惡意連結是放置在 index.asp (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為:
[Added process]
C:\WINDOWS\system32\kawdcaz.exe
C:\WINDOWS\swchost.exe
C:\WINDOWS\IGM.exe
C:\WINDOWS\IGW.exe
C:\WINDOWS\system32\avzxest.exe
C:\WINDOWS\system32\kapjdaz.exe
C:\WINDOWS\system32\raqjdtl.exe
C:\WINDOWS\system32\avwldst.exe
C:\WINDOWS\system32\ratbgtl.exe
C:\WINDOWS\system32\avwgest.exe
[DLL injection]
C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL
C:\WINDOWS\system32\avwgemn.dll
C:\WINDOWS\system32\avwldmn.dll
C:\WINDOWS\system32\avzxemn.dll
C:\WINDOWS\system32\dh3atl.dll
C:\WINDOWS\system32\dhatl.dll
C:\WINDOWS\system32\djatl.dll
C:\WINDOWS\system32\jzatl.dll
C:\WINDOWS\system32\kapjdzy.dll
C:\WINDOWS\system32\kawdczy.dll
C:\WINDOWS\system32\LYMANGR.DLL
C:\WINDOWS\system32\myatl.dll
C:\WINDOWS\system32\qqhxatl.dll
C:\WINDOWS\system32\raqjdpi.dll
C:\WINDOWS\system32\raqjdtl.exe
C:\WINDOWS\system32\ratbgpi.dll
C:\WINDOWS\system32\ratbgtl.exe
C:\WINDOWS\system32\rxjhatl.dll
C:\WINDOWS\system32\sqmapi32.dll
[Added service]
NAME: WS2IFSL (正常的服務)
DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment
FILE: \SystemRoot\System32\drivers\ws2ifsl.sys
NAME: Wdswsdewn
DISPLAY: Telephotsgoogle
FILE: C:\WINDOWS\system32\serdst.exe
[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\LYLOADER.EXE
C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL
C:\Documents and Settings\Administrator\Local Settings\Temp\MSDEG32.DLL
C:\Documents and Settings\Administrator\Local Settings\Temp\tmp87.tmp
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\014[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\11[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\15[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\19[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\3[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\7[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\13[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\17[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\5[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\9[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\0[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\12[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\16[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\4[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\8[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\10[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1299644[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\14[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\18[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\2[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\6[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\ki[1].htm
C:\WINDOWS\136741MM.DLL
C:\WINDOWS\136741WL.DLL
C:\WINDOWS\136741WO.DLL
C:\WINDOWS\Fonts\chqiaur.fon
C:\WINDOWS\Fonts\chtiaur.fon
C:\WINDOWS\Fonts\enpoafx.fon
C:\WINDOWS\Fonts\enweafx.fon
C:\WINDOWS\Fonts\msguasd.fon
C:\WINDOWS\Fonts\mswuasd.fon
C:\WINDOWS\Fonts\mszhasd.fon
C:\WINDOWS\IGM.exe
C:\WINDOWS\IGW.exe
C:\WINDOWS\swchost.exe
C:\WINDOWS\system32\0.exe
C:\WINDOWS\system32\avwgein.dll
C:\WINDOWS\system32\avwgemn.dll
C:\WINDOWS\system32\avwgest.exe
C:\WINDOWS\system32\avwldin.dll
C:\WINDOWS\system32\avwldmn.dll
C:\WINDOWS\system32\avwldst.exe
C:\WINDOWS\system32\avzxein.dll
C:\WINDOWS\system32\avzxemn.dll
C:\WINDOWS\system32\avzxest.exe
C:\WINDOWS\system32\dh3atl.dll
C:\WINDOWS\system32\dhatl.dll
C:\WINDOWS\system32\djatl.dll
C:\WINDOWS\system32\jzatl.dll
C:\WINDOWS\system32\kapjdaz.exe
C:\WINDOWS\system32\kapjdcs.dll
C:\WINDOWS\system32\kapjdzy.dll
C:\WINDOWS\system32\kawdcaz.exe
C:\WINDOWS\system32\kawdccs.dll
C:\WINDOWS\system32\kawdczy.dll
C:\WINDOWS\system32\LYLOADER.EXE
C:\WINDOWS\system32\LYMANGR.DLL
C:\WINDOWS\system32\MSDEG32.DLL
C:\WINDOWS\system32\mseam.sys
C:\WINDOWS\system32\myatl.dll
C:\WINDOWS\system32\qqhxatl.dll
C:\WINDOWS\system32\raqjdni.dll
C:\WINDOWS\system32\raqjdpi.dll
C:\WINDOWS\system32\raqjdtl.exe
C:\WINDOWS\system32\ratbgni.dll
C:\WINDOWS\system32\ratbgpi.dll
C:\WINDOWS\system32\ratbgtl.exe
C:\WINDOWS\system32\rxjhatl.dll
C:\WINDOWS\system32\serdst.exe
C:\WINDOWS\system32\sqmapi32.dll
C:\WINDOWS\system32\zhtuatl.dll
[Added LSP]
ID: 1026
NAME: MSAPI Tcpip [UDP/IP] (C:\WINDOWS\system32\sqmapi32.dll)
ID: 1027
NAME: MSAPI Tcpip [TCP/IP] (C:\WINDOWS\system32\sqmapi32.dll)
[Added COM/BHO]
{38907901-1416-3389-9981-372178569983}-C:\WINDOWS\system32\kawdczy.dll
{44783410-4F90-34A0-7820-3230ACD05F44}-C:\WINDOWS\system32\raqjdpi.dll
{4960356A-458E-DE24-BD50-268F589A56A4}-C:\WINDOWS\system32\avwldmn.dll
{4A321487-4977-D98A-C8D5-6488257545A4}-C:\WINDOWS\system32\kapjdzy.dll
{5859245F-345D-BC13-AC4F-145D
47DA34F5}-C:\WINDOWS\system32\avzxemn.dll
{5A1247C1-53DA-FF43-ABD3-345F323A48D5}-C:\WINDOWS\system32\avwgemn.dll
{76650011-3344-6688-4899-345FABCD1567}-C:\WINDOWS\system32\ratbgpi.dll
[Added registry]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value=WinSysM
Data=C:\WINDOWS\IGM.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value=WinSysW
Data=C:\WINDOWS\swchost.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value=WinSys
Data=C:\WINDOWS\IGW.exe
到目前為止 (2007/11/07 @ 13:35),下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考):
mseam.sys:
[ Symantec ], “Infostealer”
[ Nod32 ], “a variant of Win32/PSW.OnLineGames.NFC trojan”
sqmapi32.dll:
[ IntelliTrap ], “PAK_Generic.006″
[ Beta_Gen ], “Possible_Crypt-6″
[ Microsoft ], “VirTool:Win32/Obfuscator.C”
[ Kaspersky ], “PAK:UPack, Trojan-PSW.Win32.OnLineGames.guz”
[ McAfee ], “PWS-OnlineGames.j”
[ McAfee_Beta ], “PWS-OnlineGames.j”
[ Sophos ], “Mal/Packer”
[ Panda ], “Suspicious file”
[ CAV ], “Win32/Spibe!generic”
[ Nod32 ], “a variant of Win32/PSW.OnLineGames.NHF trojan”
[ Fortinet ], “suspicious”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
[ CAV Beta ], “Win32/Spibe!generic”
tmp87.tmp:
[ IntelliTrap ], “PAK_Generic.006″
[ Beta_Gen ], “Possible_Crypt-6″
[ Microsoft ], “VirTool:Win32/Obfuscator.C”
[ Kaspersky ], “PAK:UPack, Trojan-PSW.Win32.WOW.adu”
[ McAfee ], “PWS-OnlineGames.j”
[ McAfee_Beta ], “PWS-OnlineGames.j”
[ Sophos ], “Mal/Packer”
[ Panda ], “Suspicious file”
[ CAV ], “Win32/Spibe!generic”
[ Nod32 ], “a variant of Win32/PSW.OnLineGames.NHF trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/PSW.Wow.adu”
[ Norman ], “Trojan W32/Agent.DASF”
[ Sunbelt ], “VIPRE.Suspicious”
[ CAV Beta ], “Win32/Spibe!generic”
2[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack, Trojan-PSW.Win32.WOW.adu”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “[FILE:0000]:Mal/Packer, Mal/Packer”
[ CAV ], “Win32/Zuten!generic”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/CrashSystem.C”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
3[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “[FILE:0000]:Mal/Packer, Mal/Packer”
[ CAV ], “Win32/Zuten!generic”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/PSW.Onlineg.KC.2″
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
5[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “Mal/Packer”
[ CAV ], “Win32/Zuten!generic”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/CrashSystem.C”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
12[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack, Trojan-PSW.Win32.OnLineGames.gyu”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “[FILE:0000]:Mal/Packer, Mal/Packer”
[ CAV ], “Win32/Zuten!generic”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/PSW.Onlineg.KC.2″
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
14[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “[FILE:0000]:Mal/Packer, Mal/Packer”
[ CAV ], “Win32/Zuten!generic”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/PSW.Onlineg.KC.2″
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
17[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “Mal/Packer”
[ CAV ], “Win32/Zuten!generic”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/CrashSystem.C”
[ Norman ], “Trojan W32/Delf.AYPE”
[ Sunbelt ], “VIPRE.Suspicious”
18[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “[FILE:0000]:Mal/Packer, Mal/Packer”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/PSW.Onlineg.KC.2″
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
19[1].exe:
[ IntelliTrap ], “PAK_Generic.001″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “[FILE:0000]:Mal/Packer, Mal/Packer”
[ CAV ], “Win32/Zuten!generic”
[ Nod32 ], “probably a variant of Win32/PSW.OnLineGames.NGU trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/CrashSystem.C”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
LYLOADER.exe:
[ IntelliTrap ], “PAK_Generic.006″
[ Alpha_Gen ], “AP_MALPK-2″
[ Beta_Gen ], “AP_MALPK-2″
[ Symantec ], “Infostealer.Gampass”
[ Microsoft ], “[->(Upack)]:TrojanSpy:Win32/Agent.HZ”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack, Trojan-PSW.Win32.OnLineGames.gym”
[ McAfee ], “New Malware.aj !!”
[ McAfee_Beta ], “New Malware.aj !!”
[ Sophos ], “Mal/Packer”
[ Panda ], “Trj/Lineage.gen”
[ Panda_Beta ], “Trj/Lineage.gen”
[ CAV ], “Win32/Lolyda!generic”
[ Nod32 ], “a variant of Win32/PSW.Agent.NEC trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/PSW.Online.agb.2″
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
[ CAV Beta ], “Win32/Lolyda!generic”
LYMANGR.DLL:
[ IntelliTrap ], “PAK_Generic.001″
[ Beta_Gen ], “Possible_Crypt-6″
[ Symantec ], “Infostealer.Gampass”
[ Microsoft ], “VirTool:Win32/Obfuscator.C”
[ Kaspersky ], “PAK:UPack, Trojan-PSW.Win32.OnLineGames.gyn”
[ McAfee ], “Generic PWS.j”
[ McAfee_Beta ], “Generic PWS.j”
[ Sophos ], “Mal/Packer”
[ CAV ], “Win32/Lolyda!generic”
[ Nod32 ], “a variant of Win32/PSW.OnLineGames.DTR trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/PSW.Online.agb.2″
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
[ CAV Beta ], “Win32/Lolyda!generic”
MSDEG32.DLL:
[ IntelliTrap ], “PAK_Generic.001″
[ Beta_Gen ], “Possible_Crypt-6″
[ Microsoft ], “VirTool:Win32/Obfuscator.C”
[ Kaspersky ], “PAK:UPack, Trojan-PSW.Win32.OnLineGames.gyo”
[ Sophos ], “Mal/Packer”
[ CAV ], “Win32/Lolyda!generic”
[ Nod32 ], “a variant of Win32/PSW.OnLineGames.DVV trojan”
[ Fortinet ], “suspicious”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Sunbelt ], “VIPRE.Suspicious”
[ CAV Beta ], “Win32/Lolyda!generic”