IThome首页也被植入恶意程式 … :-( -->
Roger | 17 Dec, 2006 01:45
IThome首页也被植入恶意程式,到现在尚未清除,请各位小心(FireFox不会被影响)。
恶意程式码是藏在一个htm档:
[Dll Injection]
C:/Program Files/Common Files/wincreat.dll (注入某些执行程序如 Explorer.exe 等)
[Added Files]
C:/Documents and Settings/Administrator/Local Settings/Temp/feipeng.exe
C:/Documents and Settings/Administrator/Local Settings/Temp/update.exe
C:/Documents and Settings/Administrator/Local Settings/Temporary Internet Files/Content.IE5/C13NVBMZ/update[1].exe
C:/Documents and Settings/Administrator/Local Settings/Temporary Internet Files/Content.IE5/Q08VKCK4/help[1].htm
C:/Program Files/Common Files/wincreat.dll
C:/WINDOWS/system32/winCreate.exe
[Added BHO]
{D14CE39F-EED3-489A-948C-FCD588F831E7}-C:/Program Files/Common Files/wincreat.dll