New! ¹ÚȺ½ð³½²úÆ·ÊÔÓÃÉêÇëNew! ÔÚÏßɱ¶¾

kg Black p Mail Black li s Black Mail
  Ö÷Ò³  >> ¼¼ÊõÖ§³Ö
²¡¶¾Ãû³Æ£ºÈ䳿²¡¶¾Win32.Robzips.A
ÆäËüÃû³Æ£ºW32/Backdoor.HZL (F-Secure), Win32/Robknot.P!Worm, Win32/Robzips, Win32.Robzips.A, Win32/Robzips.A!ZIP, Email-Worm.Win32.Brontok.n (Kaspersky)
²¡¶¾ÊôÐÔ£ºÈ䳿²¡¶¾ Σº¦ÐÔ£º¸ßΣº¦ Á÷Ðг̶ȣº¸ß
¾ßÌå½éÉÜ£º


²¡¶¾ÌØÐÔ£º
Win32.Robzips.AÊÇÒ»ÖÖͨ¹ýÓʼþ´«²¥µÄÈ䳿¡£ËüÊÇ´óСΪ45,120×Ö½Ú£¬ÒÔUPX¸ñʽ¼Ó¿ÇµÄWin32¿ÉÔËÐгÌÐò¡£²¡¶¾Í¨¹ý·¢ËÍ´øÓдóСΪ3,894×Ö½ÚµÄZIP¸½¼þµÄÓʼþ½øÐд«²¥¡£ZIP¸½¼þÖаüº¬Ò»¸öÏÂÔØÆ÷ºÍÒ»¸öÅú´¦ÀíÎļþ¡£


¸ÐȾ·½Ê½£º
ÔËÐÐʱ£¬Win32.Robzips.AÔÚ%System%Ŀ¼ÖÐÉú³ÉÒ»¸öÈÎÒâÃû³ÆµÄÎļþ¼Ð£¬²¢Ê¹ÓÃÒÔÏÂÎļþÃû¸´ÖƲ¡¶¾µ½Õâ¸öÎļþ¼Ð£º
smss.exe
csrss.exe  
lsass.exe  
services.exe  
winlogon.exe  

ËæºóÔËÐÐÕâЩÎļþ¡£

×¢£º'%System%'ÊÇÒ»¸ö¿É±äµÄ·¾¶¡£²¡¶¾Í¨¹ý²éѯ²Ù×÷ϵͳÀ´¾ö¶¨SystemÎļþ¼ÐµÄλÖá£Windows 2000 and NTĬÈϵÄϵͳ°²×°Â·¾¶ÊÇC:\Winnt\System32; 95,98 ºÍ ME µÄÊÇC:\Windows\System; XP µÄÊÇC:\Windows\System32¡£

Ëü»¹»áʹÓÃÈÎÒâÎļþÃû¸´ÖƵ½Õâ¸öÎļþ¼ÐºÍ%Windows%Ŀ¼ÖУ¬»¹ÓÐÒÔÏÂλÖãº
%Windows%\_default<random value>.pif

Robzips»¹»á¸´ÖƵ½%Application Data%\jalak-93<random value>-bali.com£¬²¢Ìí¼ÓÕâ¸öÎļþµ½Ô¤¶¨ÈÎÎñÁбíÖУ¬ÎªÁËÿÌì11:03 am ºÍ 5:08 pmʱ¼äÔËÐв¡¶¾¡£

×¢£º%Application Data% ÊÇÒ»¸ö¿É±äĿ¼£¬Ò»°ãÔÚÒÔÏÂλÖÃ"C:\Documents and Settings\<user name>\Local Settings\Application Data"¡£
²¡¶¾Éú³ÉÒ»¸öÎı¾Îļþ"C:\Baca Bro !!!.txt"£¬Õâ¸öÎļþ°üº¬ÒÔÏÂÄÚÈÝ£º
 

Óû§´ò¿ªÕâ¸öÎļþä¯ÀÀʱ£¬Robzips»á¹Ø±ÕËü£¬²¢ÏÔʾÏÔʾÒÔÏÂÐÅÏ¢£º
 

 


´«²¥·½Ê½
ͨ¹ýÓʼþ´«²¥
Robzips·¢ËÍÓʼþµÄÓʼþµØÖ·´Ó±¾µØÎļþÖлñÈ¡£¬ËüËÑË÷ÒÔÏÂÀ©Õ¹ÃûµÄÎļþ£º
txt
htm
html
csv
eml
wab
asp
php
cfm
doc
xls
ppt

»ñÈ¡µÄÓʼþµØÖ·±£´æÔÚ"%System%\<random folder name>\Spread.Mail.Bro" and "%System%\<random folder name>\Spread.Sent.Bro"¡£

Robzips.A²»·¢ËͰüº¬ÒÔÏÂ×Ö·û´®µÄÓʼþµØÖ·£º
--
-.
-@
-_
.-
..
.@
._
.ASP
.CA.COM
.cfm
.doc
.eml
.EXE
.gif
.HTM
.JS
.pdf
.PHP
.ppt
.txt
.VBS
.xls
@-
@.
@123
@_
@ABC
@MAC
@mm
_-
_.
_@
__
abuse
acer
ADMIN
ADOBE
AHNLAB
ALADDIN
ALERT
ALWIL
anony
ANTIGEN
APACHE
ARCHIEVE
ASDF
ASSOCIATE
AVAST
AVG
AVIRA
BILLING@
BLACK
BLAH
BLEEP
borland
BROWSE
BUG
BUILDER
BUNTU
CANON
CASTLE
chip
CILLIN
CISCO
CLICK
CNET
code
coding
compaq
COMPUSE
COMPUTE
CONTOH
CRACK
DARK
DATABASE
DEMO
detik
DEVELOP
DOMAIN
DOWNLOAD
ELECTRO
ELEKTRO
ESAFE
ESAVE
ESCAN
EXAMPLE
FEEDBACK
FOO@
FREE
FUCK
FUJI
FUJITSU
GATEWAY

GRISOFT
GROUP
guru
HACK
HAURI
HELP
HIDDEN
HP.
IBM.
IEEE
INFO@
INFORMA
INTEL.
IPTEK
IRFANVIEW
jpg
KDE
KOMPUTER
LAB
LINUX
LOOKSMART
LOTUS
LUCENT
MACRO
MASTER
MATH
MICRO
MICROSOFT
MOZILLA
MSDN
MYSQL
NASA
NETSCAPE
NETWORK
NEWS
NOD32
NOKIA
NONE
NORMAN
NORTON
NOVELL
NVIDIA
OPERA
OVERTURE
PANDA
pcmag
pcmedia
pcplus
POSTGRE
PROGRAM
PROLAND
PROMO
PROTECT
PROXY
RECIPIENT
REDHA
REGIST
RELAY
RESPONSE
ROBOT
SALES
script
SECUN
SECURE
SECURITY
SEKUR
SENIOR
SERVER
SERVICE
SIEMENS
SIERRA
SLACK
SMTP
SOFT
SOME
SOURCE
SPAM
SPERSKY
SPYW
STUDIO
SUN.
SUPPORT
SUSE
SYBARI
SYMANTEC
SYNDICAT
TELECOM
TEST
torvald
TRACK
TREND
trovald
TRUST
UPDATE
USERNAME
VAKSIN
VIRUS
W3.
w32
WINRAR
WINZIP
WWW
XANDROS
XEROX
XXX
yahoo
YOUR
ZDNET
ZEND
ZOMBIE