Hinet直播网首页被植入恶意程式码 !! -->
Roger | 10 Dec, 2006 15:02
Hinet直播网首页被植入恶意程式码,到现在为止,尚未移除,请各位小心。
恶意程式码是藏在一个JS档:
以下是执行之后的行为:
[Dll Injection]
C:/WINDOWS/off1win.dll (注入某些执行程序如 explorer.exe等)
[Added file]
C:/Documents and Settings/Administrator/Local Settings/Temp/AdCount.com
C:/WINDOWS/off1win.dll
C:/WINDOWS/system32/on1Exe.exe
[ Added BHO ]
{894C0068-46AC-4F59-A140-EDE0DABA776C}-C:/WINDOWS/off1win.dll