全球華文行銷知識庫網站又被植入惡意連結
2008 年 01 月 24 日 – 22:52:00全球華文行銷知識庫網站又被植入惡意連結,此惡意程式為 Infostealer.Lineage,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒。
惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:
展示影片,請看這裡。
執行之後,有下面的行為:
[DLL injection]
C:\WINDOWS\pal32.dll
[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\22085.com
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\520[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\index[1].htm
C:\WINDOWS\pal32.dll
C:\WINDOWS\system32\winpal.exe
[Added COM/BHO]
{37A5702C-E1ED-4399-A40E-9D263EDC918A}-C:\WINDOWS\pal32.dll
到目前為止 (2008/1/23 @ 23:41),下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考):
520[1].exe:
[ Trend ], "TSPY_LINEAGE.IB"
22085.com:
[ Trend ], "TSPY_LINEAGE.IB"
winpal.exe:
[ Trend ], "TSPY_LINEAGE.IB"
1[1].htm:
[ McAfee ], "Exploit-ObscuredHtml"
[ McAfee_Beta ], "Exploit-ObscuredHtml"
[ HBEDV ], "HTML/ADODB.Exploit.Gen"
[ Norman ], "Trojan JS/Exploit!ADODB.Stream.B"
[ Rising ], "Trojan.DL.VBS.Agent.xhd"
[ Grisoft ], "Virus identified Exploit"
[ WebWasher ], "Script.ADODB.Exploit.Gen"
pal32.dll:
[ IntelliTrap ], "PAK_Generic.005″
[ Alpha_Gen ], "Possible_Lneage2″
[ Symantec ], "Infostealer.Lineage"
[ Microsoft ], "[->(NSPack)]:PWS:Win32/Lineage.gen!A"
[ Kaspersky ], "PAK:NSPack, Trojan-PSW.Win32.OnLineGames.odo"
[ McAfee ], "PWS-Lineage"
[ McAfee_Beta ], "PWS-Lineage"
[ Sophos ], "Mal/Packer"
[ Nod32 ], "a variant of Win32/PSW.Lineage.DN trojan"
[ Fortinet ], "suspicious"
[ HBEDV ], "TR/Lineage.7206F05E"
[ Norman ], "Backdoor W32/Lineage.AZWJ"
[ Ikarus ], "Trojan-PWS.Win32.Delf.hh"
[ Grisoft ], "Trojan horse PSW.Lineage.AHF"
[ eAladdin ], "Suspicious File [101]"
[ quickheal ], "TrojanPSW.OnLineGames.odo"
[ vba32 ], "Trojan-PSW.Win32.OnLineGames.odo"
[ WebWasher ], "Trojan.Lineage.7206F05E"
[ bitdefender ], "Generic.Lineage.7206F05E"


“全球華文行銷知識庫網站又被植入惡意連結” 目前有 1 迴響
可以請問一下Alpha_Gen 的病毒碼要去那下載嗎????
By Anonymous on 2008 年 01 月 25 日 - 17:50:00