惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為 (滿慘的,請各位小心一點):
[Added process]
C:\WINDOWS\sys220.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\1.exe
[DLL injection]
C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL
C:\Documents and Settings\Administrator\Local Settings\Temp\mhso0.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\qjso0.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\rxso0.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\tlso0.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\wdso0.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\ztso0.dll
C:\Program Files\Common Files\System\ado\msado15.dll
C:\Program Files\Common Files\System\msadc\msadco.dll
C:\Program Files\Common Files\System\msadc\msadcor.dll
[Added files]
在系統中建立太多的惡意檔案
到目前為止 (2007/7/12 @ 09:55),下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考):
[Logo1_.exe:
[ Trend ], "PE_LOOKED.ACX-O"
mppds.dll:
[ Symantec ], "Infostealer.Gampass"
[ Microsoft ], "PWS:Win32/Frethog.D"
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.es"
[ Fortinet ], "W32/Agent.BTI!tr.pws"
[ HBEDV ], "TR/PSW.Agent.20480″
[ Norman ], "Trojan OnlineGames.gen11″
[ Rising ], "Trojan.PSW.Win32.OnlineGames.ci"
[ Ewido ], "Trojan.OnLineGames.es"
LYMANGR.dll:
[ Symantec ], "Infostealer.Gampass"
[ Microsoft ], "VirTool:Win32/Obfuscator.C"
[ Kaspersky ], "PAK:UPack"
[ McAfee ], "Generic PWS.j"
[ Fortinet ], "suspicious"
[ HBEDV ], "HEUR/Malware"
[ Norman ], "Security Risk W32/Suspicious_U.gen"
LYLOADER.exe:
[ Alpha_Gen ], "Possible_Virus"
[ Symantec ], "Infostealer.Gampass"
[ Microsoft ], "[->(Upack)->[RSRCEmb]]:VirTool:Win32/Obfuscator.C"
[ Kaspersky ], "PAK:PE_Patch, PAK:UPack"
[ McAfee ], "New Malware.aj !!"
[ Panda ], "Suspicious file"
[ Nod32 ], "a variant of Win32/PSW.Agent.NEC trojan"
[ Fortinet ], "suspicious"
[ HBEDV ], "HEUR/Malware"
[ Norman ], "Security Risk W32/Suspicious_U.gen"
tlso0.dll:
[ Symantec ], "Infostealer.Gampass"
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.bs"
[ Fortinet ], "W32/OnlineGames.AVG!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Norman ], "Trojan W32/OnLineGames.ICJ"
[ Rising ], "Trojan.PSW.Win32.Agent.pn"
[ Ewido ], "Trojan.OnLineGames.bs"
rxso0.dll:
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.lj"
[ Panda ], "Trj/Lineage.DTB"
[ Nod32 ], "Win32/PSW.OnLineGames.NBD trojan"
[ Fortinet ], "W32/LegMir.ARC!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Rising ], "Trojan.PSW.OnlineGames.bto"
[ Ewido ], "Trojan.OnLineGames.lj"
mppds.exe:
[ Microsoft ], "PWS:Win32/Lmir.gen!J"
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.es"
[ HBEDV ], "TR/PSW.Agent.20480″
[ Rising ], "Trojan.PSW.Win32.OnlineGames.ci"
zxso0.dll:
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.qo"
[ Fortinet ], "W32/Gampass.A!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Rising ], "Trojan.PSW.Win32.WorldOnline.ja"
[ Ewido ], "Trojan.OnLineGames.qo"
ztso0.dll:
[ Symantec ], "Infostealer"
[ Kaspersky ], "Trojan-PSW.Win32.Nilage.bjp"
[ McAfee ], "PWS-LegMir.dll"
[ Nod32 ], "probably a variant of Win32/Genetik trojan"
[ Fortinet ], "W32/LegMir.BJP!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Rising ], "Trojan.PSW.Win32.OnlineGames.dfh"
wdso0.dll:
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.bs"
[ Fortinet ], "W32/OnLineGames.BS!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Rising ], "Trojan.PSW.OnlineGames.byp"
qjso0.dll:
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.bs"
[ Nod32 ], "a variant of Win32/PSW.OnLineGames.NAZ trojan"
[ Fortinet ], "W32/OnLineGames.BS!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Rising ], "Trojan.PSW.Win32.OnlineGames.del"
mhso0.dll:
[ Symantec ], "Infostealer.Gampass"
[ Microsoft ], "PWS:Win32/Legmir.E!dll"
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.yy"
[ Nod32 ], "a variant of Win32/PSW.OnLineGames.NAT trojan"
[ Fortinet ], "W32/Agent.NDP!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Rising ], "Trojan.PSW.Win32.Agent.po"
2637921.bat:
[ Kaspersky ], "Trojan.BAT.KillAV.ez"
Ravasktao.dll:
[ Alpha_Gen ], "Possible_OLGM-8″
[ Microsoft ], "PWS:Win32/Skatayo.A!dll"
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.ql"
[ McAfee ], "PWS-LegMir.dll"
[ Panda ], "Trj/Lineage.EGZ"
[ Fortinet ], "W32/LegMir.QL!tr.pws"
[ HBEDV ], "TR/Spy.Gen"
[ Rising ], "Trojan.PSW.Win32.AskTao.d"
[ Ewido ], "Trojan.OnLineGames.ql"
TIMHost.dll:
[ Symantec ], "Infostealer.Gampass"
[ Kaspersky ], "Trojan-PSW.Win32.OnLineGames.yn"
[ McAfee ], "PWS-LegMir.dll"
[ Fortinet ], "OnLine!tr"
[ HBEDV ], "TR/PSW.OnLineGames.YN.83″
[ Norman ], "Trojan W32/OnLineGames.ICK"
[ Rising ], "Trojan.PSW.Win32.RocOnline.t"
MSDEG32.dll:
[ Microsoft ], "VirTool:Win32/Obfuscator.C"
[ K
aspersky ], "PAK:UPack"
[ McAfee ], "Generic PWS.j"
[ Fortinet ], "suspicious"
[ HBEDV ], "HEUR/Malware"
[ Norman ], "Security Risk W32/Suspicious_U.gen""