2007 年 01 月 30 日 – 08:56:00
惠安移民首頁又被植入惡意連結,連結是一樣的,但惡意檔案似乎被加殼程式壓過,所以,很多防毒軟體偵測不到。
因為這個網站常常被植入惡意連結,請各位暫時不要瀏覽這個網站,等我們確認他們已經修復後,會在此更新訊息 (此惡意程式會偷帳號與密碼)。
**請幫忙通知他們,謝謝**

惡意連結是放置在首頁的:

惡意程式碼的一部份為:

執行之後,有下面的行為:
[DLL injection]
C:\WINDOWS\Debug\UserMode\ACC27FC0.dll (注入某些執行程序如檔案總管等)
[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\gt0114.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ghost0119[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\gt0119[1].exe
C:\logex.txt
C:\WINDOWS\chenzi.exe
C:\WINDOWS\Debug\UserMode\ACC27FC0.dll
C:\WINDOWS\Debug\UserMode\ACC27FC0.exe
[Added COM/BHO]
{F4AEB826-71B5-4496-B79E-146897B8064F}-C:\WINDOWS\debug\userMode\ACC27FC0.dll
到目前為止,下面的防毒軟體可以偵測到這些惡意檔案:
chenzi.exe:
[ Kaspersky ], “PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact”
[ HBEDV ], “HEUR/Malware”
ghost0119[1].exe:
[ Kaspersky ], “PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact”
[ HBEDV ], “HEUR/Malware”
gt0114.exe:
[ Kaspersky ], “PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact”
[ HBEDV ], “HEUR/Malware”
gt0119[1].exe:
[ Kaspersky ], “PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact”
[ HBEDV ], “HEUR/Malware”
ACC27FC0.dll:
[ Kaspersky ], “PAK:NSPack”
[ Sophos ], “Mal/Packer”
[ Nod32 ], “probably a variant of Win32/PSW.Lineage.DN trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Malware”
[ Rising ], “[>>NsPack]:Trojan.PSW.Lineage.msb”
ACC27FC0.exe:
[ Kaspersky ], “PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact”
[ HBEDV ], “HEUR/Malware”
614.htm:
[ HBEDV ], “JS/Psyme.D”
[ Rising ], “Trojan.DL.VBS.Agent.cih”
[ Ewido ], “Downloader.Agent.m”
happy3.htm:
[ McAfee ], “VBS/Psyme”
[ Fortinet ], “JS/Psyme.CD!tr”
[ Rising ], “Trojan.DL.VBS.Psyme.cd”
惡意程式, 網站安全 | 瀏覽數:289 | 0 迴響 »