中国博客网www.blogcn.com被挂盗号木马及维金蠕虫NewInfo.dll NewInfo.bak msmsgs.exe IDrivers.pif
2007-04-01 23:52
http://hi.baidu.com/killvir/blog/item/2db990efeda297eecf1b3e6a.html利
用ANI漏洞下载
hxxp://www.i5460.net/admin12/help.exe
hxxp://cool.47555.com/1cxxxx.exe
1、盗号木马
C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.bak
CLSID\{A6011F8F-A7F8-49AA-9ADA-49127D43138F}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{A6011F8F-A7F8-49AA-9ADA-49127D43138F}
2、维金蠕虫
code by xiaohui
Setup.exe
c:\Deleteme.bat
msmsgs.exe
SOFTWARE\Microsoft\Active Setup\Installed Components\{2bf41073-b2b1-21c1-b5c1-0701f4155588}
StubPath --->C:\Program Files\Web Publish\IDrivers.pif
下载:
hxxp://cool.47555.com/ccc/12.exe
hxxp://cool.47555.com/ccc/8-1a.exe
hxxp://cool.47555.com/ccc/mh.exe
hxxp://cool.47555.com/ccc/wmgj.exe
hxxp://cool.47555.com/ccc/wl.exe
hxxp://cool.47555.com/ccc/fy.exe
hxxp://cool.47555.com/ccc/1.exe
hxxp://cool.47555.com/ccc/2.exe
hxxp://cool.47555.com/ccc/3.exe
hxxp://cool.47555.com/up.asp
为C:\Program Files\Web Publish\temp[1].exe~temp[10].exe
Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE
%programfiles%\Internet Explorer\IEXPLORE.EXE
Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE
%programfiles%\Messenger\msmsgs.exe
Software\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.EXE
%programfiles%\Windows Media Player\wmplayer.EXE
SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\1
TypePath-->%programfiles%\TENCENT\QQ.exe
原文:
http://hi.baidu.com/killvir/blog/item/2db990efeda297eecf1b3e6a.html建议大家屏蔽网址www.18dmm.com,这个站利用当前无补丁的漏洞更新频繁 增加两个非官方ANI补丁下载
http://hi.baidu.com/killvir/blog/item/627bfd1f847fb80b304e1591.htmlCISRT紧急发布【中度风险警报】:利用微软动画光标漏洞的复合型蠕虫受灾户正在上升
http://hi.baidu.com/killvir/blog/item/01477609c34681ae2fddd47e.html非官方ANI补丁下载:
http://www.eeye.com/html/research/tools/WindowsANIZeroDayPatchSetup.exe
http://killvir.hits.io/tools/PatchAni.zip
屏蔽 cool.47555.com 吧
ANI已经疯了,打上补丁,祝大家好运吧