Ê×Ò³ | QQ¿Õ¼ä | QQ¸öÐÔ | QQ¼¼Êõ | QQ³èÎï | QQÓÎÏ· | QQºØ¿¨ | QQÏÂÔØ | QQƤ·ô | QQ³¡¾° | QQÍ·Ïñ | QQ±íÇé | QQ×ÀÃæ | QQÀÖÔ° | QQ¸ãЦ | QQ¹¤¾ß
QQ¼¼ÊõÊ×Ò³ ¡ú QQÐÂÎÅ - QQ¼¼ÇÉ - QQ֪ʶ - QQ°²È«Ö¸ÄÏ - QQ²¡¶¾ÓëľÂí - QQ¹¥»÷Óë·À·¶ - QQÃÜÂëÓëºÅÂë
¡úÄúÏÖÔÚµÄλÖ㺠ÖйúQQÌì¿Õ >> QQ¼¼Êõ >> QQ°²È« >> QQ°²È«Ö¸ÄÏ >> ÎÄÕÂÄÚÈÝ

¾¯Ìè×îÐÂQQ.Email È䳿

¸üÐÂʱ¼ä£º2006-4-12 20:14:19¡¡

Ò»¡¢¸ÅÊö£º

²¡¶¾Ãû³Æ£ºEmail-Worm.Win32.VB.ac
Îļþ´óС£º13.279k
±àдÓïÑÔ£ºMicrosoft Visual Basic
¿ÇÀàÐÍ£ºUPX-Scrambler RC1.x -> ©OnT®oL


½üÁ½ÈÕ£¬ÖÚ¶àQQÓû§¾­³£½Óµ½±ðÈË·¢À´µÄQQÓʼþ£¬ÇëСÐIJ»Òª´ò¿ª²é¿´£¬ÒÔÃâÖÐľÂí¡£
¸ÃÈä³æÊ¹ÓÃÎı¾Í¼±êºÍ.txt.exeÀ©Õ¹Ãûαװ×ÔÉí£¬ÓÕµ¼Óû§Ö´ÐÐÈ䳿Ìå¡£


¶þ¡¢·ÖÎö£º£¨vvvÊDZ»ÆÁ±ÎµôµÄÁ¬½Ó£©

  1¡¢ È䳿ÔËÐк󣬻ᵯ³öÒ»¸öÎļþ¸ñʽÎÞЧµÄ¶Ô»°¿ò£¬ÃÔ»óÓû§£¬²¢½«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼%system%Ϊ£º
 
     C:\WINDOWS\system32\Inetdbs.exe ÎļþÊôÐÔΪ£ºRHS
    
     ͬʱ½«×ÔÉí¼ÓÈ뵽ϵͳע²á±íÆô¶¯ÏîÄ¿£º
     HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    
     ¼üÃû£ºInet DataBase ¼üÖµ£º"C:\WINDOWS\System32\Inetdbs.exe"
 
  2¡¢È»ºóÈ䳿»áµ½£ºÃÜÂë½â°Ô¡£

  3¡¢½«ÏÂÔØµÄnew.jpg¸ÄÃûΪ~DF41F8.EXE²¢Ö´ÐС£Ö´ÐкóÊͷŽ«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼£º
  
     ¿½±´ÎļþΪ£º
     C:\WINDOWS\system32\mstext32.dll    7KB       
     C:\WINDOWS\system32\ÿwowexec.exe    140KB
    
     ÆäÖÐmstext32.dllÊÇRiskWare.PSWTool.Finder.a£¬Ò»¸öÓÃÀ´½øÐÐhook ²éÕÒÃÜÂëµÄdll¿â¡£
  
     ²¢Ôö¼Ó×¢²á±íÆô¶¯Ï
    
     HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
     ¼üÃû£ºMSIEXEC    ¼üÖµ£º"ÿwowexec.exe"
    
     ¸ÃľÂí»¹»áÔÚ×¢²á±íÖÐÔö¼ÓÈçϼüÖµ£¬ÓÃÀ´´æ´¢×ÔÉíÉèÖãº
    
     HKEY_CLASSES_ROOT\ZPwd_box       
         HKEY_CLASSES_ROOT\ZPwd_box    tmUpgrade_p    dword:41bfabb0
         HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box       
         HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box    tmUpgrade_p    dword:41bfabb0

   4¡¢wowexec.exe »á·ÃÎʱàºÅΪ£º163com[20030606]¡¢IP£º202.108.44.153µÄ163ÐÅÏ䣬»ñÈ¡Éý¼¶ÐÅÏ¢¡£
  
      ¶Ë¿Ú:110
      Óû§:pwdboxup
      ÃÜÂë:shengjile
     
      ÃÜÂë½â°ÔÊÇΣº¦±È½Ï´óµÄľÂí£¬¿ÉÒÔ»ñÈ¡¸÷ÖÖ¼°Ê±Í¨Ñ¶Èí¼þ¡¢EMAIL¡¢ÍøÂçÓÎÏ·¡¢ÍøÂçÒøÐС¢IEÖÐÊäÈëµÄ¸÷ÖÖÃÜÂëµÈ¡£
     
     
   5¡¢ÔÚÖØÆô¶¯ºóInetdbs.exe»á±»ÔËÐУ¬ÔËÐкó»áÏÂÔØhttp://www.vvv.com/b.wavÎļþ£¬¸ÃÎļþΪһzip°ü¹ü£¬ÎªÈ䳿Ìå×ÔÉí¡£ÔÚ%temp%Ŀ¼ÏÂÖØÃûΪ~DF0032.ZIP,ÓÃÀ´×÷Ϊ·¢ËÍÓʼþµÄ±¸Óø½¼þ¡£
      »¹»áµ½http://freehost23.vvv.com/wpzkq/MSWINSCK.OCX¿Ø¼þ±£´æµ½%system%Ŀ¼Ï£¬È·±£ÔÚijЩϵͳÉÏÄܹ»ÕýÈ··¢ËÍEMAIL£¬¸Ã¿Ø¼þΪVB ÍøÂçÖ§³Ö¿â¡£
      ͬʱ»á½«¸Ã¿Ø¼þÔÚ×¢²á±íµÄMSWinsock.WinsockºÍClassid½øÐÐ×¢²á¡£
     
     
   6¡¢Inetdbs.exe »áÄ£·ÂFOXMAIL 5.0 ½øÐз¢ËÍÀ¬»øÓʼþ£º
  
      Óʼþ±êÌâΪÏÂÃæÆäÖÐÒ»ÖÖ£º
     
      ÎÒ°®Äã,ÎÒÏëÄã,Äãϲ»¶ÎÒÂð,ÖØÒª,¾øÃÜ,ÎҵļòÀú,ÇóÖ°Êé,ÇóÖ°ÐÅ,ÎÒѧ¼ÆËã»ú,ÓÐûÓпյÄÖ°Îñ,ÉúÈÕ¿ìÀÖ,ÄãºÃ¿É°®,×Ô¼öÊé,ÉêÇëÊé,Çë¼í,¾®¸ÔɽÈýÈÕÓÎ,Ì칤ÂÃÓι«Ë¾,ϵͳ²¹¶¡,ÍÆ¹ã׬Ǯ¼¼Êõ,¼¤ÇéÍòÖÖ,ÑûÇë,Ãâ·Ñ»áÔ±,Äã°®ÎÒÂð,ÄãÏëÎÒÂð,¶Ô²»Æð£¬±ðÉúÆø,µÀǸ
     
     
      ÄÚÈÝΪÏÂÃæÒ»ÖÖ£º
     
      ÏêÇé²é¿´¸½¼þ,ÖØÒªÎļþ,¾ÍÒª¸½¼þÖÐ,×¢Òâ²éÊÕ,Á¢¼´²é¿´,×÷Æ·,Îļþ,Îĵµ,ÏêÇé,¸½¼þÖÐ,ѹËõ°üÄÚ,ѹËõ°ü,½âѹ¼´¿É,´ò¿ªÑ¹Ëõ°ü,¿´ÁËûÓÐ
  
   7¡¢·¢ËÍÀ¬»øÓʼþ¹ý³Ì£º
  
220 qs20.qq.com ESMTP QQ Mail Server
HELO XPPROSP1
250 qs20.qq.com
mail from: ockt@uixj.com
250 Ok
rcpt to: 97986@qq.com
250 Ok
DATA
354 End data with .
From: ockt@uixj.com
Date: Wed, 15 Dec 2004 13:59:55 +0800
X-Mailer: Foxmail 5.0 [cn]
To: 97986@qq.com
Subject: ÓÎÏ·±Ò·ÀµÁר¼Ò
Mime-Version: 1.0
Content-Type: multipart/mixed;
    boundary="=====line_63193098====="


This is a multi-part message in MIME format.

--=====line_63193098=====
Content-Type: text/plain;
    charset="GB2312"
Content-Transfer-Encoding: 7bit

¸½¼þÖÐ
--=====line_63193098=====
Content-Type: application/octet-stream;
    name="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
    filename="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip"

...


  
  
Èý¡¢½â¾ö°ì·¨£º


   ¸ù¾Ý·ÖÎöɾ³ý¶ÔÓ¦Îļþ£¬»Ö¸´×¢²á±í¼üÖµ¡£

  • ÉÏһƪÎÄÕ£º
  • ÏÂһƪÎÄÕ£º
  • ¾«²ÊÍÆ¼ö
    :::::: Êղر¾Õ¾ £ü ¹ØÓÚÎÒÃÇ £ü °æÈ¨ÉêÃ÷ £ü ÁªÏµÎÒÃÇ £ü ¹ã¸æ·þÎñ £ü ÓÑÇéÁ´½Ó £ü ÍøÕ¾µØÍ¼ ::::::
    © CopyRight 2006 - 2008, QQskycn.com, Inc. All Rights Reserved
    ¶õICP±¸06009991ºÅ