³]©w EYNY ¬°º¶
|
¥[¤J§Úªº³Ì·R
¹C«È:
µù¥U
|
µn¿ý
|
·j¯Á
|
À°§U
|
ÁcÅ餤¤å
|
´L¶Q·|Äy
|
¥ì²ú¹CÀ¸
|
¶Ç²Î¼Ò¦¡
¼öªù·j´M:
®ü¨¤¤C¸¹
©PªNÛ
¤Ñ¸o
®ü¸é¤ý
ÆN²´
ªiÄR¤h
ªiÄR¤h¤j¤H
¦º¯«
¥ì²ú°Q½×°Ï
»
¹q¸£¸ê°T
»
¹q¸£¨t²Î OS °Q½×
»
Windows °Q½×
» ¦p¦ó§Ö³tµo²{¤Î²¾°£´c·Nµ{¦¡
¥ð¶¢²á¤Ñ
¾Ç³N¤å¤Æ
·P±¡·P©Ê
¿³½ì¥æ¬y
®a®x¨Æ°È
®È¹C¥æ¬y
¶¼¹¥æ¬y
®a±Úªù¬£
¶K¹Ï¤À¨É
°Êº©¥æ¬y
µ¼Ö¥@¬É
¬ü®e¥´§ê
¼é¬y¸ê°T
¼vµø®T¼Ö
¹qª±¹CÀ¸
³s½u¹CÀ¸
ºôµ¸¹CÀ¸
¥æ©ö¼s³õ
¤U¸ü¤À¨É
BT¤U¸ü°Ï
CB¤U¸ü°Ï
¹q¸£¸ê°T
¼Æ½X²£«~
¤â¾÷¥æ¬y
ºô¯¸¨Æ°È
Åé¨|¹B°Ê
®É¨Æ·s»D
¤W¯Z¤@±Ú
³Õ±m®T¼Ö
¦¨¤H¸ÜÃD
Windows °Q½×
Linux °Q½×
FreeBSD °Q½×
MAC OS X °Q½×
‹‹ ¤W¤@¥DÃD
|
¤U¤@¥DÃD ››
§ë²¼
¥æ©ö
Äa½à
¬¡°Ê
¥´¦L
|
±ÀÂË
|
q¾\
|
¦¬ÂÃ
¼ÐÃD:
[Âà¸ü]
¦p¦ó§Ö³tµo²{¤Î²¾°£´c·Nµ{¦¡
z9868
¤p¾Ç¥Í(200/1000)
¼ç¤ô
UID 1466613
ºëµØ 0
¿n¤À 232
©«¤l 177
¼ç¤ô 2255 ¦Ì
¾\ŪÅv 20
µù¥U 2007-6-4
#1
µoªí©ó 2008-7-25 12:42 AM
¸ê®Æ
¤å¶°
µu®ø®§
¥ì²ú³¡¸¨®æ
¡B
¥ì²ú¥æ¤Í
¡B
¥ì²ú²á¤Ñ
¡B
¥ì²ú¬Ûï
¦p¦ó§Ö³tµo²{¤Î²¾°£´c·Nµ{¦¡
[Åã¥Ü]
[ÁôÂÃ]
¥ø·~¬É¤ÎÓ¤H¦p¦ó§Ö³tµo²{¤Î²¾°£´c·Nµ{¦¡¡H¦D¨Æ§½¬Q¤Ñ¤½¥¬¡u¯µÓD¥|©Û¡v¡A¨ÑªÀ·|¦U¬É¦Û¦æ¾Þ½m¨Ã±Æ°£´c·Nµ{¦¡ªº¤J«I¡C
¡@¯µÓD¤@¡GÃö³¬©Ò¦³¤wª¾¹ï¥~³s½uµ{¦¡¡A¦b½T©wºô¸ô¨S¦³¥¿±`¹ï¥~³s½u±¡ªp¤U¡A¶}±Òcmd.exe¡A¿é¤J§Q¥Î¡unetstat -an -p tcp¡v«ü¥O²M¬d²§±`¹ï¥~³q°TªºÀ³¥Îµ{¦¡¡AÀˬd¬O§_¦³¹ï¥~TCP 53¤Î80 port³s½u¡AÆ[¹î¬O§_¨ã´c·Nµ{¦¡¯S½è¡A¨Ãª`·NVNC¡BTerminal Service µ¥»·ºÝ»»±±5800¡B5000 and 3389 portªº¤£©ú¥~¨Ó»»±±³s½u¡CY¨Ï¥ÎªÌ¥»¨¦³¦w¸Ë»·ºÝ»»±±µ{¦¡¦pVNC©ÎTerminal Server¡A«ØÄ³§ó§ï¹w³]³s½uport¡A¨Ã³]©w¦s¨ú³s½u¤§IP¡A¥H¨¾Àb«È¨Ï¥Î¸Ó»·ºÝ»»±±µ{¦¡¡C
¡@¯µÓD¤G¡GÀˬdµn¿ý½s¿è¾¹¡]Registry¡^¡G²M¬dHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Runµ¥¦Û°Ê±Ò°Ê¸ô®|¤U¬O§_¦³¡uiexplore.exe¡v¡B¡upeep.exe¡v¡B¡ur_server.exe¡v¤Î¡uhiderun.exe¡vµ¥¦r¼Ë¤§¾÷½X¡AY¦s¦bªº¸Ü±N¸Ó¾÷½X§R°£¡C
¡@¯µÓD¤T¡GÀˮַL³n¨t²Î¥Ø¿ý¤¤¡]¸ô®|¤j¦h¬°C:\WINNT\SYSTEM32\¡^¬O§_¦s¦b¤U¦C²§±`ÀɮסA¨Ã§R°£¤§¡G¡]¤@¡^´c·Nµ{¦¡-peep.exe¡G³q±`·|¦s©ñ¦bc:\winnt\system32¥Ø¿ý¤§¤U¡A°õ¦æ«á·|¦Û°Ê²£¥Íexplorer.exe©óc:\winnt\system32¥Ø¿ý¡]¥¿±`ªºexplorer.exe¬O¦s©ñ¦bc:\winnt¤§¥Ø¿ý¤§¤U¡^¡A¨Ã©óºô¸ô³s½u«á¦Û°Ê³s½u¦Ü¸õªO¥D¾÷¤§80port¡A¤@¯ë80port¬°ºô¶¥D¾÷¤§¥Î¡Apeep.exe¤ì°¨µ{¦¡«h¥Î°µ»·ºÝ»»±±¨Ã¥i¶Ç»¼¨ü·P¬V¤§¹q¸£¤º¥ô¦óÀÉ®×¸ê®Æ¡C
¡@¡]¤G¡^´c·Nµ{¦¡-service.exe¡G¥¿±`¤§¨t²ÎÀɬ°services.exe¡A¦s©ñ©óc:\winnt\system32¥Ø¿ý¤§¤U¡AY¹q¸£¦³service.exe©Î«D¦ì©óc:\winnt\system32¥Ø¿ý¤U¤§services.exeÀɮ׫h¥i¯à¨ü¨ì·P¬V¡CService.exe°õ¦æ«á·|²£¥ÍMFC42G.DLL¤ÎWinCom32.exeµ¥¨âÓÀɮסA¨Ã©óºô¸ô³s½u«á¥HTCP¤è¦¡³s½u¦Ü¸õª©¥D¾÷53port¡A¤@¯ë53port¬°DNS¤§¥Î¡A¥B¬O¥HUDP¤è¦¡³s½u¡C
¡@¡]¤T¡^´c·Nµ{¦¡-iexplore.exe¡Giexplore.exe³Q¸m©óc:\windows\system32¥Ø¿ý¤¤¡]¥¿±`¦ì©óc:\program Files\Internet Explorer¡^¡A¸Óµ{¦¡§ï½s¦Ûª¾¦W°½±K½Xµ{¦¡nasswordspy¡BBackdoor.PowerSpider¤ÎPWSteal.Netsnake¡A¬°ª¾¦W¦¬¶°±K½X¸ê°Tµ{¦¡ªºÅܺءA·|»`¶°¨ü®`ªÌ©Ò¿é¤Jªº±b¸¹±K½X«á¥H¹q¤l¶l¥ó¤è¦¡¶Ç°e¦Ü¤¤°ê¤j³°ªº¬YÓ¶l¥ó¥D¾÷¡C
¡@¡]¥|¡^¡B¨ä¥L²§±`µ{¦¡¡G¥]¬Aexec3.exe¡Br_server.exe¡Bhiderun.exe¡Bgatec.exe¡Bgates.exe¡Bgatew.exe¡Bnc1.exe¡Bradmin.exe¡Bhbulot.exeµ¥¤wª¾ÀɦW¤§´c·Nµ{¦¡¡A¥t»Ý¤H¤uÀˮ֬O§_¦³²§±`µ{¦¡¡A¦p¡u*.bat¡v¤Î¡u*.reg¡v³q±`¬°Àb«È¤J«
[
ÂsÄý§¹¾ã¤º®e½Ð¥ýµù¥U©Îµn¤J·|û
¡C]
kato751126
¥®¨à¥Í(0/200)
¼ç¤ô
UID 4666836
ºëµØ 0
¿n¤À 38
©«¤l 32
¼ç¤ô 310 ¦Ì
¾\ŪÅv 10
µù¥U 2008-7-28
#2
µoªí©ó 2008-7-28 06:44 PM
¸ê®Æ
¤å¶°
µu®ø®§
¥ì²ú¹CÀ¸
ÁÂÁ¤j¤jªº«ü¾É!Åý§Ú¤S¾Ç¨ì¤@¨Ç¹q¸£ªº·sª¾Ãѳá!! ±À±À±À
°¨¤W¥h¸Õ¸Õ¬Ý³á!!
tang1124
¥®¨à¥Í(0/200)
¼ç¤ô
UID 1328422
ºëµØ 0
¿n¤À 117
©«¤l 43
¼ç¤ô 779 ¦Ì
¾\ŪÅv 10
µù¥U 2007-5-18
#3
µoªí©ó 2008-7-28 11:05 PM
¸ê®Æ
¤å¶°
µu®ø®§
ºû§J´µ°Q½×°Ï
¬Ý¨ì¤j¤j´£¨Ñªº¸ê®Æ¡A§Ú·Qµ¥¤U§Ú
·|¤U½u¸Õ¸Õ¬Ý¡A§Úªº¹q¸£¨ì©³¬O§_
¦³µL²¾´c·Nµ{¦¡³nÅé¡A¦b§Ú¹q¸£¤º
§@©Ç¡I·PÁ¡I
waehan11
¥®¨à¥Í(0/200)
¼ç¤ô
UID 4233509
ºëµØ 0
¿n¤À 0
©«¤l 42
¼ç¤ô 493 ¦Ì
¾\ŪÅv 10
µù¥U 2008-5-18
#4
µoªí©ó 2008-7-29 08:45 PM
¸ê®Æ
¤å¶°
µu®ø®§
¥ì²ú³¡¸¨®æ
¡B
¥ì²ú¥æ¤Í
¡B
¥ì²ú²á¤Ñ
¡B
¥ì²ú¬Ûï
ÁÂÁ±zªº´£¨Ñ~!³o¨Ç¸ê°T¤£¿ù~!
¦³¨Ç§ÚÁÙ¤£ª¾¹D~!
kengto
¤p¾Ç¥Í(200/1000)
¼ç¤ô
UID 283488
ºëµØ 0
¿n¤À 335
©«¤l 545
¼ç¤ô 5381 ¦Ì
¾\ŪÅv 20
µù¥U 2006-9-28
#5
µoªí©ó 2008-8-2 10:42 PM
¸ê®Æ
¤å¶°
µu®ø®§
ºû§J´µ°Q½×°Ï
·PÁ¤j¤j¤À¨É³o¨Ç¹ê¥Îªºª¾ÃÑ ¹ï§Ú«D±`¹ê¥Î
§ë²¼
¥æ©ö
Äa½à
¬¡°Ê
·í«e®É°Ï GMT+8, ²{¦b®É¶¡¬O 2008-10-11 09:15 PM
Powered by
Discuz!
5.0.0
© 2001-2006
Comsenz Inc.
Processed in 0.054863 second(s), 6 queries , Gzip enabled
TOP
²M°£ Cookies
-
Ápô§ÚÌ
-
¼s§i¬d¸ß [«Â¦°¥N²z]
-
¥ì²ú°Q½×°Ï
-
Archiver
±±¨î±ªOº¶
½s¿èÓ¤H¸ê®Æ
¿n¤À¥æ©ö
¤½²³¥Î¤á²Õ
¦n¤Í¦Cªí
°ò¥»·§ªp
½×¾Â±Æ¦æ
¥DÃD±Æ¦æ
µo©«±Æ¦æ
¿n¤À±Æ¦æ
¦b½u®É¶¡
ºÞ²z¹Î¶¤
ºÞ²z²Îp
«nÁn©ú¡G¥»°Q½×°Ï¬O¥H§Y®É¤W¸ü¯d¨¥ªº¤è¦¡¹B§@¡A¥ì²ú°Q½×°Ï¹ï©Ò¦³¯d¨¥ªº¯u¹ê©Ê¡B§¹¾ã©Ê¤Î¥ß³õµ¥¡A¤£t¥ô¦óªk«ß³d¥ô¡C¦Ó¤@¤Á¯d¨¥¤§¨¥½×¥u¥Nªí¯d¨¥ªÌÓ¤H·N¨£¡A¨Ã«D¥»ºô¯¸¤§¥ß³õ¡A¥Î¤á¤£À³«H¿à¤º®e¡A¨ÃÀ³¦Û¦æ§PÂ_¤º®e¤§¯u¹ê©Ê¡C©ó¦³Ãö±¡§Î¤U¡A¥Î¤áÀ³´M¨D±M·~·N¨£(¦p¯A¤ÎÂåÀø¡Bªk«ß©Î§ë¸êµ¥°ÝÃD)¡C ¥Ñ©ó¥»°Q½×°Ï¨ü¨ì¡u§Y®É¤W¸ü¯d¨¥¡v¹B§@¤è¦¡©Ò³W¡A¬G¤£¯à§¹¥þºÊ¹î©Ò¦³¯d¨¥¡AYŪªÌµo²{¦³¯d¨¥¥X²{°ÝÃD¡A½ÐÁpµ¸§ÚÌ¡C¥ì²ú°Q½×°Ï¦³Åv§R°£¥ô¦ó¯d¨¥¤Î©Úµ´¥ô¦ó¤H¤h¤W¸ü¯d¨¥¡A¦P®É¥ç¦³¤£§R°£¯d¨¥ªºÅv§Q¡C¤Á¤Å¼¶¼g²Ê¨¥Â©»y¡B½ÚÁ½¡B´è¬V¦â±¡¼É¤O©Î¤H¨§ðÀ»ªº¨¥½×¡A·q½Ð¦Û«ß¡C¥»ºô¯¸«O¯d¤@¤Áªk«ßÅv§Q¡C