆÊý¾Ý±íÃ÷ ËѺü
    ½â¾öľÂíÒþ»¼ ¾¯ÌèºÚ¿Í¿ØÖÆP
    ¾¯ÌèľÂíÏÂÔØÆ÷½«ÄúµÄµçÄÔ±ä
    µçÄÔÔËÐÐËÙ¶ÈͻȻ±äÂý¡¡¾¯Ìè
    ÇÀÏÈ¿´!QQ2008+TM2008¹¦ÄÜ×î
    ¾¯Ì裺ÓÖÒ»¸öͨ¹ý MSN´«²¥µÄ
    ÕâÖܾ¯ÌèÐÂMSN²¡¶¾
    ¡¡¡¡ÍøÓÑÆÀÂÛ£º£¨Ö»ÏÔʾ×îÐÂ5Ìõ¡£ÆÀÂÛÄÚÈÝÖ»´ú±íÍøÓѹ۵㣬Óë±¾Õ¾Á¢³¡Î޹أ¡£©
    Powered by ICE RIVER - STUDIO
    » CnXHacker.CoM   © CopyRight 2002-2006, CnXHacker.CoM™, Inc. All Rights Reserved.