060.jpgÌäÂê †
³µÍ× †
RO Skin Station SideÆâ ¥¹¥¥óÀìÍÑ¥¢¥×¥í¥À¤ËŽ¤é¤ì¤¿¡¢³ÈÄ¥»Ò¤ò .jpg¤Èµ¶Áõ¤·¤¿¥¦¥£¥ë¥¹html¤Ë¤Ä¤¤¤Æ¤ÎÁǿͤˤè¤ë¥á¥â¡£
¥¢¥«¥¦¥ó¥È¥Ï¥Ã¥¯Áí¹ç¥¹¥ì 5
http://gemma.mmobbs.com/test/read.cgi/ragnarok/1170419695/l50
¤ËÅê¹Æ¤·¤¿Ê¸¾Ï¤ò¸µ¤ËºÆ¹½À®¡£
¤³¤Î·ï¤Ë¤Ä¤¤¤Æ¤ÎÌ䤤¹ç¤ï¤»¤Ï¾åµ¥¹¥ì¤Ë¤ÆÂбþ¡£
¾ÜºÙ †
´¶À÷¥×¥í¥»¥¹ †
060.jpg¤Ï Jpeg²èÁü¤È»×¤ï¤»¤ë³ÈÄ¥»Ò¤ò»ý¤Ã¤Æ¤¤¤ë¤¬¡¢Ãæ¿È¤Ï JavaScript, VBScript¤ò´Þ¤à html¥Õ¥¡¥¤¥ë¤Ç¤¢¤ë¡£
mime¤ä³ÈÄ¥»Ò¤Ë½¾¤¦¤Þ¤È¤â¤Êhtml¥Ö¥é¥¦¥¶¤Ê¤é¤Ð¡¢²õ¤ì¤¿jpeg²èÁü¥Õ¥¡¥¤¥ë¤Ë¤·¤«¸«¤¨¤Ê¤¤¤¬¡¢Internet Explorer (¡Ö³ÈÄ¥»Ò¤Ç¤Ï¤Ê¤¯¡¢ÆâÍƤˤè¤Ã¤Æ¥Õ¥¡¥¤¥ë¤ò³«¤¯¡×¤¬¡Ö͸ú¡×¤Ë¤Ê¤Ã¤Æ¤¤¤ë IE7¤ò´Þ¤à)¤Ç¤Ï¡¢¾¡¼ê¤ËÄ̾ï¤Îhtml¤È²ò¼á¤·¡¢JavaScript¤ä¡¢VBScript¤¬(µö²Ä¤µ¤ì¤Æ¤¤¤ì¤Ð)¼Â¹Ô¤µ¤ì¤ë¡£
¤³¤Î¥Õ¥¡¥¤¥ë(060.jpg)¤Ë´Þ¤Þ¤ì¤ëVBScript¤ÎÆ°ºî †
- ¥Õ¥¡¥¤¥ë¤ÎºîÀ®
- Windows¤ÎSystem¥Ç¥£¥ì¥¯¥È¥ê (¼Â¸³´Ä¶¤Ç¤Ï C:\WINNT\system32 °Ê²¼ System¥Ç¥£¥ì¥¯¥È¥ê¤Èɽµ) ¤Ë
- TSP32E.DLL - ¥Æ¥¥¹¥È¥Õ¥¡¥¤¥ë¡£Ãæ¿È¤Ï¿ô»ú¤ÎÍåÎó (Kernel.exe¤ò¥¨¥ó¥³¡¼¥É¤·¤¿¤â¤Î)
- TSP32V.DLL - ¥Æ¥¥¹¥È¥Õ¥¡¥¤¥ë¡£Ãæ¿È¤Ï¿ô»ú¤ÎÍåÎó (Kernel.vbs¤ò¥¨¥ó¥³¡¼¥É¤·¤¿¤â¤Î)
¤È
- Kernel.exe - Win32¼Â¹Ô¥Õ¥¡¥¤¥ë
- Kernel.vbs - VBScript¥Õ¥¡¥¤¥ë
¤òºîÀ®¤¹¤ë¡£
Kernel.*¥Õ¥¡¥¤¥ë¤Ï¡¢¤½¤ì¤¾¤ì Systeme.dll, Systemv.dll¥Õ¥¡¥¤¥ë¤ÎÃæ¿È¤¬ "on" ¤Ç¤Ê¤¤¤È¤ºîÀ®¤µ¤ì¤ë(¸å½Ò)
- ¥×¥í¥°¥é¥à¡¢¥¹¥¯¥ê¥×¥È¤Îµ¯Æ°
- Systeme.dll¤òÆɤßÃæ¿È¤¬ "on"¤Ç¤Ê¤±¤ì¤Ð¡¢Kernel.exe¤ò¼Â¹Ô¤¹¤ë¡£
- Systemv.dll¤òÆɤßÃæ¿È¤¬ "on"¤Ç¤Ê¤±¤ì¤Ð¡¢Kernel.vbs¤ò¼Â¹Ô¤¹¤ë¡£
Kernel.vbs¤ÎÆ°ºî †
- 'Navid new virus 2006(1375.1) ¤È¤¤¤¦¥³¥á¥ó¥È¤ò»ý¤Ä
- ¥ì¥¸¥¹¥È¥ê¥¡¼¤ÎºîÀ®
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
¤Ë¡¢
C:\WINNT\system32\Kernel.vbs
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
¤Ë¡¢C:\WINNT\system32\Kernel.exe
¤òºîÀ®¤¹¤ë¡£
¤³¤ì¤é¤ÏPCµ¯Æ°»þ¡¢¤ª¤è¤Ó¥í¥°¥¤¥ó»þ¤Ë¼«¤é¤¬ºîÀ®¤·¤¿ Kernel.vbs¡¢Kernel.exe¤ò¼Â¹Ô¤µ¤»¤ë¤â¤Î¤Ç¤¢¤ë¡£
- ¥Õ¥é¥°¤ÎÀßÄê
- system¥Ç¥£¥ì¥¯¥È¥ê¤Ë Systemv.dll¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤òºîÀ®¤·¡¢"on"¤È¤¤¤¦Ê¸»úÎó¤òÀßÄꤹ¤ë¡£(¿½Åµ¯Æ°¤òËɤ°¤¿¤á¤ÎÆ°ºî¾õ¶·¥Õ¥é¥°¤È»×¤ï¤ì¤ë)
- html¥Õ¥¡¥¤¥ë¤Î²þÊÑ
- ¥í¡¼¥«¥ë¥Ç¥£¥¹¥¯, ¥Í¥Ã¥È¥ï¡¼¥¯¶¦Í¥É¥é¥¤¥ÖÆâ¤Ë¤¢¤ëÁ´¤Æ¤Î¥Ç¥£¥ì¥¯¥È¥ê¤ò½ä²ó¤·
htm, html, htt ¤Î³ÈÄ¥»Ò¤ò»ý¤Ä¥Õ¥¡¥¤¥ë¤Ë 060.jpg¤Ë´Þ¤Þ¤ì¤Æ¤¤¤¿¤â¤ÎÁêÅö¤Î VBScript¤òÄɲ乤롣
- Yahoo!ID¤Î°ìÍ÷¤òºîÀ®
- Yahoo!Messenger (¿ʬÆüËܤΥ桼¥¶¡¼¤Ï´Ø·¸¤Ê¤¤¤¬Ì¤³Îǧ)¤ÎProfile¥Ç¥£¥ì¥¯¥È¥ê¤ò¸«¤Ä¤±¤¿¤é¤½¤³¤ËµÏ¿¤µ¤ì¤Æ¤¤¤ë¥Õ¥¡¥¤¥ë̾¤òYahooID¤È¸«¤Ê¤·¤Æ mail.log¤Ë¥¢¥É¥ì¥¹°ìÍ÷¤òºîÀ®¤¹¤ë¡£
- send.log¤Ë"HKEY_CURRENT_USER\Software\yahoo\pager\Yahoo! User ID"¥¡¼¤ÎÃÍ + @yahoo.com ¤È¤¤¤¦Ê¸»úÎó¤òºîÀ®¤¹¤ë¡£
- ¥á¡¼¥ë¤ÎÁ÷¿®
- mail.log¤ËºîÀ®¤·¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹°ìÍ÷¤¢¤Æ¤Ë¤È¤¢¤ëURL (¸½ºß404)¤ÎÀëÅÁ¥á¡¼¥ë¤òÁ÷¤ê¤Ä¤±¤ë¡£¤½¤Î¤È¤¤Î From¤Ë¤Ï send.log¤òÀßÄꤹ¤ë¡£
- ¥Õ¥é¥°¤ÎÀßÄê
- system¥Ç¥£¥ì¥¯¥È¥ê¤Ë Systemv.dll¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤Ë¡¢"off"¤È¤¤¤¦Ê¸»úÎó¤òÀßÄꤹ¤ë¡£
Kernel.exe¤ÎÆ°ºî †
- ¾ÜºÙÉÔÌÀ
- Kernel.vbsÁêÅö¤ÎÆ°ºî¤ò»ý¤Ä¤ÈͽÁÛ¤µ¤ì¤ë¡£
- ¤½¤ì°Ê¾å¤Îµ¡Ç½¤ò»ý¤Ã¤Æ¤¤¤ë¤«¤â¤·¤ì¤Ê¤¤¡£
´¶À÷¤·¤Æ¤·¤Þ¤Ã¤¿¤é †
- Ç°¤Î¤¿¤á¥»¡¼¥Õ¥â¡¼¥É¤Çµ¯Æ°¤¹¤ë
(µ¯Æ°»þ¤Ë Kernel.exe, Kernel.vbs¤ò¼Â¹Ô¤µ¤»¤Ê¤¤¤¿¤á)
- system¥Ç¥£¥ì¥¯¥È¥êÆâ¤Î
- TSP32E.DLL
- TSP32V.DLL
- Kernel.exe
- Kernel.vbs
¥Õ¥¡¥¤¥ë¤òºï½ü¤¹¤ë¡£
- ¥ì¥¸¥¹¥È¥ê¥¡¼
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
¤òºï½ü¤¹¤ë¡£
- ¥í¡¼¥«¥ë¥Ç¥£¥¹¥¯¡¢¶¦Í¥É¥é¥¤¥Ö¤Ê¤¤¤Î *.htm, *.html, *.htt¥Õ¥¡¥¤¥ë¤ò¸¡º÷¤·ºï½ü¤¹¤ë (¤«¡¢Äɲ䵤줿VBScriptÉôʬ¤òÀÚ½ü¤¹¤ë)
- ºÆµ¯Æ°¸å WindowsUpdate¤¹¤ë
Ãí°Õ †
¸½»þÅÀ(2007/02/26)¤Ë¤ª¤¤¤Æ¡¢Symantec AntiVirus¤ÏKernel.vbs, Kernel.exe¼«ÂΤò¶¼°Ò¤È¸«¤Ê¤µ¤Ê¤¤¤Î¤Ç¤¢¤Æ¤Ë¤·¤Ê¤¤¤³¤È¡£
¥«¥¹¥Ú¥ë¥¹¥¡¼¤Ï¶¼°Ò¤È·Ù¹ð¤·¤¿¡£
Kernel.vbsʬ¤Î¶î½ü¤Ï°Ê¾å¤Î¤È¤ª¤ê¤À¤¬¡¢Kernel.exe¤Îµ¡Ç½¤Ë¤Ä¤¤¤Æ¤ÏÇÄ°®¤·¤Æ¤¤¤Ê¤¤¡£
¤½¤â¤½¤â´¶À÷¤·¤Æ¤·¤Þ¤Ã¤¿¤³¤È¼«ÂΤ¬ÌäÂê¤Ç¤¢¤ë¤Î¤Ç¡¢¤½¤ÎÂнè¤ò´Þ¤áÁá´ü¤ËºÆ¥¤¥ó¥¹¥È¡¼¥ë¤«¤é¤Î´Ä¶¤ÎºÆ¹½ÃÛ¤ò¤¹¤ë¤Ù¤¤ÈȽÃǤ¹¤ë¡£
ÍúÎò †