IThome首頁也被植入惡意程式 … :-( -->
Roger | 17 Dec, 2006 01:45
IThome首頁也被植入惡意程式,到現在尚未清除,請各位小心(FireFox不會被影響)。
惡意程式碼是藏在一個htm檔:
[Dll Injection]
C:/Program Files/Common Files/wincreat.dll (注入某些執行程序如 Explorer.exe 等)
[Added Files]
C:/Documents and Settings/Administrator/Local Settings/Temp/feipeng.exe
C:/Documents and Settings/Administrator/Local Settings/Temp/update.exe
C:/Documents and Settings/Administrator/Local Settings/Temporary Internet Files/Content.IE5/C13NVBMZ/update[1].exe
C:/Documents and Settings/Administrator/Local Settings/Temporary Internet Files/Content.IE5/Q08VKCK4/help[1].htm
C:/Program Files/Common Files/wincreat.dll
C:/WINDOWS/system32/winCreate.exe
[Added BHO]
{D14CE39F-EED3-489A-948C-FCD588F831E7}-C:/Program Files/Common Files/wincreat.dll