**請幫忙通知他們,謝謝**
惡意連結是放置在很多網頁 (Thumbs.js, 01.asp, 02.asp, 03.asp, 04.asp, 05.asp ...) 中的:
惡意程式碼的一部份為:
而且,這個網站被當成增加下面網站流量的工具:
執行之後,有下面的行為:
[Added process]
C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe
C:\WINDOWS\Logo1_.exe (有 Watchdog 的功能)
[DLL injection]
C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe (注入 svchost.exe 的執行程序)
[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\index[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\Thumbs[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\update[1].exe
C:\WINDOWS\Logo1_.exe
C:\WINDOWS\RichDll.dll
C:\_desktop.ini (每個目錄皆會產生 _desktop.ini,內容為日期)
[Modified file]
感染所有執行檔 (如果要清除這些檔案,除非防毒軟體的病毒碼增加清除這些感染檔案的特徵碼)
到目前為止,下面的防毒軟體可以偵測到這些惡意檔案:
RichDll.dll:
[ Trend ], "TROJ_LOOKED.WL"
svchost.exe:
[ Trend ], "PE_LOOKED.WL-O"
svchost.exe:
[ Trend ], "PE_LOOKED.WL-O"
update[1].exe:
[ Trend ], "PE_LOOKED.WL-O"
Logo1_.exe:
[ Trend ], "PE_LOOKED.WL-O"
index[1].htm:
[ HBEDV ], "HEUR/Exploit.HTML"
[ Ewido ], "Hijacker.Linker.e"