¬d¬Ý§¹¾ãª©¥»: msn ¬r

a220_284 2007-8-21 11:17 PM

msn ¬r

¦pªG¤¤¥ª msn ¬r~
¥i¥HÂI°µØ{....
¨g¼u sd file msg ­Ú¤H....·Ð¦º¤H¦a lu~~

¦p¦³¤j«L¥X¤â¬Û§U~
¤p§Ì·P¿E¤£ºÉ~

noel 2007-8-21 11:40 PM

[color=red]¤£ª¾¬O¤£¬O«ü³o­Ó
¤]¤£ª¾¹D¬O¤£¬O­Ó­Ó³£³o¼Ësolve[/color]

ªñ¤é¤£Â_¦³msn¥Î¤á¤¤©Û¡A¨ººØvirus·|¥Ñ§Afriend listªº¤Hsend¤@­Ófile­Ú§A¡Afile name¦h¼Æ¬°IMGxxx.zipªºÀ£ÁYÀÉ¡C½Ð±µ¦¬¡A°Ý²M·¡¬O§_¯uªº¬O§AªºªB¤Ísend­Ú§A¥ý¦n¥i¡A§_«h´N.............ʨ

Photo.zip Virus ²¾°£¤èªk

MSN·Ó¤ù¬r photo.zip (Worm.IRC.MyPhoto.a) ¸Ñ¨M¤èªk


¯f¬r¦WºÙ¡GMSN·Ó¤ù¡]Worm.IRC.MyPhoto.a¡^
¯f¬rÃþ«¬¡GįÂίf¬r
¯f¬r¦M®`¯Å§O¡G¡¹¡¹¡¹¡¸
¯f¬rµo§@²{¶H¤Î¦M®`¡G¸Ó¯f¬r·|³q¹LMSNµo°e¤º®e¬°¡§HEY lol i¡¦ve done a new photo album !  
Second ill find file and send you it.¡¨¡B¡§Hey wanna see my new photo album?¡¨µ¥¤º®eªº®ø®§¡A¦P®Éªþ±a¤@­Ó¦W¬°photo album.zipªºÀ£ÁYÀÉ¡C



¥Î¤á¹B¦æ¸ÓÀ£ÁYÀɤ¤ªºµ{¦¡§Y·|³Q¯f¬r·P¬V¡C¯f¬rÁÙ·|¦b¥Î¤á¹q¸£ùØÄÀ©ñ¤@­Ó«áªùµ{¦¡¡AÀb«È¥i¥H§Q¥ÎIRC³nÅé»·ºÝ±±¨î¤¤¬r¹q¸£¡AÅѨú­Ó¤H¸ê®Æ¡A±q¦Ó¨Ï¥Î¤á­±Á{·¥¤jªº¦w¥þ«Â¯Ù¡C
¤â¤u§R°£¡G


¤@¡B§R°£¯f¬rªºµù¥Uªí±Ò°Ê±M®×


1¡B¹B¦æregedit¡A¥´¶}µù¥Uªí½s¿è¾¹¡C¥´¶}
HKEY_LOCAL_MACHINE¢ÎSOFTWARE¢ÎMicrosoft¢ÎWindows¢ÎCurrentVersion¢Î
ShellServiceObjectDelayLoad¡A§ä¨ì¡§rdshost¡¨©Î"syshosts"¤@¶µ¡A±N¨ä­È°O¿ý¤U¨Ó¡A¨Ã±N¸Ó¶µ§R°£¡C



ª`·N¡G¡§rdshost¡¨©Î"syshosts"¶µªº­È¬°¤@­ÓCLSID¡C¯f¬r²£¥Íªº³o¬qCLSID¤£©T©w¡A¥»¨Ò¤¤¬°¡G{C7B4EE78-A8FB-4C16-AE1F-C1A568949825}¡C
    2¡B¥´¶}HKEY_CLASSES_ROOTCLSID¡A§ä¨ì­è¤~°O¿ý¤UªºCLSID¶µ¡A¥»¨Ò¬°¡G{C7B4EE78-A8FB-4C16-AE1F-C1A568949825}¡A±N¨ä§R°£¡C



¤G¡B­«·s±Ò°Ê¹q¸£


¥Ñ©ó¸Ó¯f¬r¾n¯d°O¾ÐÅé¡A¦]¦¹¡A²M°£±¼±Ò°Ê±M®×«á¥²¶·­«·s±Ò°Ê¹q¸£¤~¯à°÷§R°£¯f¬rÀÉ¡C


¤T¡B§R°£¯f¬rÀÉ


1¡B¶i¤JWindows¡AÀq»{¬°C:¢Îwindows¡A§ä¨ì¦W¬°¡§photo album.zip¡¨ªºÀɨçR°£¡C



2¡B¶i¤J¨t²Î¥Ø¿ý¡AÀq»{¬°C:¢Îwindows¢Îsystem32¡A§ä¨ì¦W¬°¡§rdshost.dll¡¨©Î"syshosts"ÀɨçR°£¡]ª`·N¬ODLLÀɤ£¬OEXE¡^¡C


3¡B­«·s±Ò°Ê¹q¸£¡AÀˬd³o´X­ÓÀɬO§_¦s¦b¡A¦pªG¤£¦s¦b¡A«h¯f¬r¤w³Q²M°£°®²b¡C


´£¥Ü¡G¸Ó¯f¬r¤â¤u²M°£¸û¬°Ácº¾¡A«ØÄ³¨Ï¥Î±þ¬r³nÅé²M°£¡C°w¹ï¡§MSN·Ó¤ù¡¨¯f¬r¡A¥Î¤áÀ³±Ä¨ú¦p¤U±¹¬I¡A¤£­n»´©ö³q¹LMSN±µ¦¬©M¹B¦æ­¯¥ÍÀÉ¡F¯f¬r§Q¥ÎMSN¶i¦æ¶Ç¼½¡A¤j¶q¦û¥Î¨t²Î¸ê·½©Mºô¸ô±a¼e¡A¦]¦¹¥ø·~§½°ìºô¥Î¤á§ó­n¥[±j¹ï¦¹¯f¬rªº¨¾½d¡F¾¨§Ö§ó·s¦Û¤vªº±þ¬r³nÅ骩¥»¡A·ç¬P±þ¬r³nÅé19.16.12ª©¥»¥i¥H¹ý©³²M°£¦¹¯f¬r¡C

copy from other:
[url=http://www.gathertrade.com/viewthread.php?tid=246&extra=page%3D1][img]http://www.gathertrade.com/images/logo.gif[/img][/url]

[[i] ¥»©«³Ì«á¥Ñ noel ©ó 2007-8-21 11:34 PM ½s¿è [/i]]

a220_284 2007-8-21 11:51 PM

oh~you are so gd~
³£¸Ü¥ª¾ð¤¯¦P¾Ç¦n kind ¬[°Õ~:sss68
(©O¥y«Y¯u¬[~µù¥UªG¤é§Ú«YËݦP·s¥ÍÁ¿....)

a220_284 2007-8-22 12:09 AM

sori~¦³³¥°Ý.....

«Y«}¤@¤G¤T³£­n°µ»ô¡H

¹B¦æregedit (­øª¾«§¾¤)
¥´¶}µù¥Uªí½s¿è¾¹¡C(­øª¾«§¾¤)

ÁÂ~

pinekin 2007-8-22 12:15 AM

¹B¦æregedit = ¶}©l==>°õ¦æ==>¥´regedit
¤@ ==>¤G==>¤T ¬O¶¶§Ç°µ¤U¥h

iyan 2007-8-22 12:16 AM

°ª¤â½Ð§A¥´±Ï§Ú°Õ

§Ú­ø¤p¤ß¤¤¥ª©Û¡A¨ä¹ê§Ú³£­øª¾«Y­ø«Y¤¤©O­Ó¯f¬r¦ý«Y³£´X¦ü~~

§Ú«Y¶}©l->°õ¦æ->regedit
¨£¨ìµnºñ½s¿èµ{¦¡

«YHKEY_LOCAL_MACHINE¢ÎSOFTWARE¢ÎMicrosoft¢ÎWindows¢ÎCurrentVersion¢Î
ShellServiceObjectDelayLoad¡A
ݯ¨ì
(¹w³]­È)
CDBurn
PostBootReminder
SysTray
WebCheck
°£¥ª©O5¼Ë§Ú´NÚ»­ø¨ì°Õ¡A§Ú­øª¾À³¸Ó°µÉA

¦AÚ»®IHKEY_CLASSES_ROOT
¤J­±¥u«Y±o
(¹w³]­È)
´N«§³£µL

½Ð°ª¤â¥´±Ï§Ú°Õ
­ø¸Ó®Í¡A¸U¤G¤À·P¿E¡A³Ò·Ð®Í~~:sss14

pinekin 2007-8-22 12:19 AM

¦pªG§AÚ»­ø¨ì §Y¬O¥Nªívirus¨S¦³¼g¤J§Aªºwindowsµn¿ýÀÉ¡A¨º´N®¥³ß§A¡A¤£¥²°µ¥H¤W·Ð´eªº°Ê§@¡C
¥u­n§Aanti-virus³n¥ó scan¨ì¤S¥i¥H²MªÅvirus´Nok¤F
(P.S. ¨ä¹ê§A¦³¤°»ò¼xª¬?)

iyan 2007-8-22 12:28 AM

¼xª¬¡G
¤@ª½³£µL°ÝÃD¡A¬ðµM¤§¶¡­Ómsn ·|lock¥ª¡AÉA³£°µ­ø¨ì
d¤H·|¦¬¨ì¤@¥y­^¤å¡A¦¸¦¸³£­ø¦P(eg.Look how cute we look in this picture?)
¤§«á¦³­Ófile


§Ú¥Î­Ónod32 ¬Jantivirus ¦Pad-aware¬Jspyware check¹L
¦ý«Y°ÝÃD³£µL§ïµ½.....

iyan 2007-8-22 12:32 AM

filename³£·|ÅÜ
³Ì¥ý«Y©O­Óimg317.zip
¤§«áÅÜ¥ªimgac157.zip

[[i] ¥»©«³Ì«á¥Ñ iyan ©ó 2007-8-22 12:29 AM ½s¿è [/i]]

pinekin 2007-8-22 12:37 AM

¦n¦³¥i¯à«YIRC-Worm.Win32.Agent.a [(Backdoor.Win32.IRCBot.acd) by Kaspersky Anti Virus.] Ê\·|auto send¤@D message­Ú¤H(¥]¬A¤¤­^¤å)
1)§A¥i¥H¥ý¹ý©³del©Ò¦³¦P§A­Ómsn¦³Ãöªºfile (uninstall, ¤â°Êdel©Ò¦³regedit¤ºªº°O¿ý, ¦w¸Ë¥Ø¿ý©³¤Uªº¬ÛÃöfileµ¥µ¥)
2)update³Ì·sªºvirus-defination ³Ì·sªºupdateÀ³¸Ó¤w¸g¦³©O­Óvirusªº¸ê®Æ (NOD32§Ú¤£¤Ó²M·¡¡A¤£¹L¦pªG§A¦³¥Îsymatic/norton´N¥i¥H¥h©xºôdownload ¤â°Êremoval tool¥hdel)
3)¥hsafe mode°µfull system scan
4)re-install msn´ú¸Õ

(²×Âk³£«Y­nª¾¹D«Y«§virus¡Aª¾¹D­Ó¦W´N¦n©ökoÊ\¡A°ß¦³´N¬Oupdate³Ì·svirus-defination¤~À°¨ì§A)

[[i] ¥»©«³Ì«á¥Ñ pinekin ©ó 2007-8-22 01:16 AM ½s¿è [/i]]

mashimaro 2007-8-22 01:12 AM

©O d °ÝÃD­Ú Franco µª³Ì©¥ !!!

iyan 2007-8-22 01:19 AM

¯«ÂݦaNOD32 µL°Õ°Õݯ¨ì­Óthreat:kiss:

C:\WINDOWS\img317.zip

Threat
Win32/IRCBot.YW trojan

ËÝ¥Nªíd «§??

¦ý«Y°ÝÃDÄ~Äò¦³Ø{.....><~~

[[i] ¥»©«³Ì«á¥Ñ iyan ©ó 2007-8-22 01:29 AM ½s¿è [/i]]

Franco 2007-8-22 11:33 AM

§r,¨ä¹êÁ¿¯uªG¥y©O,¦pªG§A¦³¥ÎE-banking,±j¿nª÷,§r,µ¥µ¥¬J¬Jºô¤W²z°]ªA°È
§Ú±j¯P´£Ä³§A­«¸ËWindow ¡A¦]¬°¨C­Óvirus³£§ï¥ª¦n¦hregistry key¡A±N¨Ó¦n¤j¦³¾÷·|·|¥X²{¨ä¥L°ÝÃD~ ¨Ò¦p¬Y¨Ç¨t²Îrun run ¤U,¬ðµM¦P§AÁ¿Error.
¸Õ·Q¤U,·í§A·Q¥Ñ¦Û¤v­Óacct transfer ¿ú¥h²Ä­Ó¤HªG«×,§A«ö¥ªconfirm and submit .. Ê\¦P§AÁ¿Error ,½Ð§AÃö³¬Ê\... ËݧA.... ·|ÂI.
=======================================

¦ý¦pªG¥u¬O¤W¤Wºô,msn ¤U. ËݧA¥Îªð¦Û¤v°¦¨¾¬r,±½§¹¹jÂ÷or del ¥ªÊ\«K¥i¥H¤F.
¦ý½Ð¥ýupdate °µ³Ì·sdatabase ,¾Ú§Ú©Òª¾KIS ­n20¸¹¬Jdatabase ¥ýcheck ¨ì..
norton ¦n¹³¨ì¼È®É³£check ­ø¨ì.......

¦]¬°§A­n­×§ïªðregistry key °µ¥¿±`... ¤£¦p­«¸Ë­«§Ö...

iyan 2007-8-22 07:42 PM

­«¸Ë¬J¸Ü¡A«Y­ø«Y¤@©w­nformat¥ª³¡¾÷Ê\....

Franco 2007-8-23 06:03 PM

[quote]­ì©«¥Ñ [i]iyan[/i] ©ó 2007-8-22 07:35 PM µoªí [url=http://www.hksyu.com/redirect.php?goto=findpost&pid=11454&ptid=1990][img]http://www.hksyu.com/images/common/back.gif[/img][/url]
­«¸Ë¬J¸Ü¡A«Y­ø«Y¤@©w­nformat¥ª³¡¾÷Ê\.... [/quote]

«Y~
¦]¬°§Y¨Ï§A­×´_ËÝÂФW¥h,³£©l²×¦³°ÝÃD

venus_spirit 2007-11-13 06:39 PM

·Q°Ý°Ý¦pªG§Ú°µ¤F¤@ªº¨BÆJ¡A¦ý¬Ý¤£¨ì¦³¢ú¢ì¢û¢ð¢÷¢û¢ü¡@©Î¡@¢û£B¢û¢ð¢÷¢û¢ü¡A§Y¬O»¡§Ú¤£¥Î¸ò¤§«áªº¨â­Ó¨BÆJ°µ¥i¥H¥Î¢é¢ö¢ü¢ñ¡@¢þ¢ñ¢ú¢ý¢û±½¬r°Õ¡A¦ý°ÝÃD¬O§Ú¥Î¤F¡@¢û¢÷¢ø¢ð¢÷¢û¡A¡@¢é¢þ¢ï¡A¡@¢²¢µ¢¯¦w¥þ衞¤h¡A³£§ä¤£¨ì¦³¢þ¢ñ¢ú¢ý¢û¡A¦ý¢î¢ñ¢ô¢í«h¨Ì¢û¢í¢ö¢ì¥X¥h

¦p¦ó¬O¦n¡H

§Æ±æ¦³°ª¤â¥´±Ï¡AÁÂÁ¡I

Franco 2007-11-14 03:18 PM

¢û£B¢û¢ð¢÷¢û¢ü ©O­ÓÀɮ׫Y¤@©w¦³¶ùØ{~~ ¤£¦p§A¼v§A crtl alt del ­Ó­Óµe­± ¨Ó¬Ý¬Ý..
¥H¤Î§Apost §Apost §Aµo°eÀÉ®×­Ó­Ó·Ó¤ù¤W¨Ó,Åý§Ú¬Ý¬Ý¦n¶Ü

shingfung_wong 2007-12-20 09:28 PM

«§«Y¶i¤JWindows¡AÀq»{¬°C:¤Êwindows...........
­¶: [1]
¬d¬Ý§¹¾ãª©¥»: msn ¬r