½Ãñ½ñÈÕÌáÐÑÄú×¢Ò⣺ÔÚ½ñÌìµÄ²¡¶¾ÖÐTrojanSpy.KeyLogger.uh“¼üÅÌÖÕ½áÕß”±äÖÖuhºÍWorm/AutoRun.ahk“UÅ̼ÄÉú³æ”±äÖÖahkÖµµÃ¹Ø×¢¡£
²¡¶¾Ãû³Æ£ºTrojanSpy.KeyLogger.uh
ÖÐ ÎÄ Ãû£º“¼üÅÌÖÕ½áÕß”±äÖÖuh
²¡¶¾³¤¶È£º326748×Ö½Ú
²¡¶¾ÀàÐÍ£º¼äµýÀàľÂí
ΣÏÕ¼¶±ð£º¡ï¡ï
Ó°ÏìÆ½Ì¨£ºWin 9X/ME/NT/2000/XP/2003
TrojanSpy.KeyLogger.uh“¼üÅÌÖÕ½áÕß”±äÖÖuhÊÇ“¼üÅÌÖÕ½áÕߔľÂí¼Ò×åµÄ×îгÉÔ±Ö®Ò»£¬²ÉÓÃDelphiÓïÑÔ±àд£¬²¢¾¹ý¼Ó¿Ç´¦Àí¡£“¼üÅÌÖÕ½áÕß”±äÖÖuhÔËÐкó£¬×ÔÎÒ¸´ÖƵ½ÏµÍ³Å̵ē\Program Files\Common Files\Microsoft Shared\MSInfo”Ŀ¼Ï£¬ÖØÐÂÃüÃûΪ“alert.exe”£¨ÊôÐÔÉèÖÃΪ“ϵͳÒþ²Ø”£©¡£½«Æä×¢²áΪϵͳ·þÎñ£¬ÊµÏÖľÂí¿ª»ú×Ô¶¯ÔËÐС£Æô¶¯“IEXPLORE.EXE”³ÌÐò£¬½«²¡¶¾´úÂë×¢ÈëÆäÖÐÔËÐУ¬Òþ²Ø×ÔÎÒ£¬·ÀÖ¹±»²éɱ¡£ÔÚºóÌ¨ÃØÃܼàÊÓ±»¸ÐȾ¼ÆËã»úÉÏÊÇ·ñÓÐÒÆ¶¯´æ´¢É豸£¬Ò»µ©·¢ÏÖ±ãÔÚÒÆ¶¯´æ´¢É豸¸ùĿ¼Ï´´½¨“autorun.inf”ÎļþºÍľÂíÖ÷³ÌÐòÎļþ£¬ÊµÏÖË«»÷ÅÌ·ûÆô¶¯“¼üÅÌÖÕ½áÕß”±äÖÖuhÔËÐС£ÃØÃܼàÊÓÓû§´ò¿ªµÄ´°¿Ú±êÌ⣬ÇÔÈ¡Óû§ÊäÈëµÄÍøÂçÓÎÏ·¡¢ÍøÂçÒøÐÐÒÔ¼°¼´Ê±Í¨Ñ¶¹¤¾ßµÄÕ˺š¢ÃÜÂëµÈÐÅÏ¢£¬²¢½«»úÃÜÐÅÏ¢·¢Ë͵½º§¿ÍÖ¸¶¨µÄ·þÎñÆ÷ÉÏ£¬¸øÓû§´øÀ´¼«´óµÄËðʧ¡£ÁíÍ⣬“¼üÅÌÖÕ½áÕß”±äÖÖuh¿ÉÄÜÓ뺧¿ÍÖ¸¶¨µÄ·þÎñÆ÷½¨Á¢ÍøÂçÁ¬½Ó£¬ÕìÌýº§¿ÍµÄÖ¸Áî½øÐжñÒâ²Ù×÷£¬ÖÂʹ±»¸ÐȾµÄ¼ÆËã»ú±»º§¿ÍÔ¶³ÌÍêÈ«¿ØÖÆ£¬ÑÏÖØÍþвÓû§¼ÆËã»úÐÅÏ¢°²È«¡£
²¡¶¾Ãû³Æ£ºWorm/AutoRun.ahk
ÖÐ ÎÄ Ãû£º“UÅ̼ÄÉú³æ”±äÖÖahk
²¡¶¾³¤¶È£º140036×Ö½Ú
²¡¶¾ÀàÐÍ£ºÈ䳿
ΣÏÕ¼¶±ð£º¡ï¡ï
Ó°ÏìÆ½Ì¨£ºWin 9X/ME/NT/2000/XP/2003
Worm/AutoRun.ahk“UÅ̼ÄÉú³æ”±äÖÖahkÊÇ“UÅ̼ÄÉú³æ”È䳿¼Ò×åµÄ×îгÉÔ±Ö®Ò»£¬²ÉÓø߼¶ÓïÑÔ±àд£¬²¢¾¹ý¼Ó¿Ç´¦Àí¡£“UÅ̼ÄÉú³æ”±äÖÖahkÔËÐкó£¬ÔÚ±»¸ÐȾ¼ÆËã»úϵͳµÄ“%SystemRoot%\system32\”Ŀ¼ÏÂÊͷŲ¡¶¾Îļþ“kavo.exe”ºÍ¶ñÒâ×é¼þ“kavo0.dll”¡£ÐÞ¸Ä×¢²á±í£¬ÊµÏÖÈ䳿¿ª»ú×Ô¶¯ÔËÐС£½«“kavo0.dll”²åÈëµ½ËùÓÐÓû§¼¶È¨Ï޵Ľø³ÌÖмÓÔØÔËÐУ¬Òþ²Ø×ÔÎÒ£¬·ÀÖ¹±»²éɱ¡£ÆÆ»µ×¢²á±í£¬ÖÂʹ“ÏÔʾÒþ²ØÎļþ”¹¦ÄÜʧЧ¡£ÔÚ±»¸ÐȾ¼ÆËã»ú¸÷¸öÅÌ·û¸ùĿ¼Ï´´½¨“autorun.inf”ÎļþºÍÈ䳿Ö÷³ÌÐòÎļþ£¨ÎļþÃûËæ»úÉú³É£©£¬²¢ÇÒ¼àÊÓÒÆ¶¯´æ´¢É豸£¬Ò»µ©·¢ÏÖ±»¸ÐȾ¼ÆËã»úÓÐеÄÒÆ¶¯´æ´¢É豸ʱ²¡¶¾±ãÔÚÆä¸ùĿ¼Ï´´½¨“autorun.inf”ÎļþºÍÈ䳿Ö÷³ÌÐòÎļþ£¬ÊµÏÖË«»÷ÅÌ·ûÆô¶¯“UÅ̼ÄÉú³æ”±äÖÖahk²¡¶¾³ÌÐòÔËÐеÄÄ¿µÄ¡£ÁíÍ⣬“UÅ̼ÄÉú³æ”±äÖÖahk»¹»áÔÚ±»¸ÐȾ¼ÆËã»úºóÌ¨ÃØÃÜÇÔÈ¡ÍøÂçÓÎÏ·Íæ¼ÒµÄÓÎÏ·Õʺš¢ÓÎÏ·ÃÜÂë¡¢²Ö¿âÃÜÂë¡¢½ÇÉ«µÈ¼¶µÈÐÅÏ¢£¬²¢ÔÚºǫ́½«Íæ¼ÒÐÅÏ¢·¢Ë͵½º§¿ÍÖ¸¶¨µÄÔ¶³Ì·þÎñÆ÷ÉÏ£¬ÖÂÊ¹Íæ¼ÒµÄÓÎÏ·Õʺš¢×°±¸ÎïÆ·¡¢½ðÇ®µÈ¶ªÊ§£¬¸øÓÎÏ·Íæ¼Ò´øÀ´·Ç³£´óµÄËðʧ¡£