<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2979908129018178067</id><updated>2011-10-06T13:38:37.864+08:00</updated><category term='作業系統'/><category term='網站黑名單'/><category term='防毒軟體'/><category term='教育訓練'/><category term='搜尋引擎'/><category term='工具與教學'/><category term='研討會'/><category term='虛擬機器'/><category term='安全漏洞'/><category term='自我觀點'/><category term='網站安全'/><category term='產業趨勢'/><category term='網站遭駭'/><category term='加密與解密'/><category term='數位鑑識'/><category term='廣告軟體'/><category term='釣魚網站'/><category term='Rootkit'/><category term='修補程式'/><category term='驗證'/><category term='惡意程式'/><category term='相關連結'/><category term='資訊安全'/><category term='其他'/><category term='徵才'/><category term='垃圾郵件'/><category term='產業新聞'/><category term='false-positive'/><category term='即時通訊'/><category term='評比測試'/><category term='PoC'/><title type='text'>大砲開講</title><subtitle type='html'>分享是進步的原動力&lt;br /&gt; 
&lt;a href='http://www.rogerspeaking.com'&gt;大砲開講新網址為 www.rogerspeaking.com&lt;/a&gt;&lt;br /&gt;
注意：關於被植入惡意連結網站，本站只揭露相關資訊，如果該網站已修復，請來信告知，謝謝。</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default?start-index=101&amp;max-results=100'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>586</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-41555063196641145</id><published>2008-04-09T13:51:00.002+08:00</published><updated>2008-04-10T14:41:18.371+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='其他'/><title type='text'>部落格轉移公告</title><content type='html'>此部落格 (rogerspeaking.blogspot.com) 已經移至 &lt;a href="http://rogerspeaking.com/"&gt;rogerspeaking.com&lt;/a&gt;，此部落格所有舊文章仍然可以瀏覽，&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;但如果您想留言或瀏覽新文章的話，麻煩請至 &lt;/span&gt;&lt;a style="font-weight: bold; color: rgb(255, 0, 0);" href="http://rogerspeaking.com/"&gt;rogerspeaking.com&lt;/a&gt;，謝謝。造成您的不便，深感抱歉。&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-41555063196641145?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/41555063196641145/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=41555063196641145' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/41555063196641145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/41555063196641145'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/04/blog-post_09.html' title='部落格轉移公告'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-5123975077193992270</id><published>2008-03-25T11:46:00.004+08:00</published><updated>2008-03-25T11:58:57.203+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>曼秀雷敦網站被值入惡意連結</title><content type='html'>曼秀雷敦網站被值入惡意連結，此惡意程式為 PWS:Win32/Gamania.gen!D，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R-h3Gta2AtI/AAAAAAAABCk/pMBAVtdAr4I/s1600-h/mentholatum_home_20080325.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R-h3Gta2AtI/AAAAAAAABCk/pMBAVtdAr4I/s320/mentholatum_home_20080325.png" alt="" id="BLOGGER_PHOTO_ID_5181522328444863186" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R-h3Nda2AuI/AAAAAAAABCs/AoJ6ZS1SLHI/s1600-h/mentholatum_malurl_20080325.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R-h3Nda2AuI/AAAAAAAABCs/AoJ6ZS1SLHI/s320/mentholatum_malurl_20080325.png" alt="" id="BLOGGER_PHOTO_ID_5181522444408980194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Google Search查詢的結果，如下圖所示：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R-h3y9a2AvI/AAAAAAAABC0/rnKH7lNhfPg/s1600-h/mentholatum_home_search_by_google_20080325.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R-h3y9a2AvI/AAAAAAAABC0/rnKH7lNhfPg/s320/mentholatum_home_search_by_google_20080325.png" alt="" id="BLOGGER_PHOTO_ID_5181523088654074610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL Injection]&lt;br /&gt;C:\WINDOWS\Debug\0C9C4681802F.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Desktop\2.bat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\microsofts.vbs&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\js[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ms06014[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ma2[1].exe&lt;br /&gt;C:\WINDOWS\Debug\0C9C4681802F.dll&lt;br /&gt;C:\WINDOWS\Debug\0C9C4681802F.exe&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{083A5F21-BCB9-4B21-A121-2584BEEFBFEF}-C:\WINDOWS\Debug\0C9C4681802F.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/3/25 @ 11:)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;0C9C4681802F.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Gamania.gen!D"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.tdw"&lt;br /&gt; [     Panda        ], "Trj/Lineage.HTK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.HTK"&lt;br /&gt; [     Alwil        ], "Win32:Gamania-EB [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Lineage!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.Online.tdw"&lt;br /&gt; [     Norman       ], "Trojan W32/OnLineGames.ALRD"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.QMOnline.gl"&lt;br /&gt; [     Ikarus       ], "Generic.Lineage"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.rzt"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.Online.tdw"&lt;br /&gt;0C9C4681802F.exe:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Gamania.gen!D"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.spw"&lt;br /&gt; [     McAfee       ], "New Malware.x !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.x !!"&lt;br /&gt; [     Alwil        ], "Win32:Gamania-EB [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Lineage!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.spw"&lt;br /&gt; [     Norman       ], "Trojan W32/OnLineGames.ALND"&lt;br /&gt; [     Rising       ], "Trojan.Win32.Agent.zri"&lt;br /&gt; [     Clamav       ], "Trojan.Spy-26631"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Delf.GI"&lt;br /&gt; [     Grisoft      ], "Trojan horse Generic9.BGHG"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.spw"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.spw"&lt;br /&gt;ma2[1].exe:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Gamania.gen!D"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.spw"&lt;br /&gt; [     McAfee       ], "New Malware.x !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.x !!"&lt;br /&gt; [     Alwil        ], "Win32:Gamania-EB [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Lineage!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.spw"&lt;br /&gt; [     Norman       ], "Trojan W32/OnLineGames.ALND"&lt;br /&gt; [     Rising       ], "Trojan.Win32.Agent.zri"&lt;br /&gt; [     Clamav       ], "Trojan.Spy-26631"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Delf.GI"&lt;br /&gt; [     Grisoft      ], "Trojan horse Generic9.BGHG"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.spw"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.spw"&lt;br /&gt;ms06014[1].htm:&lt;br /&gt; [     Microsoft    ], "[-&gt;(SCRIPT0000)]:TrojanDownloader:VBS/Psyme.gen!D"&lt;br /&gt; [     Kaspersky    ], "Trojan-Downloader.VBS.Agent.lb"&lt;br /&gt; [     Sophos       ], "Mal/Psyme-A"&lt;br /&gt; [     HBEDV        ], "JS/Dldr.Noopt.1969"&lt;br /&gt; [     Rising       ], "Trojan.DL.Script.VBS.Small.fb"&lt;br /&gt; [     Ikarus       ], "JS.Downloader.Noopt.1969"&lt;br /&gt; [     Ewido        ], "Downloader.AniLoad.nae"&lt;br /&gt; [     Grisoft      ], "Virus found JS/Downloader.Agent"&lt;br /&gt; [     WebWasher    ], "Script.Dldr.Noopt.1969"&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-5123975077193992270?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/5123975077193992270/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=5123975077193992270' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5123975077193992270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5123975077193992270'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/03/blog-post.html' title='曼秀雷敦網站被值入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_JNaO8YWc9rQ/R-h3Gta2AtI/AAAAAAAABCk/pMBAVtdAr4I/s72-c/mentholatum_home_20080325.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-4586277502387820807</id><published>2008-02-25T16:08:00.008+08:00</published><updated>2008-02-26T00:44:23.243+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='安全漏洞'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>NAUTICA台灣網站被值入惡意連結</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：目前惡意連結已移除 (2008/2/25@16:14)&lt;/span&gt;&lt;br /&gt;NAUTICA台灣網站被值入惡意連結，此惡意程式為 TROJ_DLOADER.EMD，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R8J5NiaHBXI/AAAAAAAABCM/jihAAl_GBZE/s1600-h/nautica-taiwan_home_20080222.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R8J5NiaHBXI/AAAAAAAABCM/jihAAl_GBZE/s320/nautica-taiwan_home_20080222.png" alt="" id="BLOGGER_PHOTO_ID_5170828595656328562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R8J5YSaHBYI/AAAAAAAABCU/LfAs458HE-A/s1600-h/nautica-taiwan_malurl_20080222.bmp"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R8J5YSaHBYI/AAAAAAAABCU/LfAs458HE-A/s320/nautica-taiwan_malurl_20080222.bmp" alt="" id="BLOGGER_PHOTO_ID_5170828780339922306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;展示影片，請看&lt;a href="http://itinternals.com/archives/2008/02/25/592"&gt;這裡&lt;/a&gt;。&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Google Search查詢的結果，如下所示：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R8J5fyaHBZI/AAAAAAAABCc/NbA1zKN812E/s1600-h/nautica-taiwan_infected_by_google_search_20080222.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R8J5fyaHBZI/AAAAAAAABCc/NbA1zKN812E/s320/nautica-taiwan_infected_by_google_search_20080222.png" alt="" id="BLOGGER_PHOTO_ID_5170828909188941202" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\System32\CcEvtSvc.exe&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: CcEvtSvc&lt;br /&gt;DISPLAY: CcEvtSvc&lt;br /&gt;FILE: C:\WINDOWS\System32\CcEvtSvc.exe -k netsvcs&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\in[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\nautica-taiwan.com[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\stat[1].htm&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat&lt;br /&gt;C:\WINDOWS\system32\CcEvtSvc.exe&lt;br /&gt;C:\WINDOWS\system32\MI84.tmp&lt;br /&gt;C:\WINDOWS\system32\reeppoor.tmp&lt;br /&gt;C:\winzvdi.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/2/22 @ 20:35)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;CcEvtSvc.exe:&lt;br /&gt;[ Trend ], "TROJ_BMVD.A"&lt;br /&gt;MI84.tmp:&lt;br /&gt;[ Trend ], "TROJ_BMVD.A"&lt;br /&gt;winzvdi.exe:&lt;br /&gt;[ Trend ], "TROJ_DLOADER.EMD"&lt;br /&gt;in[1].htm:&lt;br /&gt;[     Kaspersky    ], "Trojan-Downloader.JS.Zapchast.f"&lt;br /&gt;[     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt;nautica-taiwan.com[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt;[     Sophos       ], "Mal/Iframe-F"&lt;br /&gt;[     HBEDV        ], "HTML/Dldr.Iframe.U"&lt;br /&gt;[     WebWasher    ], "Script.Dldr.Iframe.U"&lt;br /&gt;[     bitdefender  ], "Trojan.IFrame.AK"&lt;br /&gt;stat[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-4586277502387820807?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/4586277502387820807/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=4586277502387820807' title='2 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4586277502387820807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4586277502387820807'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/02/nautica.html' title='NAUTICA台灣網站被值入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_JNaO8YWc9rQ/R8J5NiaHBXI/AAAAAAAABCM/jihAAl_GBZE/s72-c/nautica-taiwan_home_20080222.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8275367495508929647</id><published>2008-02-25T15:38:00.010+08:00</published><updated>2008-02-26T00:44:43.447+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='安全漏洞'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><category scheme='http://www.blogger.com/atom/ns#' term='網站遭駭'/><title type='text'>台中縣清水鎮公所被轉址與被入惡意連結</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：都已經N天了，目前惡意連結還在(2008/2/25@15:40)，無言... &lt;/span&gt;&lt;br /&gt;台中縣清水鎮公所被轉址與被入惡意連結，此惡意程式為 TSPY_QQPASS.CH，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: 匿名網友)&lt;div id="fullpost"&gt;&lt;br /&gt;當連上台中縣清水鎮公所網站後，馬上被轉址到下列網站：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R8J0WSaHBVI/AAAAAAAABB8/SuXskZwQKF4/s1600-h/chinshui_home_20080219.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R8J0WSaHBVI/AAAAAAAABB8/SuXskZwQKF4/s320/chinshui_home_20080219.png" alt="" id="BLOGGER_PHOTO_ID_5170823248422045010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;該網頁原始碼，如下所示：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R8J0FiaHBUI/AAAAAAAABB0/4hfrPeVfxAg/s1600-h/chinshui_malurl_redirection_20080219.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R8J0FiaHBUI/AAAAAAAABB0/4hfrPeVfxAg/s320/chinshui_malurl_redirection_20080219.png" alt="" id="BLOGGER_PHOTO_ID_5170822960659236162" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;展示影片，請看&lt;a href="http://itinternals.com/archives/2008/02/25/589"&gt;這裡&lt;/a&gt;。&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Google Search查詢的結果，沒發現任何異狀，如下所示：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R8J1kSaHBWI/AAAAAAAABCE/PcFpFMKGnuM/s1600-h/chinshui_home_by_google_search_20080225.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R8J1kSaHBWI/AAAAAAAABCE/PcFpFMKGnuM/s320/chinshui_home_by_google_search_20080225.png" alt="" id="BLOGGER_PHOTO_ID_5170824588451841378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\Program Files\Common Files\svchost.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\Program Files\Common Files\svchost.exe&lt;br /&gt;C:\Program Files\Internet Explorer\OnlO0r.dll&lt;br /&gt;C:\WINDOWS\system32\fhdoor0.dll&lt;br /&gt;C:\WINDOWS\system32\mndoor0.dll&lt;br /&gt;C:\WINDOWS\system32\qhdoor0.dll&lt;br /&gt;C:\WINDOWS\system32\qzdoor0.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\M1.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ss[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\addr[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\click[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\main[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\s[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\add_54738542[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\ms[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\%46%41%51%2E%6A%73[1]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1542776[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\FAQ[1].htm&lt;br /&gt;C:\Program Files\Common Files\fjOs0r.dll&lt;br /&gt;C:\Program Files\Common Files\svchost.exe&lt;br /&gt;C:\Program Files\Internet Explorer\OnlO0r.bak&lt;br /&gt;C:\Program Files\Internet Explorer\OnlO0r.dll&lt;br /&gt;C:\Program Files\Internet Explorer\OnlO0r.obk&lt;br /&gt;C:\temp.exe&lt;br /&gt;C:\WINDOWS\system32\fhdoor0.dll&lt;br /&gt;C:\WINDOWS\system32\mndoor0.dll&lt;br /&gt;C:\WINDOWS\system32\qhdoor0.dll&lt;br /&gt;C:\WINDOWS\system32\qqdoor0.dll&lt;br /&gt;C:\WINDOWS\system32\qsdoor0.dll&lt;br /&gt;C:\WINDOWS\system32\qzdoor0.dll&lt;br /&gt;C:\WINDOWS\~Temp358.tmp&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{49C496E9-732D-4F5D-BEE9-EC113FAA1C97}-C:\WINDOWS\system32\qzdoor0.dll&lt;br /&gt;{61C1B9CE-1A6F-4994-B4A4-0E7C99AD4C28}-C:\WINDOWS\system32\mndoor0.dll&lt;br /&gt;{6C7596CB-31CC-BBA3-BE51-2EEA62F9C51D}-C:\Program Files\Common Files\fjOs0r.dll&lt;br /&gt;{80F15C30-5E9D-4CB9-BE85-F3D5564C6F83}-C:\WINDOWS\system32\fhdoor0.dll&lt;br /&gt;{ABD0935D-B35A-47BD-BA9A-81678DDE74DD}-C:\WINDOWS\system32\qhdoor0.dll&lt;br /&gt;{C2626E66-D21B-E628-C1DF-1DACCFA36ED2}-C:\Program Files\Common Files\fjOs0r.dll&lt;br /&gt;{C26A8AB5-B935-400C-A152-0488714725B1}-C:\WINDOWS\system32\qsdoor0.dll&lt;br /&gt;{CC3596CB-D6C1-ECA1-AE51-DEEA63F6C21C}-C:\Program Files\Internet Explorer\OnlO0r.dll&lt;br /&gt;{D64AC2E4-95B1-40DD-90D9-0C60F7CA64BF}-C:\WINDOWS\system32\qqdoor0.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/2/19 @ 01:31)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;qqdoor0.dll:&lt;br /&gt;[ Trend ], "Possible_Strat-6"&lt;br /&gt;qhdoor0.dll:&lt;br /&gt;[ Trend ], "TSPY_QQPASS.CH"&lt;br /&gt;mndoor0.dll:&lt;br /&gt;[ Trend ], "Possible_Strat-6"&lt;br /&gt;fhdoor0.dll:&lt;br /&gt;[ Trend ], "TSPY_FRETHOG.WF"&lt;br /&gt;svchost.exe:&lt;br /&gt;[ Trend ], "TSPY_ONLINEG.BOM"&lt;br /&gt;OnlO0r.bak:&lt;br /&gt;[ Trend ], "TROJ_Generic.A"&lt;br /&gt;s[1].exe:&lt;br /&gt;[ Trend ], "TROJ_Generic.A"&lt;br /&gt;~Temp358.tmp:&lt;br /&gt;[ Trend ], "TROJ_Generic.A"&lt;br /&gt;qzdoor0.dll:&lt;br /&gt;[ Trend ], "TSPY_FRETHOG.WF"&lt;br /&gt;qsdoor0.dll:&lt;br /&gt;[ Trend ], "TSPY_FRETHOG.WF"&lt;br /&gt;OnlO0r.obk:&lt;br /&gt;[    Symantec     ], "W32.Drom"&lt;br /&gt;[    Microsoft    ], "Worm:Win32/Rodvir.gen"&lt;br /&gt;[    Kaspersky    ], "Trojan-PSW.Win32.Delf.apc"&lt;br /&gt;[    McAfee       ], "PWS-QQPass"&lt;br /&gt;[    McAfee_Beta  ], "PWS-QQPass"&lt;br /&gt;[    Sophos       ], "Mal/PWS-K"&lt;br /&gt;[    Alwil        ], "Win32:AutoRun-U"&lt;br /&gt;[    CAV          ], "Win32/Rodvir.AJ"&lt;br /&gt;[    Nod32        ], "Win32/PSW.OnLineGames.NBR trojan"&lt;br /&gt;[    Fortinet     ], "K!tr.pws"&lt;br /&gt;[    HBEDV        ], "TR/PSW.Delf.ifd.11"&lt;br /&gt;[    Norman       ], "Trojan W32/QQPass.HSC"&lt;br /&gt;[    Ikarus       ], "Trojan-PWS.Win32.OnLineGames.lpg"&lt;br /&gt;[    Grisoft      ], "Trojan horse PSW.Generic5.AJLF"&lt;br /&gt;[    quickheal    ], "TrojanPSW.Delf.apc"&lt;br /&gt;[    vba32        ], "Trojan-PSW.Win32.Delf.apc"&lt;br /&gt;[    Authentium   ], "W32/InfoStealer!Generic"&lt;br /&gt;[    Sunbelt      ], "Trojan-PWS.Delf.IFD"&lt;br /&gt;[    WebWasher    ], "Trojan.PSW.Delf.ifd.11"&lt;br /&gt;[    bitdefender  ], "Trojan.PWS.Delf.IFD"&lt;br /&gt;temp.exe:&lt;br /&gt;[    IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[    Symantec     ], "W32.Drom"&lt;br /&gt;[    Microsoft    ], "[-&gt;(UPX)]:Worm:Win32/Rodvir.gen"&lt;br /&gt;[    Kaspersky    ], "PAK:PE_Patch.UPX, PAK:UPX"&lt;br /&gt;[    McAfee       ], "[0000d0f0.EXE]:PWS-QQPass"&lt;br /&gt;[    McAfee_Beta  ], "[GenUnp\0000d0f0.EXE]:PWS-QQPass"&lt;br /&gt;[    Sophos       ], "[FILE:0000]:Mal/PWS-K"&lt;br /&gt;[    CAV          ], "Win32/Rodvir!generic"&lt;br /&gt;[    Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NBR trojan"&lt;br /&gt;[    Fortinet     ], "K!tr.pws"&lt;br /&gt;[    HBEDV        ], "TR/Autorun.BK"&lt;br /&gt;[    Ikarus       ], "Trojan-PWS.Win32.Delf.aky"&lt;br /&gt;[    Grisoft      ], "Trojan horse PSW.OnlineGames.AEIB"&lt;br /&gt;[    eAladdin     ], "Suspicious File [101]"&lt;br /&gt;[    WebWasher    ], "Trojan.Autorun.BK"&lt;br /&gt;[    bitdefender  ], "Dropped:Trojan.PWS.Delf.IFD"&lt;br /&gt;ss[1].exe:&lt;br /&gt;[    IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[    Symantec     ], "W32.Drom"&lt;br /&gt;[    Microsoft    ], "[-&gt;(UPX)]:Worm:Win32/Rodvir.gen"&lt;br /&gt;[    Kaspersky    ], "PAK:PE_Patch.UPX, PAK:UPX"&lt;br /&gt;[    McAfee       ], "[0000d0f0.EXE]:PWS-QQPass"&lt;br /&gt;[    McAfee_Beta  ], "[GenUnp\0000d0f0.EXE]:PWS-QQPass"&lt;br /&gt;[    Sophos       ], "[FILE:0000]:Mal/PWS-K"&lt;br /&gt;[    CAV          ], "Win32/Rodvir!generic"&lt;br /&gt;[    Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NBR trojan"&lt;br /&gt;[    Fortinet     ], "K!tr.pws"&lt;br /&gt;[    HBEDV        ], "TR/Autorun.BK"&lt;br /&gt;[    Ikarus       ], "Trojan-PWS.Win32.Delf.aky"&lt;br /&gt;[    Grisoft      ], "Trojan horse PSW.OnlineGames.AEIB"&lt;br /&gt;[    eAladdin     ], "Suspicious File [101]"&lt;br /&gt;[    WebWasher    ], "Trojan.Autorun.BK"&lt;br /&gt;[    bitdefender  ], "Dropped:Trojan.PWS.Delf.IFD"&lt;br /&gt;OnlO0r.dll:&lt;br /&gt;[    Symantec     ], "W32.Drom"&lt;br /&gt;[    Microsoft    ], "Worm:Win32/Rodvir.gen"&lt;br /&gt;[    Kaspersky    ], "Trojan-PSW.Win32.Delf.apx"&lt;br /&gt;[    McAfee       ], "PWS-QQPass"&lt;br /&gt;[    McAfee_Beta  ], "PWS-QQPass"&lt;br /&gt;[    Sophos       ], "Mal/PWS-K"&lt;br /&gt;[    Alwil        ], "Win32:AutoRun-U"&lt;br /&gt;[    CAV          ], "Win32/Rodvir!generic"&lt;br /&gt;[    Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NBR trojan"&lt;br /&gt;[    Fortinet     ], "K!tr.pws"&lt;br /&gt;[    HBEDV        ], "TR/PSW.Delf.ifd.12"&lt;br /&gt;[    Ikarus       ], "Trojan-PWS.Delf.IFD"&lt;br /&gt;[    Grisoft      ], "Trojan horse PSW.Generic5.AKDY"&lt;br /&gt;[    Authentium   ], "W32/InfoStealer!Generic"&lt;br /&gt;[    WebWasher    ], "Trojan.PSW.Delf.ifd.12"&lt;br /&gt;[    bitdefender  ], "Trojan.PWS.Delf.IFD"&lt;br /&gt;fjOs0r.dll:&lt;br /&gt;[    Symantec     ], "W32.Drom"&lt;br /&gt;[    Microsoft    ], "Worm:Win32/Rodvir.gen"&lt;br /&gt;[    Kaspersky    ], "Trojan-PSW.Win32.Delf.apx"&lt;br /&gt;[    McAfee       ], "PWS-QQPass"&lt;br /&gt;[    McAfee_Beta  ], "PWS-QQPass"&lt;br /&gt;[    Sophos       ], "Mal/PWS-K"&lt;br /&gt;[    Alwil        ], "Win32:AutoRun-U"&lt;br /&gt;[    CAV          ], "Win32/Rodvir!generic"&lt;br /&gt;[    Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NBR trojan"&lt;br /&gt;[    Fortinet     ], "K!tr.pws"&lt;br /&gt;[    HBEDV        ], "TR/PSW.Delf.ifd.12"&lt;br /&gt;[    Ikarus       ], "Trojan-PWS.Delf.IFD"&lt;br /&gt;[    Grisoft      ], "Trojan horse PSW.Generic5.AKDY"&lt;br /&gt;[    Authentium   ], "W32/InfoStealer!Generic"&lt;br /&gt;[    WebWasher    ], "Trojan.PSW.Delf.ifd.12"&lt;br /&gt;[    bitdefender  ], "Trojan.PWS.Delf.IFD"&lt;br /&gt;ms[1].htm:&lt;br /&gt;[    WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;FAQ[1].htm:&lt;br /&gt;[    WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;click[1].htm:&lt;br /&gt;[    Sophos       ], "Mal/Iframe-A"&lt;br /&gt;addr[1].js:&lt;br /&gt;[    Kaspersky    ], "PAK:JSPack, Trojan-Downloader.JS.Small.kq"&lt;br /&gt;[    Ikarus       ], "Trojan-Downloader.JS.Small.kq"&lt;br /&gt;add_54738542[1].htm:&lt;br /&gt;[    WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;%46%41%51%2E%6A%73[1]:&lt;br /&gt;[    Sophos       ], "Mal/Iframe-C"&lt;br /&gt;[    Grisoft      ], "Virus found HTML/Framer"&lt;br /&gt;main[1].htm:&lt;br /&gt;[    WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8275367495508929647?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8275367495508929647/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8275367495508929647' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8275367495508929647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8275367495508929647'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/02/blog-post_25.html' title='台中縣清水鎮公所被轉址與被入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R8J0WSaHBVI/AAAAAAAABB8/SuXskZwQKF4/s72-c/chinshui_home_20080219.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8717531509780776437</id><published>2008-02-15T13:39:00.010+08:00</published><updated>2008-02-15T14:34:18.431+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>協合國際法律事務所網站被值入惡意連結</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：目前惡意連結已移除 (2008/2/15 @ 14:14)&lt;/span&gt;&lt;br /&gt;協合國際法律事務所網站被值入惡意連結，此惡意程式為 TROJ_DLOADER.DXI，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7UnKiaHBOI/AAAAAAAABA4/0lcq3jLVtH0/s1600-h/lcs_home_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7UnKiaHBOI/AAAAAAAABA4/0lcq3jLVtH0/s320/lcs_home_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5167079209466004706" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7UnWiaHBPI/AAAAAAAABBA/-T8dPj5-n-o/s1600-h/lcs_malurl_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7UnWiaHBPI/AAAAAAAABBA/-T8dPj5-n-o/s320/lcs_malurl_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5167079415624434930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;展示影片，請看&lt;a href="http://itinternals.com/archives/2008/02/15/499"&gt;這裡&lt;/a&gt;。&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Google Search查詢的結果，如下所示：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7UngiaHBQI/AAAAAAAABBI/llz_B9a50O8/s1600-h/lc_infected_by_google_search.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7UngiaHBQI/AAAAAAAABBI/llz_B9a50O8/s320/lc_infected_by_google_search.png" alt="" id="BLOGGER_PHOTO_ID_5167079587423126786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\system32\lssass.exe&lt;br /&gt;C:\WINDOWS\system32\12.exe&lt;br /&gt;C:\WINDOWS\system32\4.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\system32\HDDGuard.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: ATI2HDDSRV&lt;br /&gt;DISPLAY: ATI2HDDSRV&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\ati32srv.sys&lt;br /&gt;&lt;br /&gt;NAME: DeepFree Update&lt;br /&gt;DISPLAY: DeepFree Update&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\pcihdd2.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MicroSofts.pif&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MicroSofts.vbs&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\11[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\985195[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\go[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\jh[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\xx[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\tw[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\down[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\rl[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\vccd[1].htm&lt;br /&gt;C:\WINDOWS\system32\HDDGuard.dll&lt;br /&gt;C:\WINDOWS\system32\lssass.exe&lt;br /&gt;C:\WINDOWS\system32\WIN.INI&lt;br /&gt;C:\WINDOWS\system32\drivers\pcihdd2.sys&lt;br /&gt;C:\WINDOWS\system32\drivers\ati32srv.sys&lt;br /&gt;C:\WINDOWS\system32\12.exe&lt;br /&gt;C:\WINDOWS\system32\4.exe&lt;br /&gt;C:\WINDOWS\system32\73120.dat&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/2/12 @ 14:41)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;11[1].js:&lt;br /&gt;[     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt;12.exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     Panda_Beta   ], "Suspicious file"&lt;br /&gt;[     CAV          ], "Win32/Tilcun!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NML trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "HEUR/Crypted"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     eAladdin     ], "Suspicious File [104]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;73120.dat:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.005"&lt;br /&gt;[     Kaspersky    ], "PAK:NSPack"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     Panda_Beta   ], "Suspicious file"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "HEUR/Malware"&lt;br /&gt;[     Norman       ], "Trojan W32/Hupigon.gen67"&lt;br /&gt;[     Ikarus       ], "Backdoor.Win32.Agent.ahj"&lt;br /&gt;[     eAladdin     ], "Suspicious File [101]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Win32.NewMalware.MH!49939"&lt;br /&gt;[     bitdefender  ], "Trojan.PWS.OnlineGames.OQN"&lt;br /&gt;jh[2].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ppp.js:&lt;br /&gt;[     HBEDV        ], "HTML/Shellcode.Gen"&lt;br /&gt;[     Norman       ], "Trojan HTML/IFrameBof.A"&lt;br /&gt;[     Ewido        ], "Not-A-Virus.Exploit.HTML.IframeBof.d"&lt;br /&gt;[     Authentium   ], "HTML/IFrameBoF"&lt;br /&gt;[     WebWasher    ], "Script.Shellcode.Gen"&lt;br /&gt;rl[1].js:&lt;br /&gt;[     Sophos       ], "Troj/Rexplo-A"&lt;br /&gt;[     HBEDV        ], "JS/Agent.ES"&lt;br /&gt;[     Ikarus       ], "Trojan-Downloader.JS.Agent.ol"&lt;br /&gt;[     Grisoft      ], "Virus found Exploit"&lt;br /&gt;[     WebWasher    ], "Script.Agent.ES"&lt;br /&gt;[     bitdefender  ], "Dropped:Trojan.Downloader.JS.Agent.OL"&lt;br /&gt;tw[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt;[     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt;[     Norman       ], "Trojan HTML/Exploit!IFrame.G"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;vccd[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt;[     Kaspersky    ], "Trojan-Downloader.HTML.IFrame.ee"&lt;br /&gt;[     Sophos       ], "Mal/Iframe-A"&lt;br /&gt;[     HBEDV        ], "JS/Dldr.Age.GGG.167"&lt;br /&gt;[     Norman       ], "Trojan HTML/Exploit!IFrame.G"&lt;br /&gt;[     WebWasher    ], "Script.Dldr.Age.GGG.167"&lt;br /&gt;xx[1].htm:&lt;br /&gt;[     HBEDV        ], "HTML/Dldr.aaa.330"&lt;br /&gt;[     WebWasher    ], "Script.Dldr.aaa.330"&lt;br /&gt;down[1].exe:&lt;br /&gt;[ Trend ], "TROJ_DLOADER.DXI"&lt;br /&gt;HDDGuard.dll:&lt;br /&gt;[ Trend ], "TROJ_AGENT.GES"&lt;br /&gt;lssass.exe:&lt;br /&gt;[ Trend ], "BKDR_HUPIGON.OHB"&lt;br /&gt;lz.js:&lt;br /&gt;[ Trend ], "JS_IFRAMEBO.AL"&lt;br /&gt;MicroSofts.pif:&lt;br /&gt;[ Trend ], "TROJ_DLOADER.DXI"&lt;br /&gt;4.exe:&lt;br /&gt;[ Trend ], "TROJ_SMALL.CAL"&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8717531509780776437?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8717531509780776437/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8717531509780776437' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8717531509780776437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8717531509780776437'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/02/blog-post_8730.html' title='協合國際法律事務所網站被值入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7UnKiaHBOI/AAAAAAAABA4/0lcq3jLVtH0/s72-c/lcs_home_20080212.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-1481569976198946632</id><published>2008-02-15T13:21:00.008+08:00</published><updated>2008-02-15T14:27:03.121+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>太奇數位科技虛擬主機代管中心網站被值入惡意連結</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：目前惡意連結已移除 (2008/2/15 @ 14:14)&lt;br /&gt;&lt;/span&gt;太奇數位科技虛擬主機代管中心網站被值入惡意連結，此惡意程式為 BKDR_HUPIGON.FVR，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R7UkNSaHBKI/AAAAAAAABAY/HXNY3rivV4M/s1600-h/ez_home_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R7UkNSaHBKI/AAAAAAAABAY/HXNY3rivV4M/s320/ez_home_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5167075958175761570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7UkXCaHBLI/AAAAAAAABAg/1k5-17qEhCQ/s1600-h/ez_malurl_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7UkXCaHBLI/AAAAAAAABAg/1k5-17qEhCQ/s320/ez_malurl_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5167076125679486130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;解碼之後，惡意連結如下所示：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R7UkdSaHBMI/AAAAAAAABAo/hilDW9GE5lw/s1600-h/ez_malurl_decoded_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R7UkdSaHBMI/AAAAAAAABAo/hilDW9GE5lw/s320/ez_malurl_decoded_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5167076233053668546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;展示影片，請看&lt;a href="http://itinternals.com/archives/2008/02/15/497"&gt;這裡&lt;/a&gt;。&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Google Search查詢的結果，如下所示：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7UkpCaHBNI/AAAAAAAABAw/wFF80iqk3ew/s1600-h/ez_infected_by_google_search.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7UkpCaHBNI/AAAAAAAABAw/wFF80iqk3ew/s320/ez_infected_by_google_search.png" alt="" id="BLOGGER_PHOTO_ID_5167076434917131474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE (此為微軟ie，但惡意程式利用它，將它隱匿起來，並且，此執行程序會將system.exe鎖住)&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: Windows security service&lt;br /&gt;DISPLAY: Windows security service&lt;br /&gt;FILE: C:\Program Files\systeminfo1\system.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\g0ld.com&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\%73%79%73%2E%68%74%6D[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\last[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\sv[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\virtualhost[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\status[1].js&lt;br /&gt;C:\jiji1.exe&lt;br /&gt;C:\Program Files\systeminfo1\system.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/2/12 @ 14:39)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;system.exe:&lt;br /&gt;[ Trend ], "BKDR_HUPIGON.FVR"&lt;br /&gt;%73%79%73%2E%68%74%6D[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;g0ld.com:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/sv.exe]:Trojan-Downloader.Win32.Agent.iph"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\sv.exe]:Mal/Behav-010"&lt;br /&gt;[     Nod32        ], "[?CAB ?sv.exe]:a variant of Win32/TrojanDownloader.Delf.NJH trojan"&lt;br /&gt;[     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;jiji1.exe:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/www.exe]:Backdoor.Win32.Hupigon.aubv"&lt;br /&gt;[     McAfee       ], "BackDoor-AWQ"&lt;br /&gt;[     McAfee_Beta  ], "BackDoor-AWQ"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\www.exe]:Mal/Behav-058"&lt;br /&gt;[     Nod32        ], "[?CAB ?www.exe]:a variant of Win32/Hupigon trojan"&lt;br /&gt;[     Fortinet     ], "[www.exe]:W32/Hupigon.YQ!tr.bdr"&lt;br /&gt;[     Norman       ], "Trojan Hupigon.gen126.dropper"&lt;br /&gt;[     Rising       ], "[&gt;&gt;www.exe&gt;&gt;Aspack212r]:Backdoor.Gpigeon.GEN"&lt;br /&gt;[     Ewido        ], "[/www.exe]:Backdoor.Hupigon.awp, [/www.exe]:Backdoor.Hupigon.awp"&lt;br /&gt;[     Grisoft      ], "[\www.exe]:Trojan horse BackDoor.Small.52.BQ, Trojan horse BackDoor.Small.52.BQ"&lt;br /&gt;[     quickheal    ], "Win32.Backdoor.Hupigon.ngr3"&lt;br /&gt;[     vba32        ], "BackDoor.Pigeon.6620"&lt;br /&gt;[     WebWasher    ], "Trojan.Backdoor.Hupigon.ami"&lt;br /&gt;last[1].exe:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/www.exe]:Backdoor.Win32.Hupigon.aubv"&lt;br /&gt;[     McAfee       ], "BackDoor-AWQ"&lt;br /&gt;[     McAfee_Beta  ], "BackDoor-AWQ"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\www.exe]:Mal/Behav-058"&lt;br /&gt;[     Nod32        ], "[?CAB ?www.exe]:a variant of Win32/Hupigon trojan"&lt;br /&gt;[     Fortinet     ], "[www.exe]:W32/Hupigon.YQ!tr.bdr"&lt;br /&gt;[     Norman       ], "Trojan Hupigon.gen126.dropper"&lt;br /&gt;[     Rising       ], "[&gt;&gt;www.exe&gt;&gt;Aspack212r]:Backdoor.Gpigeon.GEN"&lt;br /&gt;[     Ewido        ], "[/www.exe]:Backdoor.Hupigon.awp, [/www.exe]:Backdoor.Hupigon.awp"&lt;br /&gt;[     Grisoft      ], "[\www.exe]:Trojan horse BackDoor.Small.52.BQ, Trojan horse BackDoor.Small.52.BQ"&lt;br /&gt;[     quickheal    ], "Win32.Backdoor.Hupigon.ngr3"&lt;br /&gt;[     vba32        ], "BackDoor.Pigeon.6620"&lt;br /&gt;[     WebWasher    ], "Trojan.Backdoor.Hupigon.ami"&lt;br /&gt;sv[1].exe:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/sv.exe]:Trojan-Downloader.Win32.Agent.iph"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\sv.exe]:Mal/Behav-010"&lt;br /&gt;[     Nod32        ], "[?CAB ?sv.exe]:a variant of Win32/TrojanDownloader.Delf.NJH trojan"&lt;br /&gt;[     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-1481569976198946632?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/1481569976198946632/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=1481569976198946632' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1481569976198946632'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1481569976198946632'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/02/blog-post_15.html' title='太奇數位科技虛擬主機代管中心網站被值入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_JNaO8YWc9rQ/R7UkNSaHBKI/AAAAAAAABAY/HXNY3rivV4M/s72-c/ez_home_20080212.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-7886195012948860891</id><published>2008-02-14T17:24:00.005+08:00</published><updated>2008-02-14T18:16:05.693+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='垃圾郵件'/><title type='text'>電子情書夾帶風暴蠕蟲</title><content type='html'>這幾天收到大量有關西洋情人節的電子郵件，內容都包含一個下載連結，開啟其中一個，電腦就叫個不停，發送大量的外部封包，喔，原來是風暴蠕蟲(Storm Worm)。如果各位收到類似的電子郵件，千萬別執行來路不明的連結，否則，就送您上天堂囉！&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7QNEyaHBJI/AAAAAAAABAQ/lRfvzTlZbp0/s1600-h/storm_worm_valentine_home_20080214.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7QNEyaHBJI/AAAAAAAABAQ/lRfvzTlZbp0/s320/storm_worm_valentine_home_20080214.png" alt="" id="BLOGGER_PHOTO_ID_5166769048402723986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;展示影片，請看&lt;a href="http://video.google.com/videoplay?docid=-8644233733421475940"&gt;這裡&lt;/a&gt; (高解析度的AVI檔，請從&lt;a href="http://itinternals.com/wp-content/uploads/2008/02/storm_worm_demo_20080214.zip"&gt;這裡&lt;/a&gt;下載，影片解碼器，可以在&lt;a href="http://www.vmware.com/download/eula/moviedecoder_v55.html"&gt;VMWARE網站&lt;/a&gt;上下載)。&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為(具有Rootkit行為)：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added service]&lt;br /&gt;NAME: diperto1e9d-1b49&lt;br /&gt;DISPLAY: diperto1e9d-1b49&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\diperto1e9d-1b49.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\valentine[1].exe&lt;br /&gt;C:\WINDOWS\system32\diperto.ini&lt;br /&gt;C:\WINDOWS\system32\diperto1e9d-1b49.sys&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/2/14 @ 16:25)，下面的防毒軟體(32家中，只有19家偵測到)可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;AhnLab-V3:   &lt;br /&gt;AntiVir: Worm/Zhelatin.pb&lt;br /&gt;Authentium:   &lt;br /&gt;Avast:&lt;br /&gt;AVG: I-Worm/Nuwar.N&lt;br /&gt;BitDefender: Trojan.Peed.IWW&lt;br /&gt;CAT-QuickHeal:&lt;br /&gt;ClamAV: Trojan.Peed-103&lt;br /&gt;DrWeb: Trojan.Packed.357&lt;br /&gt;eSafe: Suspicious File&lt;br /&gt;eTrust-Vet: Win32/Sintun!generic&lt;br /&gt;EwidoL:&lt;br /&gt;FileAdvisor:&lt;br /&gt;Fortinet: W32/PackTibs.M&lt;br /&gt;F-Prot: W32/Zhelatin.F.gen!Eldorado&lt;br /&gt;F-Secure: Packed.Win32.Tibs.ic&lt;br /&gt;Ikarus: Trojan.Peed.IWV&lt;br /&gt;Kaspersky: Packed.Win32.Tibs.ic&lt;br /&gt;McAfee: W32/Nuwar@MM&lt;br /&gt;Microsoft: TrojanDropper:Win32/Nuwar.gen!B&lt;br /&gt;NOD32v2: probably a variant of Win32/Nuwar.Gen&lt;br /&gt;Norman:&lt;br /&gt;Panda:&lt;br /&gt;Prevx1:&lt;br /&gt;Sophos: W32/Dorf-AW&lt;br /&gt;Sunbelt:&lt;br /&gt;Symantec: Trojan.Peacomm&lt;br /&gt;TheHacker:&lt;br /&gt;VBA32:&lt;br /&gt;VirusBuster: Trojan.DR.Tibs.Gen!Pac.142&lt;br /&gt;Webwasher-Gateway: Worm.Zhelatin.pb&lt;br /&gt;Trend Micro: WORM_NUWAR.AR&lt;br /&gt;&lt;br /&gt;附加訊息&lt;br /&gt;File size: 121857 bytes&lt;br /&gt;MD5: a932b94554f91e4cbd24f204f8dfe577&lt;br /&gt;SHA1: 5fdc1488dd85af9265e398fe4b402c87a845c17f&lt;br /&gt;PEiD: MinGW GCC 3.x&lt;br /&gt;&lt;br /&gt;詳細掃描結果，請參考&lt;a href="http://www.virustotal.com/zh-tw/analisis/63ab29dd8bddd9b60ede7d96f5fd22ed"&gt;這裡&lt;/a&gt;。&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-7886195012948860891?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/7886195012948860891/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=7886195012948860891' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/7886195012948860891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/7886195012948860891'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/02/blog-post_14.html' title='電子情書夾帶風暴蠕蟲'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7QNEyaHBJI/AAAAAAAABAQ/lRfvzTlZbp0/s72-c/storm_worm_valentine_home_20080214.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-1891851764006502495</id><published>2008-02-12T17:20:00.000+08:00</published><updated>2008-02-12T22:05:18.365+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>李玟箖飾品設計網站被值入惡意連結</title><content type='html'>李玟箖飾品設計網站被值入惡意連結，此惡意程式為 BKDR_HUPIGON.FVR，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: 匿名網友)&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R7Fl3yaHBDI/AAAAAAAAA_k/urJyR6gC5JY/s1600-h/accessory_home_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R7Fl3yaHBDI/AAAAAAAAA_k/urJyR6gC5JY/s320/accessory_home_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5166022256669164594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;當進入此網站，點擊進入Blog或飾品後，會被轉址到Yahoo的部落格(如下圖所示)，但此部落格目前沒有被值入惡意連結(留下空的iframe的痕跡)：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7FpKiaHBEI/AAAAAAAAA_s/sxO0WNhsFVo/s1600-h/accessory_redirect_to_yahoo_bambi-souland.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R7FpKiaHBEI/AAAAAAAAA_s/sxO0WNhsFVo/s320/accessory_redirect_to_yahoo_bambi-souland.png" alt="" id="BLOGGER_PHOTO_ID_5166025877326595138" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7GnRCaHBGI/AAAAAAAAA_8/oK2PNBvKv8k/s1600-h/accessory_malurl_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7GnRCaHBGI/AAAAAAAAA_8/oK2PNBvKv8k/s320/accessory_malurl_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5166094158716666978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;解碼之後，惡意連結如下所示：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7GnfCaHBII/AAAAAAAABAI/jDQ016StWb8/s1600-h/accessory_malurl_decoded_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R7GnfCaHBII/AAAAAAAABAI/jDQ016StWb8/s320/accessory_malurl_decoded_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5166094399234835586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;展示影片，請看&lt;a href="http://video.google.com/videoplay?docid=6417921268250283092"&gt;這裡&lt;/a&gt; (高解析度的AVI檔，請從&lt;a href="http://itinternals.com/wp-content/uploads/2008/02/accessory_infected_20080212.zip"&gt;這裡&lt;/a&gt;下載)。&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Google Search查詢的結果，如下所示：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R7FtRyaHBFI/AAAAAAAAA_0/pzbZlucNNec/s1600-h/accessory_by_google_search_20080212.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R7FtRyaHBFI/AAAAAAAAA_0/pzbZlucNNec/s320/accessory_by_google_search_20080212.png" alt="" id="BLOGGER_PHOTO_ID_5166030399927157842" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE (此為微軟ie，但惡意程式利用它，將它隱匿起來，並且，此執行程序會將system.exe鎖住)&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: Windows security service&lt;br /&gt;DISPLAY: Windows security service&lt;br /&gt;FILE: C:\Program Files\systeminfo1\system.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\g0ld.com&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\sv[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\accessory.com[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\last[2].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\%73%79%73%2E%68%74%6D[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\%73%79%73%2E%68%74%6D[2].htm&lt;br /&gt;C:\jiji1.exe&lt;br /&gt;C:\Program Files\systeminfo1\system.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/2/12 @ 14:39)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;system.exe:&lt;br /&gt;[ Trend ], "BKDR_HUPIGON.FVR"&lt;br /&gt;%73%79%73%2E%68%74%6D[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;g0ld.com:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/sv.exe]:Trojan-Downloader.Win32.Agent.iph"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\sv.exe]:Mal/Behav-010"&lt;br /&gt;[     Nod32        ], "[?CAB ?sv.exe]:a variant of Win32/TrojanDownloader.Delf.NJH trojan"&lt;br /&gt;[     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;jiji1.exe:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/www.exe]:Backdoor.Win32.Hupigon.aubv"&lt;br /&gt;[     McAfee       ], "BackDoor-AWQ"&lt;br /&gt;[     McAfee_Beta  ], "BackDoor-AWQ"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\www.exe]:Mal/Behav-058"&lt;br /&gt;[     Nod32        ], "[?CAB ?www.exe]:a variant of Win32/Hupigon trojan"&lt;br /&gt;[     Fortinet     ], "[www.exe]:W32/Hupigon.YQ!tr.bdr"&lt;br /&gt;[     Norman       ], "Trojan Hupigon.gen126.dropper"&lt;br /&gt;[     Rising       ], "[&gt;&gt;www.exe&gt;&gt;Aspack212r]:Backdoor.Gpigeon.GEN"&lt;br /&gt;[     Ewido        ], "[/www.exe]:Backdoor.Hupigon.awp, [/www.exe]:Backdoor.Hupigon.awp"&lt;br /&gt;[     Grisoft      ], "[\www.exe]:Trojan horse BackDoor.Small.52.BQ, Trojan horse BackDoor.Small.52.BQ"&lt;br /&gt;[     quickheal    ], "Win32.Backdoor.Hupigon.ngr3"&lt;br /&gt;[     vba32        ], "BackDoor.Pigeon.6620"&lt;br /&gt;[     WebWasher    ], "Trojan.Backdoor.Hupigon.ami"&lt;br /&gt;last[1].exe:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/www.exe]:Backdoor.Win32.Hupigon.aubv"&lt;br /&gt;[     McAfee       ], "BackDoor-AWQ"&lt;br /&gt;[     McAfee_Beta  ], "BackDoor-AWQ"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\www.exe]:Mal/Behav-058"&lt;br /&gt;[     Nod32        ], "[?CAB ?www.exe]:a variant of Win32/Hupigon trojan"&lt;br /&gt;[     Fortinet     ], "[www.exe]:W32/Hupigon.YQ!tr.bdr"&lt;br /&gt;[     Norman       ], "Trojan Hupigon.gen126.dropper"&lt;br /&gt;[     Rising       ], "[&gt;&gt;www.exe&gt;&gt;Aspack212r]:Backdoor.Gpigeon.GEN"&lt;br /&gt;[     Ewido        ], "[/www.exe]:Backdoor.Hupigon.awp, [/www.exe]:Backdoor.Hupigon.awp"&lt;br /&gt;[     Grisoft      ], "[\www.exe]:Trojan horse BackDoor.Small.52.BQ, Trojan horse BackDoor.Small.52.BQ"&lt;br /&gt;[     quickheal    ], "Win32.Backdoor.Hupigon.ngr3"&lt;br /&gt;[     vba32        ], "BackDoor.Pigeon.6620"&lt;br /&gt;[     WebWasher    ], "Trojan.Backdoor.Hupigon.ami"&lt;br /&gt;sv[1].exe:&lt;br /&gt;[     Alpha_Gen    ], "Possible_TrojDAS"&lt;br /&gt;[     Kaspersky    ], "ARC:Rsrc-Package, ARC:[data0000.cab]:CAB, [data0000.cab/sv.exe]:Trojan-Downloader.Win32.Agent.iph"&lt;br /&gt;[     Sophos       ], "[SfxArchiveData\sv.exe]:Mal/Behav-010"&lt;br /&gt;[     Nod32        ], "[?CAB ?sv.exe]:a variant of Win32/TrojanDownloader.Delf.NJH trojan"&lt;br /&gt;[     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-1891851764006502495?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/1891851764006502495/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=1891851764006502495' title='2 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1891851764006502495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1891851764006502495'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/02/blog-post.html' title='李玟箖飾品設計網站被值入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_JNaO8YWc9rQ/R7Fl3yaHBDI/AAAAAAAAA_k/urJyR6gC5JY/s72-c/accessory_home_20080212.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2249263306945383511</id><published>2008-01-25T18:23:00.000+08:00</published><updated>2008-01-25T18:42:33.601+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>聲寶公司網站遭駭且被值入惡意程式</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：目前此網站尚未修復 (2008/1/25 @ 18:28)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;聲寶公司網站遭駭且被值入惡意程式，此惡意程式為 BKDR_JAVAKBD.A/TSPY_MPASS.A，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R5m5YT4QzBI/AAAAAAAAA_c/hGvigNIj5Vk/s1600-h/sampo_hacked_20080125.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R5m5YT4QzBI/AAAAAAAAA_c/hGvigNIj5Vk/s320/sampo_hacked_20080125.png" alt="" id="BLOGGER_PHOTO_ID_5159358675433868306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;展示影片，請看&lt;a href="http://itinternals.com/archives/2008/01/25/311"&gt;這裡&lt;/a&gt;。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\Taskmanager.exe&lt;br /&gt;C:\WINDOWS\Wintask.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\system32\JDukeNative.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\index[10&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\JVM83.tmp&lt;br /&gt;C:\WINDOWS\Function.zip&lt;br /&gt;C:\WINDOWS\system32\JDukeNative.dll&lt;br /&gt;C:\WINDOWS\system32\User_Info.exe&lt;br /&gt;C:\WINDOWS\TaskManager.exe&lt;br /&gt;C:\WINDOWS\Wintask.exe&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=Taskmanager&lt;br /&gt;Data=C:\WINDOWS\TaskManager.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=Wintask&lt;br /&gt;Data=C:\WINDOWS\WinTask.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/1/23 @ 23:41)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[ Trend ], "BKDR_JAVAKBD.A"&lt;br /&gt;Wintask.exe:&lt;br /&gt;[ Trend ], "BKDR_JAVAKBD.A"&lt;br /&gt;index[10:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     HBEDV        ], "HTML/Infected.WebPage.Gen"&lt;br /&gt; [     WebWasher    ], "Script.Infected.WebPage.Gen"&lt;br /&gt;User_Info.exe:&lt;br /&gt; [     TMAS         ], "CrackingApps_MPass"&lt;br /&gt; [     Symantec     ], "Hacktool.PassReminder"&lt;br /&gt; [     Kaspersky    ], "PAK:UPX"&lt;br /&gt; [     McAfee       ], "PWCrack-MPass"&lt;br /&gt; [     McAfee_Beta  ], "PWCrack-MPass"&lt;br /&gt; [     Panda        ], "HackTool/MSNpass.G"&lt;br /&gt; [     Panda_Beta   ], "HackTool/MSNpass.G"&lt;br /&gt; [     Fortinet     ], "HackerTool/MessenPass"&lt;br /&gt; [     HBEDV        ], "SPR/PSW.Messen.103.4"&lt;br /&gt; [     Ewido        ], "Not-A-Virus.PSWTool.Win32.Messen.102"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     quickheal    ], "Trojan.Horst.pp"&lt;br /&gt; [     WebWasher    ], "Riskware.PSW.Messen.103.4"&lt;br /&gt; [     bitdefender  ], "Application.Messenpass.B"&lt;br /&gt;Function.zip/xynx.hex:&lt;br /&gt; [     Ikarus       ], "PSWTool.Win32.Messen.102"&lt;br /&gt; [     Ewido        ], "Not-A-Virus.PSWTool.Win32.Messen.102"&lt;br /&gt;Function.zip/TaskManager.exe:&lt;br /&gt; [     Alwil        ], "JS:BackDoor-KBD-12"&lt;br /&gt; [     Ikarus       ], "Virus.JS.Backdoor.KBD.12"&lt;br /&gt;Function.zip/Wintask.exe:&lt;br /&gt; [     Alwil        ], "JS:BackDoor-KBD-11"&lt;br /&gt; [     Ikarus       ], "Backdoor.Java.KBD"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2249263306945383511?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2249263306945383511/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2249263306945383511' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2249263306945383511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2249263306945383511'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/blog-post_25.html' title='聲寶公司網站遭駭且被值入惡意程式'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R5m5YT4QzBI/AAAAAAAAA_c/hGvigNIj5Vk/s72-c/sampo_hacked_20080125.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2359157942382227992</id><published>2008-01-24T22:52:00.001+08:00</published><updated>2008-01-24T23:06:28.027+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>全球華文行銷知識庫網站又被植入惡意連結</title><content type='html'>全球華文行銷知識庫網站又被植入惡意連結，此惡意程式為 Infostealer.Lineage，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R5imtD4Qy_I/AAAAAAAAA_M/VhS4cDbKUVk/s1600-h/cyberone_home_20080124.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R5imtD4Qy_I/AAAAAAAAA_M/VhS4cDbKUVk/s320/cyberone_home_20080124.png" alt="" id="BLOGGER_PHOTO_ID_5159056666218515442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R5inIT4QzAI/AAAAAAAAA_U/t7PH3DF7G7Q/s1600-h/cyberone_malurl_20080124.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R5inIT4QzAI/AAAAAAAAA_U/t7PH3DF7G7Q/s320/cyberone_malurl_20080124.png" alt="" id="BLOGGER_PHOTO_ID_5159057134369950722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;展示影片，請看&lt;a href="http://itinternals.com/archives/2008/01/24/296"&gt;這裡&lt;/a&gt;。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\pal32.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\22085.com&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\520[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\index[1].htm&lt;br /&gt;C:\WINDOWS\pal32.dll&lt;br /&gt;C:\WINDOWS\system32\winpal.exe&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{37A5702C-E1ED-4399-A40E-9D263EDC918A}-C:\WINDOWS\pal32.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/1/23 @ 23:41)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;520[1].exe:&lt;br /&gt;[ Trend ], "TSPY_LINEAGE.IB"&lt;br /&gt;22085.com:&lt;br /&gt;[ Trend ], "TSPY_LINEAGE.IB"&lt;br /&gt;winpal.exe:&lt;br /&gt;[ Trend ], "TSPY_LINEAGE.IB"&lt;br /&gt;1[1].htm:&lt;br /&gt;[     McAfee       ], "Exploit-ObscuredHtml"&lt;br /&gt;[     McAfee_Beta  ], "Exploit-ObscuredHtml"&lt;br /&gt;[     HBEDV        ], "HTML/ADODB.Exploit.Gen"&lt;br /&gt;[     Norman       ], "Trojan JS/Exploit!ADODB.Stream.B"&lt;br /&gt;[     Rising       ], "Trojan.DL.VBS.Agent.xhd"&lt;br /&gt;[     Grisoft      ], "Virus identified Exploit"&lt;br /&gt;[     WebWasher    ], "Script.ADODB.Exploit.Gen"&lt;br /&gt;pal32.dll:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.005"&lt;br /&gt;[     Alpha_Gen    ], "Possible_Lneage2"&lt;br /&gt;[     Symantec     ], "Infostealer.Lineage"&lt;br /&gt;[     Microsoft    ], "[-&gt;(NSPack)]:PWS:Win32/Lineage.gen!A"&lt;br /&gt;[     Kaspersky    ], "PAK:NSPack, Trojan-PSW.Win32.OnLineGames.odo"&lt;br /&gt;[     McAfee       ], "PWS-Lineage"&lt;br /&gt;[     McAfee_Beta  ], "PWS-Lineage"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.Lineage.DN trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Lineage.7206F05E"&lt;br /&gt;[     Norman       ], "Backdoor W32/Lineage.AZWJ"&lt;br /&gt;[     Ikarus       ], "Trojan-PWS.Win32.Delf.hh"&lt;br /&gt;[     Grisoft      ], "Trojan horse PSW.Lineage.AHF"&lt;br /&gt;[     eAladdin     ], "Suspicious File [101]"&lt;br /&gt;[     quickheal    ], "TrojanPSW.OnLineGames.odo"&lt;br /&gt;[     vba32        ], "Trojan-PSW.Win32.OnLineGames.odo"&lt;br /&gt;[     WebWasher    ], "Trojan.Lineage.7206F05E"&lt;br /&gt;[     bitdefender  ], "Generic.Lineage.7206F05E"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2359157942382227992?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2359157942382227992/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2359157942382227992' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2359157942382227992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2359157942382227992'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/blog-post_7727.html' title='全球華文行銷知識庫網站又被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_JNaO8YWc9rQ/R5imtD4Qy_I/AAAAAAAAA_M/VhS4cDbKUVk/s72-c/cyberone_home_20080124.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8500689189859527738</id><published>2008-01-18T16:59:00.000+08:00</published><updated>2008-01-24T02:47:52.030+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資訊安全'/><category scheme='http://www.blogger.com/atom/ns#' term='教育訓練'/><title type='text'>「資安技術教育訓練」準備要開課了</title><content type='html'>&lt;a href="http://www.malware-test.com/"&gt;Malware-Test Lab&lt;/a&gt;將在今年二、三月舉辦「資安技術教育訓練」，名額有限，額滿不再招生，如果您有興趣的話，請盡速報名。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;主辦單位：&lt;/span&gt;&lt;a href="http://www.malware-test.com/"&gt;Malware-Test Lab&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;對象：&lt;/span&gt;對此有興趣之相關人員&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;地點：&lt;/span&gt;&lt;a href="http://edu.uuu.com.tw/"&gt;恆逸&lt;/a&gt;或&lt;a href="http://www.iiiedu.org.tw/Taipei/"&gt;資策會&lt;/a&gt;台北教育訓練中心&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;課程費用(&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;課程費用包含稅、講義、茶點、午餐等費用&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;)：&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;2008/1/31以前報名，每人每門課程，新台幣6000元&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;2008/1/31以後報名，每人每門課程，新台幣7000元&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;關於學生部分，每人每門課程，新台幣5000元&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：三門課可以分開報名，你可以選擇你想上的課程報名。&lt;/span&gt;&lt;br /&gt;============================================&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;報名方式：&lt;br /&gt;&lt;/span&gt;請將課程費用匯入下列帳號，然後，將下列的資料寄到 &lt;span style="font-weight: bold;"&gt;service@malware-test.com&lt;/span&gt;：&lt;br /&gt;&lt;ul&gt;&lt;li&gt;您的姓名&lt;/li&gt;&lt;li&gt;您的手機號碼&lt;br /&gt;&lt;/li&gt;&lt;li&gt;您的公司名稱和公司統一編號&lt;/li&gt;&lt;li&gt;發票要開二聯式，還是三聯式(可以報公司帳)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;您的轉帳帳號後六碼&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;轉帳資訊：&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;戶名：梅爾斯特系統有限公司&lt;/li&gt;&lt;li&gt;帳號：212-03-200119-7&lt;/li&gt;&lt;li&gt;銀行/分行：國泰世華銀行 敦化分行&lt;/li&gt;&lt;li&gt;銀行代碼：013&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;聯絡方式：&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;電子郵件：service@malware-test.com&lt;/li&gt;&lt;li&gt;公司電話：02-22507096&lt;/li&gt;&lt;li&gt;手機號碼：0935-660646&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;============================================&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;課程名稱：&lt;/span&gt;OS Architecture and Internals (Windows作業系統架構與核心運作原理)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;開課時間：&lt;/span&gt;2008年2月23日 星期六 09:30~16:30&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;難易度：&lt;/span&gt;中高&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;課程內容 (如果有時間，會多講幾個主題)：&lt;/span&gt;&lt;br /&gt;Introduction&lt;br /&gt;System Architecture&lt;br /&gt;                   　- Requirements and Design Goals&lt;br /&gt;                   　- Operating System Model&lt;br /&gt;                   　- Architecture Overview&lt;br /&gt;                   　- Key System Components&lt;br /&gt;System Mechanism&lt;br /&gt;                   　- Trap Dispatching&lt;br /&gt;                   　- Object Manager&lt;br /&gt;                   　- Synchronization&lt;br /&gt;                   　- System Worker Threads&lt;br /&gt;                   　- Local Procedure Calls(LPCs)&lt;br /&gt;                   　- Wow64&lt;br /&gt;Process and Threads&lt;br /&gt;                   　- Process Internals&lt;br /&gt;                   　- Flow of CreateProcess&lt;br /&gt;                   　- Thread Internals&lt;br /&gt;                   　- Thread Scheduling&lt;br /&gt;                   　- Job Objects&lt;br /&gt;&lt;br /&gt;============================================&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;課程名稱：&lt;/span&gt;User-Mode Rootkit原理、防護與實作&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;開課時間：&lt;/span&gt;2008年3月1日 星期六 09:30~16:30&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;難易度：&lt;/span&gt;中高&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;課程內容 (如果有時間，會多講 ernel-Mode Rootkit)：&lt;/span&gt;&lt;br /&gt;What is a Rootkit?&lt;br /&gt;What can Rootkits do?&lt;br /&gt;User-Mode Rootkits techniques&lt;br /&gt;                   　- Replace files&lt;br /&gt;                   　- Hook DLL’s functions(IAT)&lt;br /&gt;                   　- Modify DLL’s functions(Raw code change)&lt;br /&gt;                   　- DLL injection&lt;br /&gt;                   　...&lt;br /&gt;Tools&lt;br /&gt;Demo&lt;br /&gt;Hands-on Exercises&lt;br /&gt;&lt;br /&gt;============================================&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;課程名稱：&lt;/span&gt;Static Malware and Spyware Analysis (靜態惡意程式與間諜軟體分析)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;開課時間：&lt;/span&gt;2008年3月8日 星期六 09:30~16:30&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;難易度：&lt;/span&gt;中高&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;課程內容 (如果有時間，會多講幾個主題)：&lt;/span&gt;&lt;br /&gt;Introduction to Assembly&lt;br /&gt;Malware Overview&lt;br /&gt;PE Format&lt;br /&gt;Infection Techniques&lt;br /&gt;Self-protection Techniques&lt;br /&gt;Find API Addresses&lt;br /&gt;DLL Patching&lt;br /&gt;...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;注意：&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;主辦單位保有改變課程時間與地點的權利。&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;報名繳費後，如果臨時有事，無法前來，概不退費。&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8500689189859527738?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8500689189859527738/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8500689189859527738' title='13 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8500689189859527738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8500689189859527738'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/blog-post_18.html' title='「資安技術教育訓練」準備要開課了'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-4895413113357280249</id><published>2008-01-18T10:06:00.000+08:00</published><updated>2008-01-19T20:45:35.080+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='其他'/><category scheme='http://www.blogger.com/atom/ns#' term='產業新聞'/><title type='text'>ITinternals網站正式上線</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://itinternals.com"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R5ANydFbszI/AAAAAAAAA_E/r_7q1r-0bUk/s320/itinternals-logo.gif" alt="" id="BLOGGER_PHOTO_ID_5156636733791253298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;經過幾個禮拜的測試，&lt;a href="http://itinternals.com/"&gt;ITternals&lt;/a&gt;網站正式上線了。這個網站主會專注在提供資安新聞、技術、評論及討論等議題，希望各位踴躍提供批評與建議。另外，我們現在正在招募有志一同、有熱情的義工(Volunteer)，幫忙撰寫、編輯各種資安新聞與技術，如果您有興趣，請聯絡我，我的電子郵件是 &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;roger(at)malware-test.com&lt;/span&gt;。&lt;br /&gt;&lt;br /&gt;義工條件有下列幾個(不是必要條件，有興趣者皆可)：&lt;br /&gt;&lt;ul&gt;&lt;li&gt;懂電腦相關技術&lt;/li&gt;&lt;li&gt;懂資安相關技術&lt;/li&gt;&lt;li&gt;懂Windows、Linux、Mac OS X等作業系統&lt;br /&gt;&lt;/li&gt;&lt;li&gt;懂英文&lt;/li&gt;&lt;li&gt;...&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-4895413113357280249?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/4895413113357280249/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=4895413113357280249' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4895413113357280249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4895413113357280249'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/itinternals.html' title='ITinternals網站正式上線'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_JNaO8YWc9rQ/R5ANydFbszI/AAAAAAAAA_E/r_7q1r-0bUk/s72-c/itinternals-logo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2055539046426511203</id><published>2008-01-16T14:54:00.000+08:00</published><updated>2008-01-16T15:31:12.975+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><category scheme='http://www.blogger.com/atom/ns#' term='垃圾郵件'/><title type='text'>情人節未到，風暴蠕蟲先到</title><content type='html'>情人節快要到了，風暴蠕蟲(Storm Worm)作者也跟著蠢蠢欲動。最近發現很多垃圾郵件中都包含風暴蠕蟲的下載連結，如果不小心點擊連結，那會很慘勒。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R42sNdFbswI/AAAAAAAAA-s/Lh9ULUOquzI/s1600-h/storm_worm_home_20080116.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R42sNdFbswI/AAAAAAAAA-s/Lh9ULUOquzI/s320/storm_worm_home_20080116.png" alt="" id="BLOGGER_PHOTO_ID_5155966495554777858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added service]&lt;br /&gt;NAME: burito33dc-bb&lt;br /&gt;DISPLAY: burito33dc-bb&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\burito33dc-bb.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Temp\withlove.exe&lt;br /&gt;C:\WINDOWS\system32\burito33dc-bb.sys&lt;br /&gt;C:\WINDOWS\system32\burito.ini&lt;br /&gt;&lt;br /&gt;此惡意程式具有 Rootkit 的行為 (如下圖所示)，受害者將不知道系統中有此惡意程式：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R42titFbsxI/AAAAAAAAA-0/-kzcF3cVXSs/s1600-h/rootkit-behavior1.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R42titFbsxI/AAAAAAAAA-0/-kzcF3cVXSs/s320/rootkit-behavior1.png" alt="" id="BLOGGER_PHOTO_ID_5155967960138625810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R42totFbsyI/AAAAAAAAA-8/z29C8Lv41OA/s1600-h/rootkit-behavior2.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R42totFbsyI/AAAAAAAAA-8/z29C8Lv41OA/s320/rootkit-behavior2.png" alt="" id="BLOGGER_PHOTO_ID_5155968063217840930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/1/16 @ 12:28)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;burito33dc-bb.sys:&lt;br /&gt;[ Trend ], "TROJ_PEACOMM.BM"&lt;br /&gt;with_love.exe:&lt;br /&gt;[     McAfee       ], "W32/Nuwar@MM"&lt;br /&gt;[     McAfee_Beta  ], "W32/Nuwar@MM"&lt;br /&gt;[     Nod32        ], "a variant of Win32/Nuwar worm"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;withlove.exe:&lt;br /&gt;[     McAfee       ], "W32/Nuwar@MM"&lt;br /&gt;[     McAfee_Beta  ], "W32/Nuwar@MM"&lt;br /&gt;[     Nod32        ], "a variant of Win32/Nuwar worm"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2055539046426511203?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2055539046426511203/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2055539046426511203' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2055539046426511203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2055539046426511203'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/blog-post_16.html' title='情人節未到，風暴蠕蟲先到'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_JNaO8YWc9rQ/R42sNdFbswI/AAAAAAAAA-s/Lh9ULUOquzI/s72-c/storm_worm_home_20080116.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-3819839046175132709</id><published>2008-01-16T10:40:00.000+08:00</published><updated>2008-01-17T23:24:51.180+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>GSN 政府網際服務網被植入惡意連結</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;更新資訊：目前已修復&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;GSN 政府網際服務網被植入惡意連結，此惡意程式為 Backdoor.Win32.Agent.ana，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R41v1tFbsuI/AAAAAAAAA-c/FDUbIFngejE/s1600-h/gsn_nat_gov_home_20080116.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R41v1tFbsuI/AAAAAAAAA-c/FDUbIFngejE/s320/gsn_nat_gov_home_20080116.png" alt="" id="BLOGGER_PHOTO_ID_5155900116835218146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在 04-03.html，但是指到 202(dot)39(dot)47(dot)197，這台主機應該被駭客完全控制了 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R41yZ9FbsvI/AAAAAAAAA-k/ZaACEOkNR-s/s1600-h/gsn_nat_gov_malfile_20080116.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R41yZ9FbsvI/AAAAAAAAA-k/ZaACEOkNR-s/s320/gsn_nat_gov_malfile_20080116.png" alt="" id="BLOGGER_PHOTO_ID_5155902938628731634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\drum[1].ani&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\update[1].exe&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\back1.reg&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\back2.reg&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Comon\ctfmon.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/1/15 @ 15:19)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;04-03[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ctfmon.exe-:&lt;br /&gt;[     Alpha_Gen    ], "Possible_HUPIGON"&lt;br /&gt;[     Kaspersky    ], "Backdoor.Win32.Agent.ana"&lt;br /&gt;[     Sophos       ], "Mal/Dropper-G"&lt;br /&gt;[     CAV          ], "Win32/Lidoor.B"&lt;br /&gt;[     Nod32        ], "Win32/Agent.ANA trojan"&lt;br /&gt;[     HBEDV        ], "BDS/Agent.bze"&lt;br /&gt;[     Grisoft      ], "Trojan horse BackDoor.Agent.GIX"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt;[     Authentium   ], "W32/Backdoor.ARVK"&lt;br /&gt;[     WebWasher    ], "Trojan.Backdoor.Agent.bze"&lt;br /&gt;[     bitdefender  ], "BehavesLike:Win32.ExplorerHijack"&lt;br /&gt;drum[1].ani:&lt;br /&gt;[     Symantec     ], "Downloader"&lt;br /&gt;[     Microsoft    ], "Exploit:Win32/Anicmoo.A"&lt;br /&gt;[     Kaspersky    ], "Exploit.Win32.IMG-ANI.gen"&lt;br /&gt;[     McAfee       ], "Exploit-ANIfile.c"&lt;br /&gt;[     McAfee_Beta  ], "Exploit-ANIfile.c"&lt;br /&gt;[     Alwil        ], "CVE-2007-0038"&lt;br /&gt;[     Nod32        ], "a variant of Win32/TrojanDownloader.Ani.Gen trojan"&lt;br /&gt;[     Fortinet     ], "W32/MalFormed_ANI.C"&lt;br /&gt;[     HBEDV        ], "EXP/Ani.Gen"&lt;br /&gt;[     Rising       ], "Hack.SuspiciousAni"&lt;br /&gt;[     Grisoft      ], "Virus found Exploit"&lt;br /&gt;[     WebWasher    ], "Exploit.Ani.Gen"&lt;br /&gt;[     bitdefender  ], "Exploit.Win32.MS05-002.Gen"&lt;br /&gt;server_time[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;update[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "Possible_HUPIGON"&lt;br /&gt;[     Symantec     ], "Backdoor.Trojan"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact"&lt;br /&gt;[     Sophos       ], "[FILE:0000]:Mal/Dropper-G, Mal/Dropper-G"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     Panda_Beta   ], "Suspicious file"&lt;br /&gt;[     Nod32        ], "a variant of Win32/Agent.BZE trojan"&lt;br /&gt;[     HBEDV        ], "BDS/Agent.bze"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Trojan.Backdoor.Agent.bze"&lt;br /&gt;[     bitdefender  ], "BehavesLike:Win32.ExplorerHijack"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-3819839046175132709?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/3819839046175132709/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=3819839046175132709' title='2 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/3819839046175132709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/3819839046175132709'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/gsn.html' title='GSN 政府網際服務網被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R41v1tFbsuI/AAAAAAAAA-c/FDUbIFngejE/s72-c/gsn_nat_gov_home_20080116.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-349488592689433412</id><published>2008-01-14T17:47:00.000+08:00</published><updated>2008-01-14T18:15:54.014+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>台北市公寓大廈暨社區服務協會網站被植入惡意連結</title><content type='html'>台北市公寓大廈暨社區服務協會網站被植入惡意連結，此惡意程式為 TSPY_ONLINEG.NSM，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: 匿名網友)&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R4swh9FbssI/AAAAAAAAA-M/8d01GTTJ2Es/s1600-h/tbca_org_home_20080107.jpg"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R4swh9FbssI/AAAAAAAAA-M/8d01GTTJ2Es/s320/tbca_org_home_20080107.jpg" alt="" id="BLOGGER_PHOTO_ID_5155267558346830530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R4sxJdFbstI/AAAAAAAAA-U/NZqjsebOY7w/s1600-h/tbca_org_malurl_20080107.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R4sxJdFbstI/AAAAAAAAA-U/NZqjsebOY7w/s320/tbca_org_malurl_20080107.png" alt="" id="BLOGGER_PHOTO_ID_5155268236951663314" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\system32\gjcsczc.exe&lt;br /&gt;C:\WINDOWS\system32\avwghst.exe&lt;br /&gt;C:\WINDOWS\system32\avwlist.exe&lt;br /&gt;C:\WINDOWS\system32\mszxaab32.dll&lt;br /&gt;C:\WINDOWS\Fonts\kawdjaz.exe&lt;br /&gt;C:\WINDOWS\system32\rsjzasp.exe&lt;br /&gt;C:\WINDOWS\Fonts\raqjltl.exe&lt;br /&gt;C:\WINDOWS\Fonts\rsztosp.exe&lt;br /&gt;C:\WINDOWS\system32\TxoMoU.Exe&lt;br /&gt;C:\WINDOWS\system32\avwghst.exe&lt;br /&gt;C:\WINDOWS\Fonts\ratbttl.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxsmis.exe&lt;br /&gt;c:\Program Files\lsasso.exe&lt;br /&gt;C:\WINDOWS\system32\gjtmazc.exe&lt;br /&gt;C:\WINDOWS\Fonts\rsjzbsp.exe&lt;br /&gt;C:\WINDOWS\system32\avzxlst.exe&lt;br /&gt;C:\WINDOWS\system32\swrcfac.exe&lt;br /&gt;C:\WINDOWS\Fonts\avwgist.exe&lt;br /&gt;C:\WINDOWS\system32\avwghst.exe&lt;br /&gt;C:\WINDOWS\system32\avwlist.exe&lt;br /&gt;C:\WINDOWS\Fonts\kawdjaz.exe&lt;br /&gt;C:\WINDOWS\Fonts\raqjltl.exe&lt;br /&gt;C:\WINDOWS\system32\avzxmst.exe&lt;br /&gt;C:\WINDOWS\system32\avzxlst.exe&lt;br /&gt;C:\WINDOWS\Fonts\rsmyksp.exe&lt;br /&gt;C:\WINDOWS\Fonts\jsqxbzc.exe&lt;br /&gt;C:\WINDOWS\Fonts\jsqxbzc.exe&lt;br /&gt;C:\WINDOWS\system32\swrcfac.exe&lt;br /&gt;C:\WINDOWS\Fonts\jsqsczc.exe&lt;br /&gt;C:\WINDOWS\Fonts\avwljst.exe&lt;br /&gt;C:\WINDOWS\Fonts\wsmsfax.exe&lt;br /&gt;C:\WINDOWS\system32\okmhdaz.exe&lt;br /&gt;C:\WINDOWS\system32\jsqxazc.exe&lt;br /&gt;C:\WINDOWS\Fonts\rarjftl.exe&lt;br /&gt;C:\WINDOWS\Fonts\gjcsdzc.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\MSInfo\System76.Ins&lt;br /&gt;C:\Program Files\Common Files\Services\svchost.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys&lt;br /&gt;C:\WINDOWS\124327MM.DLL&lt;br /&gt;C:\WINDOWS\124327WL.DLL&lt;br /&gt;C:\WINDOWS\Fonts\avwgimn.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwljmn.dll&lt;br /&gt;C:\WINDOWS\Fonts\gjcsdyc.dll&lt;br /&gt;C:\WINDOWS\Fonts\jsqscyc.dll&lt;br /&gt;C:\WINDOWS\Fonts\jsqxbyc.dll&lt;br /&gt;C:\WINDOWS\Fonts\kawdjzy.dll&lt;br /&gt;C:\WINDOWS\Fonts\raqjlpi.dll&lt;br /&gt;C:\WINDOWS\Fonts\rarjfpi.dll&lt;br /&gt;C:\WINDOWS\Fonts\ratbtpi.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsjzbpm.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsmykpm.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsztopm.dll&lt;br /&gt;C:\WINDOWS\Fonts\wsmsfzx.dll&lt;br /&gt;C:\WINDOWS\system32\aimivc.dll&lt;br /&gt;C:\WINDOWS\system32\anxitdnwow.dll&lt;br /&gt;C:\WINDOWS\system32\avwghmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwlimn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxlmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxmmn.dll&lt;br /&gt;C:\WINDOWS\system32\cmdbcs.dll&lt;br /&gt;C:\WINDOWS\system32\DirectX10.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\gdmsi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwli32.dll&lt;br /&gt;C:\WINDOWS\system32\gjcscyc.dll&lt;br /&gt;C:\WINDOWS\system32\gjtmayc.dll&lt;br /&gt;C:\WINDOWS\system32\hrekfp.dll&lt;br /&gt;C:\WINDOWS\system32\IGB_DJOL_1007.dll&lt;br /&gt;C:\WINDOWS\system32\jdzctd.dll&lt;br /&gt;C:\WINDOWS\system32\jsqxayc.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxsmma.dll&lt;br /&gt;C:\WINDOWS\system32\Kvsc3.dll&lt;br /&gt;C:\WINDOWS\system32\kxhqcluzx.dll&lt;br /&gt;C:\WINDOWS\system32\LotusHlp.dll&lt;br /&gt;C:\WINDOWS\system32\MsIMMs32.dll&lt;br /&gt;C:\WINDOWS\system32\MsPrint32D.dll&lt;br /&gt;C:\WINDOWS\system32\okmhdzy.dll&lt;br /&gt;C:\WINDOWS\system32\oyhkmx.dll&lt;br /&gt;C:\WINDOWS\system32\PTSShell.dll&lt;br /&gt;C:\WINDOWS\system32\rcmwkscdj.dll&lt;br /&gt;C:\WINDOWS\system32\rsjzapm.dll&lt;br /&gt;C:\WINDOWS\system32\swrcfzc.dll&lt;br /&gt;C:\WINDOWS\system32\upxdnd.dll&lt;br /&gt;C:\WINDOWS\system32\whulgh.dll&lt;br /&gt;C:\WINDOWS\system32\WinForm.dll&lt;br /&gt;C:\WINDOWS\system32\wsmsezx.dll&lt;br /&gt;C:\WINDOWS\system32\WSockDrv32.dll&lt;br /&gt;C:\WINDOWS\system32\zeakpn.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: PciHardDisk&lt;br /&gt;DISPLAY: PciHardDisk&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\fat32.sys&lt;br /&gt;&lt;br /&gt;NAME: PciHdd&lt;br /&gt;DISPLAY: PciHdd&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\pcihdd.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\autorun.inf&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\callrun.vbs&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\commomds.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYLOADER.EXE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MSDEG32.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\OPE133.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\OPE98.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\OPE99.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\OPEC8.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\OPEED.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\OPEF3.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\OPEFA.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\temp336.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp104.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp105.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp106.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp107.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp108.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp10B.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp10D.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp10E.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp110.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp111.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp113.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp115.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp117.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp118.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp11A.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp11B.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp11C.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp11E.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp11F.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp120.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp121.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp124.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp125.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp126.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp128.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp129.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp12A.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp12B.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp12C.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp12E.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp12F.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp130.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp131.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp132.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA0.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA1.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA2.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA3.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA4.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA5.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA7.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA8.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpAA.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpAB.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpAC.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpAD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB0.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB1.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB3.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB4.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB7.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB8.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpB9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpBA.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpBC.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpBE.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpBF.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC0.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC1.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC2.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC3.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC4.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC5.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC7.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpCA.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpCC.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpCD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpCE.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpCF.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD1.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD2.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD3.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD4.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD7.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpDB.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpDC.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpDD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpDE.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpDF.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE0.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE3.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE4.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE5.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpEA.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpEB.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpEC.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpF0.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpF1.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpF2.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpF4.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpF5.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpF6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpFD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\06014[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\370[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\a11[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\a13[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\a16[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\a18[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\a22[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\a26[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\gg[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ha[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\jh[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\real[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s28[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\shell[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\shell[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\shibie[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\vip[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\web[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\xx[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\Zn3703[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\Zn3703[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\6681666[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\a15[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\a17[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\a20[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\a24[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\baidu[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\g15[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\g1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\gg[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ha[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\s28[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\shell[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\shibie[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\web[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\xx[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\06014[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\101logo[1].jpg&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1531419[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\370[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a10[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a14[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a19[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a23[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a28[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\dm[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\g15[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\gg[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\ha[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\IENoRun[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\ms[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\rl[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\shell[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\table[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\985195[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\a12[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\a21[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\a25[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\dm[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\gg[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\IE[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\mm_menu[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\ms1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\s28[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\s[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\web[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\xx[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\Zn3703[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\ntuser.com&lt;br /&gt;C:\pagefile.pif&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\MSInfo\System36.jup&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\MSInfo\System76.Ins&lt;br /&gt;C:\Program Files\Common Files\Services\svchost.exe&lt;br /&gt;C:\Program Files\ctfmond.exe&lt;br /&gt;C:\Program Files\ctfmonf.exe&lt;br /&gt;C:\Program Files\ctfmoni.exe&lt;br /&gt;C:\Program Files\ctfmonj.exe&lt;br /&gt;C:\Program Files\ctfmonk.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\anHVaZQ7.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Bh6I6kyz.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\DV21yAp4.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Tao&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvWin_5.Jmp&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Sy_Win7k.Jmp&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\v7FOBoPh.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Tao&lt;br /&gt;C:\Program Files\lsass6.exe&lt;br /&gt;C:\Program Files\lsass7.exe&lt;br /&gt;C:\Program Files\lsasso.exe&lt;br /&gt;C:\soS.Exe&lt;br /&gt;C:\WINDOWS\124327L.exe&lt;br /&gt;C:\WINDOWS\124327M.exe&lt;br /&gt;C:\WINDOWS\124327MM.DLL&lt;br /&gt;C:\WINDOWS\124327WL.DLL&lt;br /&gt;C:\WINDOWS\AVPSrv.exE&lt;br /&gt;C:\WINDOWS\cmdbcs.exe&lt;br /&gt;C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;C:\WINDOWS\Fonts\ardasbse.fon&lt;br /&gt;C:\WINDOWS\Fonts\armebsea.fon&lt;br /&gt;C:\WINDOWS\Fonts\avwghina.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwgiin.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwgimn.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwgist.exe&lt;br /&gt;C:\WINDOWS\Fonts\avwliinc.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwljin.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwljmn.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwljst.exe&lt;br /&gt;C:\WINDOWS\Fonts\avzxlin.dll&lt;br /&gt;C:\WINDOWS\Fonts\avzxminc.dll&lt;br /&gt;C:\WINDOWS\Fonts\chqibur.fon&lt;br /&gt;C:\WINDOWS\Fonts\chrebur.fon&lt;br /&gt;C:\WINDOWS\Fonts\chtibur.fon&lt;br /&gt;C:\WINDOWS\Fonts\enwebfx.fon&lt;br /&gt;C:\WINDOWS\Fonts\gejibnd.fon&lt;br /&gt;C:\WINDOWS\Fonts\gemobnd.fon&lt;br /&gt;C:\WINDOWS\Fonts\gezebnd.fon&lt;br /&gt;C:\WINDOWS\Fonts\gjcscssb.dll&lt;br /&gt;C:\WINDOWS\Fonts\gjcsdss.dll&lt;br /&gt;C:\WINDOWS\Fonts\gjcsdyc.dll&lt;br /&gt;C:\WINDOWS\Fonts\gjcsdzc.exe&lt;br /&gt;C:\WINDOWS\Fonts\gjcubxw.fon&lt;br /&gt;C:\WINDOWS\Fonts\gjtmass.dll&lt;br /&gt;C:\WINDOWS\Fonts\gjtoaxw.fon&lt;br /&gt;C:\WINDOWS\Fonts\jshubxw.fon&lt;br /&gt;C:\WINDOWS\Fonts\jsqscss.dll&lt;br /&gt;C:\WINDOWS\Fonts\jsqscyc.dll&lt;br /&gt;C:\WINDOWS\Fonts\jsqsczc.exe&lt;br /&gt;C:\WINDOWS\Fonts\jsqxassb.dll&lt;br /&gt;C:\WINDOWS\Fonts\jsqxbss.dll&lt;br /&gt;C:\WINDOWS\Fonts\jsqxbyc.dll&lt;br /&gt;C:\WINDOWS\Fonts\jsqxbzc.exe&lt;br /&gt;C:\WINDOWS\Fonts\jssgbxw.fon&lt;br /&gt;C:\WINDOWS\Fonts\kawdjaz.exe&lt;br /&gt;C:\WINDOWS\Fonts\kawdjcs.dll&lt;br /&gt;C:\WINDOWS\Fonts\kawdjzy.dll&lt;br /&gt;C:\WINDOWS\Fonts\kvdxsmcfb.dll&lt;br /&gt;C:\WINDOWS\Fonts\msguasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\msgubsd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mswubsd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mszhasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mszhbsd.fon&lt;br /&gt;C:\WINDOWS\Fonts\okmhdcsb.dll&lt;br /&gt;C:\WINDOWS\Fonts\raqjlni.dll&lt;br /&gt;C:\WINDOWS\Fonts\raqjlpi.dll&lt;br /&gt;C:\WINDOWS\Fonts\raqjltl.exe&lt;br /&gt;C:\WINDOWS\Fonts\rarjfni.dll&lt;br /&gt;C:\WINDOWS\Fonts\rarjfpi.dll&lt;br /&gt;C:\WINDOWS\Fonts\rarjftl.exe&lt;br /&gt;C:\WINDOWS\Fonts\ratbtni.dll&lt;br /&gt;C:\WINDOWS\Fonts\ratbtpi.dll&lt;br /&gt;C:\WINDOWS\Fonts\ratbttl.exe&lt;br /&gt;C:\WINDOWS\Fonts\rsjzafgb.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsjzbfg.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsjzbpm.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsjzbsp.exe&lt;br /&gt;C:\WINDOWS\Fonts\rsmykfg.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsmykpm.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsmyksp.exe&lt;br /&gt;C:\WINDOWS\Fonts\rsztofg.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsztopm.dll&lt;br /&gt;C:\WINDOWS\Fonts\rsztosp.exe&lt;br /&gt;C:\WINDOWS\Fonts\swrcfcsb.dll&lt;br /&gt;C:\WINDOWS\Fonts\system\ati2evxx.exe&lt;br /&gt;C:\WINDOWS\Fonts\wirebfw.fon&lt;br /&gt;C:\WINDOWS\Fonts\wsmsecja.dll&lt;br /&gt;C:\WINDOWS\Fonts\wsmsfax.exe&lt;br /&gt;C:\WINDOWS\Fonts\wsmsfcj.dll&lt;br /&gt;C:\WINDOWS\Fonts\wsmsfzx.dll&lt;br /&gt;C:\WINDOWS\Fonts\wymoafz.fon&lt;br /&gt;C:\WINDOWS\Fonts\wymobfz.fon&lt;br /&gt;C:\WINDOWS\Kvsc3.exE&lt;br /&gt;C:\WINDOWS\LotusHlp.exe&lt;br /&gt;C:\WINDOWS\MsIMMs32.exE&lt;br /&gt;C:\WINDOWS\MsPrint32D.exe&lt;br /&gt;C:\WINDOWS\NVDispDRV.EXE&lt;br /&gt;C:\WINDOWS\PTSShell.exe&lt;br /&gt;C:\WINDOWS\quit.exe&lt;br /&gt;C:\WINDOWS\SHAProc.exe&lt;br /&gt;C:\WINDOWS\system32\0SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\12SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\18SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\19SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\20SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\3SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\5SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\6SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\7SvTh.exe&lt;br /&gt;C:\WINDOWS\system32\aimivc.dll&lt;br /&gt;C:\WINDOWS\system32\anxitdnwow.dll&lt;br /&gt;C:\WINDOWS\system32\Autorun.Inf&lt;br /&gt;C:\WINDOWS\system32\AVPSrv.dll&lt;br /&gt;C:\WINDOWS\system32\avwghmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwghst.exe&lt;br /&gt;C:\WINDOWS\system32\avwlimn.dll&lt;br /&gt;C:\WINDOWS\system32\avwlist.exe&lt;br /&gt;C:\WINDOWS\system32\avzxlmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxlst.exe&lt;br /&gt;C:\WINDOWS\system32\avzxmmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxmst.exe&lt;br /&gt;C:\WINDOWS\system32\bgktyp.dll&lt;br /&gt;C:\WINDOWS\system32\cmdbcs.dll&lt;br /&gt;C:\WINDOWS\system32\Com\comrepl32.exe&lt;br /&gt;C:\WINDOWS\system32\config\AppEventw.cfg&lt;br /&gt;C:\WINDOWS\system32\config\sysEventw.cfg&lt;br /&gt;C:\WINDOWS\system32\DbgHlp32.dll&lt;br /&gt;C:\WINDOWS\system32\DirectX10.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\msconkt.sys&lt;br /&gt;C:\WINDOWS\system32\drivers\pcibus.sys&lt;br /&gt;C:\WINDOWS\system32\drivers\scvhost.exe&lt;br /&gt;C:\WINDOWS\system32\drivers\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\elucgv.dll&lt;br /&gt;C:\WINDOWS\system32\FTCCompress.dll&lt;br /&gt;C:\WINDOWS\system32\FUEb.CoM&lt;br /&gt;C:\WINDOWS\system32\FUEc.CoM&lt;br /&gt;C:\WINDOWS\system32\FUEx.CoM&lt;br /&gt;C:\WINDOWS\system32\gdmsi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwli32.dll&lt;br /&gt;C:\WINDOWS\system32\gjcscyc.dll&lt;br /&gt;C:\WINDOWS\system32\gjcsczc.exe&lt;br /&gt;C:\WINDOWS\system32\gjtmayc.dll&lt;br /&gt;C:\WINDOWS\system32\gjtmazc.exe&lt;br /&gt;C:\WINDOWS\system32\hrekfp.dll&lt;br /&gt;C:\WINDOWS\system32\IGB_DJOL_1007.dll&lt;br /&gt;C:\WINDOWS\system32\IGB_DJOL_1007.exe&lt;br /&gt;C:\WINDOWS\system32\ixdttm.dll&lt;br /&gt;C:\WINDOWS\system32\jdzctd.dll&lt;br /&gt;C:\WINDOWS\system32\jsqxayc.dll&lt;br /&gt;C:\WINDOWS\system32\jsqxazc.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxsmis.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxsmma.dll&lt;br /&gt;C:\WINDOWS\system32\Kvsc3.dll&lt;br /&gt;C:\WINDOWS\system32\kxhqcluzx.dll&lt;br /&gt;C:\WINDOWS\system32\LotusHlp.dll&lt;br /&gt;C:\WINDOWS\system32\LYLOADER.EXE&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\MSDEG32.DLL&lt;br /&gt;C:\WINDOWS\system32\mshmsdjs32.dll&lt;br /&gt;C:\WINDOWS\system32\MsIMMs32.dll&lt;br /&gt;C:\WINDOWS\system32\MsPrint32D.dll&lt;br /&gt;C:\WINDOWS\system32\mszxaab32.dll&lt;br /&gt;C:\WINDOWS\system32\NVDispDrv.dll&lt;br /&gt;C:\WINDOWS\system32\okmhdaz.exe&lt;br /&gt;C:\WINDOWS\system32\okmhdzy.dll&lt;br /&gt;C:\WINDOWS\system32\oyhkmx.dll&lt;br /&gt;C:\WINDOWS\system32\PTSShell.dll&lt;br /&gt;C:\WINDOWS\system32\rcmwkscdj.dll&lt;br /&gt;C:\WINDOWS\system32\REGKEY.hiv&lt;br /&gt;C:\WINDOWS\system32\rsjzapm.dll&lt;br /&gt;C:\WINDOWS\system32\rsjzasp.exe&lt;br /&gt;C:\WINDOWS\system32\sfkxrl.dll&lt;br /&gt;C:\WINDOWS\system32\SHAProc.dll&lt;br /&gt;C:\WINDOWS\system32\swrcfac.exe&lt;br /&gt;C:\WINDOWS\system32\swrcfzc.dll&lt;br /&gt;C:\WINDOWS\system32\taimpo.txt&lt;br /&gt;C:\WINDOWS\system32\TxoMoU.Exe&lt;br /&gt;C:\WINDOWS\system32\upxdnd.dll&lt;br /&gt;C:\WINDOWS\system32\whulgh.dll&lt;br /&gt;C:\WINDOWS\system32\WinForm.dll&lt;br /&gt;C:\WINDOWS\system32\wsmseax.exe&lt;br /&gt;C:\WINDOWS\system32\wsmsezx.dll&lt;br /&gt;C:\WINDOWS\system32\WSockDrv32.dll&lt;br /&gt;C:\WINDOWS\system32\wsvzwl.dll&lt;br /&gt;C:\WINDOWS\system32\wxptdi.sys&lt;br /&gt;C:\WINDOWS\system32\xpsvde.dll&lt;br /&gt;C:\WINDOWS\system32\zeakpn.dll&lt;br /&gt;C:\WINDOWS\upxdnd.exe&lt;br /&gt;C:\WINDOWS\WinForm.exE&lt;br /&gt;C:\WINDOWS\WSockDrv32.exe&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}-C:\WINDOWS\system32\rsjzapm.dll&lt;br /&gt;{1C098A56-F90F-A789-901F-8906546720C1}-C:\WINDOWS\system32\gjtmayc.dll&lt;br /&gt;{1D098345-9012-8750-8910-9128098134D1}-C:\WINDOWS\system32\jsqxayc.dll&lt;br /&gt;{22FAACDE-34DA-CCD4-AB4D-DA34485A3422}-C:\WINDOWS\Fonts\rsjzbpm.dll&lt;br /&gt;{2D098345-9012-8750-8910-9128098134D2}-C:\WINDOWS\Fonts\jsqxbyc.dll&lt;br /&gt;{3A098324-8631-9087-7650-8907643562A3}-C:\WINDOWS\Fonts\jsqscyc.dll&lt;br /&gt;{3FA10261-B890-F432-A453-69F1023513F3}-C:\WINDOWS\system32\gjcscyc.dll&lt;br /&gt;{471B15AD-7A9C-491D-9C19-4E15B12DCE00}-C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys&lt;br /&gt;{4A57CAD1-412F-9547-713F-9641FA3FC7A4}-C:\WINDOWS\system32\okmhdzy.dll&lt;br /&gt;{4bcb7a90-b0ab-498e-81ab-9c6f50f0d977}-IGB_DJOL_1007.dll&lt;br /&gt;{4FA10261-B890-F432-A453-69F1023513F4}-C:\WINDOWS\Fonts\gjcsdyc.dll&lt;br /&gt;{57650011-3344-6688-4899-345FABCD1575}-C:\WINDOWS\Fonts\ratbtpi.dll&lt;br /&gt;{6598FF45-DA60-F48A-BC43-10AC47853D56}-C:\WINDOWS\Fonts\rarjfpi.dll&lt;br /&gt;{778A7521-FA87-34AB-34C2-4893F3AD34C7}-C:\WINDOWS\system32\swrcfzc.dll&lt;br /&gt;{792FADFA-BCDE-ACDF-CDEF-21054865CBA7}-C:\WINDOWS\system32\wsmsezx.dll&lt;br /&gt;{892FADFA-BCDE-ACDF-CDEF-21054865CBA8}-C:\WINDOWS\Fonts\wsmsfzx.dll&lt;br /&gt;{8A1247C1-53DA-FF43-ABD3-345F323A48D8}-C:\WINDOWS\system32\avwghmn.dll&lt;br /&gt;{9960356A-458E-DE24-BD50-268F589A56A9}-C:\WINDOWS\system32\avwlimn.dll&lt;br /&gt;{9963387B-212E-4643-B207-82DAEA0E713D}-C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys&lt;br /&gt;{9A1247C1-53DA-FF43-ABD3-345F323A48D9}-C:\WINDOWS\Fonts\avwgimn.dll&lt;br /&gt;{A8907901-1416-3389-9981-37217856998A}-C:\WINDOWS\Fonts\kawdjzy.dll&lt;br /&gt;{A960356A-458E-DE24-BD50-268F589A56AA}-C:\WINDOWS\Fonts\avwljmn.dll&lt;br /&gt;{BE32FA58-3453-FA2D-BC49-F340348ACCEB}-C:\WINDOWS\Fonts\rsmykpm.dll&lt;br /&gt;{C4783410-4F90-34A0-7820-3230ACD05F4C}-C:\WINDOWS\Fonts\raqjlpi.dll&lt;br /&gt;{C859245F-345D-BC13-AC4F-145D47DA34FC}-C:\WINDOWS\system32\avzxlmn.dll&lt;br /&gt;{D859245F-345D-BC13-AC4F-145D47DA34FD}-C:\WINDOWS\system32\avzxmmn.dll&lt;br /&gt;{DD561258-45F3-A451-F908-A258458226DD}-C:\WINDOWS\system32\kvdxsmma.dll&lt;br /&gt;{F34345F1-DACF-3452-CB7D-4620F34A153F}-C:\WINDOWS\Fonts\rsztopm.dll&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=crsss&lt;br /&gt;Data=C:\WINDOWS\system32\TxoMoU.Exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinForm&lt;br /&gt;Data=C:\WINDOWS\WinForm.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WSockDrv32&lt;br /&gt;Data=C:\WINDOWS\WSockDrv32.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=upxdnd&lt;br /&gt;Data=C:\WINDOWS\upxdnd.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=MsIMMs32&lt;br /&gt;Data=C:\WINDOWS\MsIMMs32.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=MsPrint32D&lt;br /&gt;Data=C:\WINDOWS\MsPrint32D.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=cmdbcs&lt;br /&gt;Data=C:\WINDOWS\cmdbcs.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=LotusHlp&lt;br /&gt;Data=C:\WINDOWS\LotusHlp.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=NVDispDrv&lt;br /&gt;Data=C:\WINDOWS\NVDispDRV.EXE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=AVPSrv&lt;br /&gt;Data=C:\WINDOWS\AVPSrv.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=DbgHlp32&lt;br /&gt;Data=C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=KVP&lt;br /&gt;Data =C:\WINDOWS\system32\drivers\svchost.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysM&lt;br /&gt;Data=C:\WINDOWS\124327M.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysW&lt;br /&gt;Data=C:\WINDOWS\124327L.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=&lt;br /&gt;Data=C:\Program Files\Common Files\Services\svchost.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=PTSShell&lt;br /&gt;Data=C:\WINDOWS\PTSShell.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=Kvsc3&lt;br /&gt;Data=C:\WINDOWS\Kvsc3.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=SHAProc&lt;br /&gt;Data=C:\WINDOWS\SHAProc.exe&lt;br /&gt;&lt;br /&gt;HKCU\Software\Microsoft\Internet Explorer\Main&lt;br /&gt;Value=Start Page&lt;br /&gt;Data=http://ww.94ak.com&lt;br /&gt;&lt;br /&gt;HKU\S-1-5-21-515967899-583907252-839522115-500\Software\Microsoft\Internet Explorer\Main&lt;br /&gt;Value=Start Page&lt;br /&gt;Data=http://ww.94ak.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/1/14 @ 18:13)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;稍後更新...&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-349488592689433412?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/349488592689433412/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=349488592689433412' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/349488592689433412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/349488592689433412'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/blog-post.html' title='台北市公寓大廈暨社區服務協會網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_JNaO8YWc9rQ/R4swh9FbssI/AAAAAAAAA-M/8d01GTTJ2Es/s72-c/tbca_org_home_20080107.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-6960969511967268843</id><published>2008-01-04T15:31:00.000+08:00</published><updated>2008-01-04T15:50:50.015+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='即時通訊'/><title type='text'>MSN病毒(Photos1-2008.zip)祝您新年快樂</title><content type='html'>新一波的MSN病毒又開始到處流竄，最近各位的MSN可能會收到名為 Photos1-2008.zip、PrivatePhoto2008.zip 或 Dc6.zip 的檔案，壓縮檔中包含一個名為 photo151.JPEG_www.HappyNewYear.com 或 Image78145-2008.jpg_www.MsnMessenger.scr 的檔案，請各位千萬不要執行此檔案，否則，後果自行負責囉！&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;第一種行為：&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\happy2008.exe&lt;br /&gt;C:\WINDOWS\svchost.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\svchost.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\RECYCLER\S-1-5-21-515967899-583907252-839522115-500\Dc6.zip&lt;br /&gt;C:\setup.exe&lt;br /&gt;C:\WINDOWS\happy2008.exe&lt;br /&gt;C:\WINDOWS\Photos1-2008.zip&lt;br /&gt;C:\WINDOWS\PrivatePhoto2008.zip&lt;br /&gt;C:\WINDOWS\svchost.exe&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=Windows svchost&lt;br /&gt;Data=svchost.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;第二種行為：&lt;/span&gt;&lt;br /&gt;[Added process]&lt;br /&gt;C:\WINDOWS\svchost.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\svchost.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\RECYCLER\S-1-5-21-515967899-583907252-839522115-500\Dc6.zip&lt;br /&gt;C:\WINDOWS\PrivatePhoto2008.zip&lt;br /&gt;C:\WINDOWS\svchost.exe&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=Windows svchost&lt;br /&gt;Data=svchost.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2008/1/4 @ 15:03)，下面的防毒軟體可以偵測到這些惡意檔案 &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;(僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Dc6.zip/photo151.JPEG_www.HappyNewYear.com:&lt;br /&gt;[ Trend ], "WORM_IRCBOT.EL"&lt;br /&gt;happy2008.exe:&lt;br /&gt;[ Trend ], "WORM_IRCBOT.EL"&lt;br /&gt;Photos1-2008.zip/photo151.JPEG_www.HappyNewYear.com:&lt;br /&gt;[ Trend ], "WORM_IRCBOT.EL"&lt;br /&gt;PrivatePhoto2008.zip/Image78145-2008.jpg_www.MsnMessenger.scr:&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Rising       ], "Backdoor.Win32.PBot.b"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;setup.exe:&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Rising       ], "Backdoor.Win32.PBot.b"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;svchost.exe:&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Rising       ], "Backdoor.Win32.PBot.b"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-6960969511967268843?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/6960969511967268843/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=6960969511967268843' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/6960969511967268843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/6960969511967268843'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2008/01/msnphotos1-2008zip.html' title='MSN病毒(Photos1-2008.zip)祝您新年快樂'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-1202827597643186913</id><published>2007-12-31T10:17:00.000+08:00</published><updated>2007-12-31T15:32:16.208+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>D-Link(友訊科技)網站被植入惡意連結</title><content type='html'>&lt;span style="color: rgb(255, 0, 0);"&gt;注意：最近此網站上有「星光幫演唱會來囉」的訊息，不曉得有多少網友因為這個訊息，瀏覽此網站而中獎勒！&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;D-Link(友訊科技)網站被植入惡意連結，此惡意程式為 TSPY_ONLINEG.ISZ/TSPY_GAMPASS.AK/TSPY_LEGMIR.CSF，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: 匿名網友)&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3hTa9FbsqI/AAAAAAAAA98/W24HPtkKL-E/s1600-h/dlinktw_home_20071231.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3hTa9FbsqI/AAAAAAAAA98/W24HPtkKL-E/s320/dlinktw_home_20071231.png" alt="" id="BLOGGER_PHOTO_ID_5149957896437215906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3hTm9FbsrI/AAAAAAAAA-E/6aQCE1qcfZ4/s1600-h/dlinktw_malurls_20071231.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3hTm9FbsrI/AAAAAAAAA-E/6aQCE1qcfZ4/s320/dlinktw_malurls_20071231.png" alt="" id="BLOGGER_PHOTO_ID_5149958102595646130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;此惡意程式有一部分是利用RealPlayer的安全漏洞，詳細資訊，請參考&lt;span style="font-size:100%;"&gt;&lt;/span&gt; &lt;a href="http://secunia.com/cve_reference/CVE-2007-5601/"&gt;CVE-2007-5601&lt;/a&gt;。&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\system32\wszjdax.exe&lt;br /&gt;C:\WINDOWS\system32\wsmseax.exe&lt;br /&gt;C:\WINDOWS\system32\gjfhazc.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxlis.exe&lt;br /&gt;C:\WINDOWS\system32\gjtmazc.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxslis.exe&lt;br /&gt;C:\WINDOWS\system32\avwlhst.exe&lt;br /&gt;C:\WINDOWS\system32\avwghst.exe&lt;br /&gt;C:\WINDOWS\system32\avzxlst.exe&lt;br /&gt;C:\WINDOWS\system32\kafykaz.exe&lt;br /&gt;C:\WINDOWS\system32\kapjgaz.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\136741MM.DLL&lt;br /&gt;C:\WINDOWS\system32\AVPSrv.dll&lt;br /&gt;C:\WINDOWS\system32\avwghmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwlhmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxlmn.dll&lt;br /&gt;C:\WINDOWS\system32\cmdbcs.dll&lt;br /&gt;C:\WINDOWS\system32\gjfhayc.dll&lt;br /&gt;C:\WINDOWS\system32\gjtmayc.dll&lt;br /&gt;C:\WINDOWS\system32\kafykzy.dll&lt;br /&gt;C:\WINDOWS\system32\kapjgzy.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxlma.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxslma.dll&lt;br /&gt;C:\WINDOWS\system32\Kvsc3.dll&lt;br /&gt;C:\WINDOWS\system32\LotusHlp.dll&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\MsIMMs32.dll&lt;br /&gt;C:\WINDOWS\system32\MsPrint32D.dll&lt;br /&gt;C:\WINDOWS\system32\PTSShell.dll&lt;br /&gt;C:\WINDOWS\system32\SSLDyn.dll&lt;br /&gt;C:\WINDOWS\system32\upxdnd.dll&lt;br /&gt;C:\WINDOWS\system32\wsmsezx.dll&lt;br /&gt;C:\WINDOWS\system32\wszjdzx.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: PciHardDisk&lt;br /&gt;DISPLAY: PciHardDisk&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\fat32.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYLOADER.EXE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MSDEG32.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\111[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\13[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\18[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\22[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\3[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\5[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\r[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\10[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1299644[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\16[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\20[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\24[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\4[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\7[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\Cip[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\dy[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\rl[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\11[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\14[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\19[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\23[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\6[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\9[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\new232[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\stat[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\014[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\0[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\11[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\17[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\21[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\25[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\8[1].exe&lt;br /&gt;C:\WINDOWS\136741L.exe&lt;br /&gt;C:\WINDOWS\136741M.exe&lt;br /&gt;C:\WINDOWS\136741MM.DLL&lt;br /&gt;C:\WINDOWS\136741WL.DLL&lt;br /&gt;C:\WINDOWS\AVPSrv.exE&lt;br /&gt;C:\WINDOWS\cmdbcs.exe&lt;br /&gt;C:\WINDOWS\Fonts\ardaase.fon&lt;br /&gt;C:\WINDOWS\Fonts\ardasbse.fon&lt;br /&gt;C:\WINDOWS\Fonts\avwghinb.dll&lt;br /&gt;C:\WINDOWS\Fonts\avwlhinb.dll&lt;br /&gt;C:\WINDOWS\Fonts\avzxlin.dll&lt;br /&gt;C:\WINDOWS\Fonts\enfeafx.fon&lt;br /&gt;C:\WINDOWS\Fonts\enpobfx.fon&lt;br /&gt;C:\WINDOWS\Fonts\gjfeaxw.fon&lt;br /&gt;C:\WINDOWS\Fonts\gjfhass.dll&lt;br /&gt;C:\WINDOWS\Fonts\gjtmass.dll&lt;br /&gt;C:\WINDOWS\Fonts\gjtoaxw.fon&lt;br /&gt;C:\WINDOWS\Fonts\kafykcsb.dll&lt;br /&gt;C:\WINDOWS\Fonts\kapjgcsb.dll&lt;br /&gt;C:\WINDOWS\Fonts\kvdxlcfb.dll&lt;br /&gt;C:\WINDOWS\Fonts\kvdxslcfb.dll&lt;br /&gt;C:\WINDOWS\Fonts\msguasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mswuasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mszhasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\wsmsecjb.dll&lt;br /&gt;C:\WINDOWS\Fonts\wszjdcj.dll&lt;br /&gt;C:\WINDOWS\Fonts\wymoafz.fon&lt;br /&gt;C:\WINDOWS\Fonts\wyzuafz.fon&lt;br /&gt;C:\WINDOWS\Kvsc3.exE&lt;br /&gt;C:\WINDOWS\LotusHlp.exe&lt;br /&gt;C:\WINDOWS\MsIMMs32.exE&lt;br /&gt;C:\WINDOWS\MsPrint32D.exe&lt;br /&gt;C:\WINDOWS\PTSShell.exe&lt;br /&gt;C:\WINDOWS\SSLDyn.exE&lt;br /&gt;C:\WINDOWS\system32\AVPSrv.dll&lt;br /&gt;C:\WINDOWS\system32\avwghmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwghst.exe&lt;br /&gt;C:\WINDOWS\system32\avwlhmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwlhst.exe&lt;br /&gt;C:\WINDOWS\system32\avzxlmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxlst.exe&lt;br /&gt;C:\WINDOWS\system32\cmdbcs.dll&lt;br /&gt;C:\WINDOWS\system32\config\sysEventw.cfg&lt;br /&gt;C:\WINDOWS\system32\gjfhayc.dll&lt;br /&gt;C:\WINDOWS\system32\gjfhazc.exe&lt;br /&gt;C:\WINDOWS\system32\gjtmayc.dll&lt;br /&gt;C:\WINDOWS\system32\gjtmazc.exe&lt;br /&gt;C:\WINDOWS\system32\kafykaz.exe&lt;br /&gt;C:\WINDOWS\system32\kafykzy.dll&lt;br /&gt;C:\WINDOWS\system32\kapjgaz.exe&lt;br /&gt;C:\WINDOWS\system32\kapjgzy.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxlis.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxlma.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxslis.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxslma.dll&lt;br /&gt;C:\WINDOWS\system32\Kvsc3.dll&lt;br /&gt;C:\WINDOWS\system32\LotusHlp.dll&lt;br /&gt;C:\WINDOWS\system32\LYLOADER.EXE&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\MSDEG32.DLL&lt;br /&gt;C:\WINDOWS\system32\MsIMMs32.dll&lt;br /&gt;C:\WINDOWS\system32\MsPrint32D.dll&lt;br /&gt;C:\WINDOWS\system32\PTSShell.dll&lt;br /&gt;C:\WINDOWS\system32\REGKEY.hiv&lt;br /&gt;C:\WINDOWS\system32\SSLDyn.dll&lt;br /&gt;C:\WINDOWS\system32\upxdnd.dll&lt;br /&gt;C:\WINDOWS\system32\wsmseax.exe&lt;br /&gt;C:\WINDOWS\system32\wsmsezx.dll&lt;br /&gt;C:\WINDOWS\system32\wszjdax.exe&lt;br /&gt;C:\WINDOWS\system32\wszjdzx.dll&lt;br /&gt;C:\WINDOWS\system32\wxptdi.sys&lt;br /&gt;C:\WINDOWS\upxdnd.exe&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{1C098A56-F90F-A789-901F-8906546720C1}-C:\WINDOWS\system32\gjtmayc.dll&lt;br /&gt;{1D908534-AD45-920F-AC89-4024FA9D26D1}-C:\WINDOWS\system32\gjfhayc.dll&lt;br /&gt;{45679330-4034-9021-7012-909856721374}-C:\WINDOWS\system32\wszjdzx.dll&lt;br /&gt;{792FADFA-BCDE-ACDF-CDEF-21054865CBA7}-C:\WINDOWS\system32\wsmsezx.dll&lt;br /&gt;{7A321487-4977-D98A-C8D5-6488257545A7}-C:\WINDOWS\system32\kapjgzy.dll&lt;br /&gt;{8960356A-458E-DE24-BD50-268F589A56A8}-C:\WINDOWS\system32\avwlhmn.dll&lt;br /&gt;{8A1247C1-53DA-FF43-ABD3-345F323A48D8}-C:\WINDOWS\system32\avwghmn.dll&lt;br /&gt;{BB681598-AD5F-BC8C-77DC-748FAC8D3FBB}-C:\WINDOWS\system32\kafykzy.dll&lt;br /&gt;{C859245F-345D-BC13-AC4F-145D47DA34FC}-C:\WINDOWS\system32\avzxlmn.dll&lt;br /&gt;{CC87A354-ABC3-DEDE-FF33-3213FD7447CC}-C:\WINDOWS\system32\kvdxlma.dll&lt;br /&gt;{CD561258-45F3-A451-F908-A258458226DC}-C:\WINDOWS\system32\kvdxslma.dll&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=SSLDyn&lt;br /&gt;Data=C:\WINDOWS\SSLDyn.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=upxdnd&lt;br /&gt;Data=C:\WINDOWS\upxdnd.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=AVPSrv&lt;br /&gt;Data=C:\WINDOWS\AVPSrv.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=cmdbcs&lt;br /&gt;Data=C:\WINDOWS\cmdbcs.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysM&lt;br /&gt;Data=C:\WINDOWS\136741M.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysW&lt;br /&gt;Data=C:\WINDOWS\136741L.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=Kvsc3&lt;br /&gt;Data=C:\WINDOWS\Kvsc3.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=MsPrint32D&lt;br /&gt;Data=C:\WINDOWS\MsPrint32D.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=PTSShell&lt;br /&gt;Data=C:\WINDOWS\PTSShell.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=LotusHlp&lt;br /&gt;Data=C:\WINDOWS\LotusHlp.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=MsIMMs32&lt;br /&gt;Data=C:\WINDOWS\MsIMMs32.exE&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/12/31 @ 10:39)，下面的防毒軟體可以偵測到這些惡&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;稍後更新...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-1202827597643186913?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/1202827597643186913/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=1202827597643186913' title='2 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1202827597643186913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1202827597643186913'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/12/d-link.html' title='D-Link(友訊科技)網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3hTa9FbsqI/AAAAAAAAA98/W24HPtkKL-E/s72-c/dlinktw_home_20071231.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-5519526463851289065</id><published>2007-12-28T10:25:00.000+08:00</published><updated>2007-12-28T10:43:11.962+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='垃圾郵件'/><title type='text'>風暴蠕蟲新變種報到</title><content type='html'>不到一天的時間，風暴蠕蟲的作者又改變惡意檔案下載網域名稱，繼續散播新變種的風暴蠕蟲，請各位小心。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3Rgc9FbsoI/AAAAAAAAA9s/_2PQzdoztw8/s1600-h/newyearcards2008_20071228.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3Rgc9FbsoI/AAAAAAAAA9s/_2PQzdoztw8/s320/newyearcards2008_20071228.png" alt="" id="BLOGGER_PHOTO_ID_5148846324541272706" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;郵件名稱 (Subject) 有下面幾種：&lt;br /&gt;&lt;br /&gt;A fresh new year&lt;br /&gt;As the new year...&lt;br /&gt;As you embrace another new year&lt;br /&gt;Blasting new year&lt;br /&gt;Happy 2008!&lt;br /&gt;Happy New Year!&lt;br /&gt;It's the new Year&lt;br /&gt;Joyous new year&lt;br /&gt;New Hope and New Beginnings&lt;br /&gt;New Year Ecard&lt;br /&gt;New Year Postcard&lt;br /&gt;Opportunities for the new year&lt;br /&gt;Wishes for the new year&lt;br /&gt;Happy New Year to You!&lt;br /&gt;Happy New Year to &lt;email&gt;&lt;br /&gt;Lots of greetings on the new year&lt;br /&gt;New Year wishes for You&lt;br /&gt;Dance to the New 2008 Year tune&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為 (具有隱匿行為)：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added service]&lt;br /&gt;NAME: bldy1b60-7eb3&lt;br /&gt;DISPLAY: bldy1b60-7eb3&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\bldy1b60-7eb3.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Desktop\happy-2008.exe&lt;br /&gt;C:\WINDOWS\system32\bldy1b60-7eb3.sys&lt;br /&gt;C:\WINDOWS\system32\bldy_sys.config&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/12/27 @ 22:02)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;bldy_sys.config:&lt;br /&gt; [     Microsoft    ], "Backdoor:Win32/Nuwar.B!ini"&lt;br /&gt;happy-2008.exe:&lt;br /&gt; [     Symantec     ], "Trojan.Peacomm"&lt;br /&gt; [     McAfee       ], "W32/Nuwar@MM"&lt;br /&gt; [     McAfee_Beta  ], "W32/Nuwar@MM"&lt;br /&gt; [     Sophos       ], "Mal/Dorf-H"&lt;br /&gt; [     Panda_Beta   ], "W32/Nuwar.MS.worm"&lt;br /&gt; [     Nod32        ], "Win32/Nuwar.BA worm"&lt;br /&gt; [     Fortinet     ], "W32/Tibs.G@mm"&lt;br /&gt; [     HBEDV        ], "TR/Crypt.XDR.Gen"&lt;br /&gt; [     Authentium   ], "W32/Dropper.gen6"&lt;br /&gt; [     WebWasher    ], "Trojan.Crypt.XDR.Gen"&lt;br /&gt;bldy1b60-7eb3.sys:&lt;br /&gt; [     Microsoft    ], "Backdoor:WinNT/Nuwar.B!sys"&lt;br /&gt; [     McAfee       ], "Downloader-BAI.sys.gen.a"&lt;br /&gt; [     McAfee_Beta  ], "Downloader-BAI.sys.gen.a"&lt;br /&gt; [     CAV          ], "Win32/Sintun!generic"&lt;br /&gt; [     Nod32        ], "Win32/Nuwar.BA worm"&lt;br /&gt; [     HBEDV        ], "TR/Rootkit.Gen"&lt;br /&gt; [     quickheal    ], "Backdoor.Agent.dln"&lt;br /&gt; [     WebWasher    ], "Trojan.Rootkit.Gen"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-5519526463851289065?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/5519526463851289065/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=5519526463851289065' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5519526463851289065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5519526463851289065'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/12/blog-post_28.html' title='風暴蠕蟲新變種報到'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R3Rgc9FbsoI/AAAAAAAAA9s/_2PQzdoztw8/s72-c/newyearcards2008_20071228.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2743794392439394981</id><published>2007-12-26T15:42:00.000+08:00</published><updated>2007-12-26T16:11:02.139+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='垃圾郵件'/><title type='text'>新年快樂病毒報到</title><content type='html'>最近信箱收到一些垃圾郵件是有關新年快樂的訊息，但此信件中包含可下載風暴蠕蟲 (Storm Worm) 的連結，下載檔案名稱為 &lt;span style="font-weight: bold;"&gt;happy-2008.exe&lt;/span&gt;，可見此病毒的作者又開始利用「放年假的心態」，以散播新變種的風暴蠕蟲，請各位小心囉。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R3IMhtFbsnI/AAAAAAAAA9k/NlG8irXeHeE/s1600-h/newyearvirus_home_20071226.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R3IMhtFbsnI/AAAAAAAAA9k/NlG8irXeHeE/s320/newyearvirus_home_20071226.png" alt="" id="BLOGGER_PHOTO_ID_5148191097215496818" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為 (具有隱匿行為)：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added service]&lt;br /&gt;NAME: init_1c52-26ff&lt;br /&gt;DISPLAY: init_1c52-26ff&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\init_1c52-26ff.sys (random file name)&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\happy-2008[1].exe&lt;br /&gt;C:\WINDOWS\system32\init_1c52-26ff.sys&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/12/26 @ 14:41)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;init_1c52-26ff.sys:&lt;br /&gt;[     Microsoft    ], "Backdoor:WinNT/Nuwar.B!sys"&lt;br /&gt;[     McAfee       ], "Downloader-BAI.sys.gen.a"&lt;br /&gt;[     McAfee_Beta  ], "Downloader-BAI.sys.gen.a"&lt;br /&gt;[     Alwil        ], "Win32:Zhelatin-ASX [Wrm]"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/Fuclip trojan"&lt;br /&gt;[     HBEDV        ], "TR/Rootkit.Gen"&lt;br /&gt;[     Ikarus       ], "Backdoor.Win32.Agent.amd"&lt;br /&gt;[     WebWasher    ], "Trojan.Rootkit.Gen"&lt;br /&gt;init_sys_config:&lt;br /&gt;[     Microsoft    ], "Backdoor:Win32/Nuwar.B!ini"&lt;br /&gt;[     Sophos       ], "Troj/Dorfin-Fam"&lt;br /&gt;happy-2008[1].exe:&lt;br /&gt;[     Microsoft    ], "Backdoor:WinNT/Nuwar.B!sys"&lt;br /&gt;[     McAfee       ], "W32/Nuwar@MM"&lt;br /&gt;[     McAfee_Beta  ], "W32/Nuwar@MM"&lt;br /&gt;[     Alwil        ], "Win32:Zhelatin-ASX [Wrm]"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/Fuclip trojan"&lt;br /&gt;[     HBEDV        ], "TR/Rootkit.Gen"&lt;br /&gt;[     Authentium   ], "W32/StormWorm.Q"&lt;br /&gt;[     WebWasher    ], "Trojan.Rootkit.Gen"&lt;br /&gt;[     bitdefender  ], "DeepScan:Generic.Malware.FMH@mmign.893777D0"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2743794392439394981?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2743794392439394981/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2743794392439394981' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2743794392439394981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2743794392439394981'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/12/blog-post_9976.html' title='新年快樂病毒報到'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_JNaO8YWc9rQ/R3IMhtFbsnI/AAAAAAAAA9k/NlG8irXeHeE/s72-c/newyearvirus_home_20071226.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-6401000515260554168</id><published>2007-12-26T13:14:00.000+08:00</published><updated>2007-12-26T13:25:32.342+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='即時通訊'/><title type='text'>聖誕節MSN病毒</title><content type='html'>昨天收到從一個朋友的MSN傳送過來的一個樣本，名為「christmas-2007.zip」，壓縮檔中包含一個名為 「img2007-12.JPEG.scr」的檔案，分析後，它具有惡意行為，請各位小心囉。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\servidevice.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\WINDOWS\Chirstmas-2007.zip&lt;br /&gt;C:\WINDOWS\servidevice.exe&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=ryan1918&lt;br /&gt;Data=servidevice.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/12/25 @ 13:58)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Chirstmas-2007.zip/img2007-12.JPEG.scr:&lt;br /&gt; [     Nod32        ], "Win32/IRCBot.ABP trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Rising       ], "Backdoor.Win32.PBot.b"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Banload.ams"&lt;br /&gt; [     Authentium   ], "W32/Document-disguised-based!Maximus"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;servidevice.exe:&lt;br /&gt; [     Nod32        ], "Win32/IRCBot.ABP trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Rising       ], "Backdoor.Win32.PBot.b"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Banload.ams"&lt;br /&gt; [     Authentium   ], "W32/Document-disguised-based!Maximus"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-6401000515260554168?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/6401000515260554168/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=6401000515260554168' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/6401000515260554168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/6401000515260554168'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/12/msn.html' title='聖誕節MSN病毒'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-4716233685736356176</id><published>2007-12-26T10:25:00.000+08:00</published><updated>2007-12-26T10:54:09.554+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>北軟股份有限公司網站被植入惡意連結</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：此惡意連結已經存在該公司網頁很多天了，都不見他們處理，想必有很多人中獎。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;北軟股份有限公司網站被植入惡意連結，此惡意程式為 TROJ_SMALL.DXW，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: 匿名網友)&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R3G8k9FbslI/AAAAAAAAA9U/GeLYST8XqXw/s1600-h/goldensoft_home_20071226.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R3G8k9FbslI/AAAAAAAAA9U/GeLYST8XqXw/s320/goldensoft_home_20071226.png" alt="" id="BLOGGER_PHOTO_ID_5148103192119849554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面也有，可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R3G8wNFbsmI/AAAAAAAAA9c/UeeyBCiE4z4/s1600-h/goldensoft_malurl_20071226.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R3G8wNFbsmI/AAAAAAAAA9c/UeeyBCiE4z4/s320/goldensoft_malurl_20071226.png" alt="" id="BLOGGER_PHOTO_ID_5148103385393377890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;此惡意程式是利用RealPlayer的安全漏洞，詳細資訊，請參考&lt;span style="font-size:100%;"&gt;&lt;/span&gt; &lt;a href="http://secunia.com/cve_reference/CVE-2007-5601/"&gt;CVE-2007-5601&lt;/a&gt;。&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/12/24 @ 16:24)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;6.gif:&lt;br /&gt;[ Trend ], "JS_REALPLAY.J"&lt;br /&gt;ads.jpg.exe:&lt;br /&gt;[ Trend ], "TROJ_SMALL.DXW"&lt;br /&gt;web.exe:&lt;br /&gt;[ Trend ], "TROJ_ALMANAHE.AC"&lt;br /&gt;1.gif:&lt;br /&gt;[ Trend ], "JS_AGENT.AEVS"&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-4716233685736356176?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/4716233685736356176/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=4716233685736356176' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4716233685736356176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4716233685736356176'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/12/blog-post_26.html' title='北軟股份有限公司網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_JNaO8YWc9rQ/R3G8k9FbslI/AAAAAAAAA9U/GeLYST8XqXw/s72-c/goldensoft_home_20071226.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-4274178450631022321</id><published>2007-12-12T17:33:00.000+08:00</published><updated>2007-12-12T18:02:34.591+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>高雄市觀光協會網站被植入惡意連結</title><content type='html'>高雄市觀光協會網站被植入惡意連結，此惡意程式為 PWS:Win32/Gamania.gen!B，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R1-wmj20UzI/AAAAAAAAA9E/3PVpUkqqX6A/s1600-h/khhta_home_20071212.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R1-wmj20UzI/AAAAAAAAA9E/3PVpUkqqX6A/s320/khhta_home_20071212.png" alt="" id="BLOGGER_PHOTO_ID_5143023475987075890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁和 index-down.asp (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R1-wwz20U0I/AAAAAAAAA9M/JDLmrVfCbhg/s1600-h/khhta_malurl_20071212.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R1-wwz20U0I/AAAAAAAAA9M/JDLmrVfCbhg/s320/khhta_malurl_20071212.png" alt="" id="BLOGGER_PHOTO_ID_5143023652080735042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\Help\9712499B91DB.DLL&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\autorun.inf&lt;br /&gt;C:\Documents and Settings\Administrator\Desktop\2.bat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\~s.bat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\m[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\gmsex[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\h[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\stat[1].htm&lt;br /&gt;C:\shell.exe&lt;br /&gt;C:\WINDOWS\Help\9712499B91DB.DLL&lt;br /&gt;C:\WINDOWS\Help\9712499B91DB.EXE&lt;br /&gt;C:\WINDOWS\Help\autorun.inf&lt;br /&gt;&lt;br /&gt;[ Added COM/BHO ]&lt;br /&gt;{6B12A5F5-CABF-41EE-B8B3-EC5D2AAFF132}-C:\WINDOWS\HELP\9712499B91DB.DLL&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/12/12 @ 16:04)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;9712499B91DB.DLL:&lt;br /&gt;[ Trend ], "Possible_Infostl"&lt;br /&gt;9712499B91DB.EXE:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Mlwr-13"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Gamania.gen!B"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/LineDLL-B, [FILE:0001]:Mal/LineDLL-B, Mal/EncPk-AP"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     HBEDV        ], "DR/Delphi.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/Malware"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Delphi.Gen"&lt;br /&gt;autorun.inf:&lt;br /&gt; [     Beta_Gen     ], "Possible_Otorun1"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.OnlineGames.NIT"&lt;br /&gt; [     bitdefender  ], "Trojan.PWS.OnLineGames.NIT"&lt;br /&gt;gmsex[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Mlwr-13"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Gamania.gen!B"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/LineDLL-B, [FILE:0001]:Mal/LineDLL-B, Mal/EncPk-AP"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     HBEDV        ], "DR/Delphi.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/Malware"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Delphi.Gen"&lt;br /&gt;h[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Sophos       ], "Mal/Iframe-A"&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Norman       ], "Trojan HTML/Exploit!IFrame.G"&lt;br /&gt;m[1].htm:&lt;br /&gt; [     McAfee       ], "Exploit-ObscuredHtml"&lt;br /&gt; [     McAfee_Beta  ], "Exploit-ObscuredHtml"&lt;br /&gt; [     HBEDV        ], "HTML/ADODB.Exploit.Gen"&lt;br /&gt; [     Grisoft      ], "Virus found JS/Downloader.Agent"&lt;br /&gt; [     WebWasher    ], "Script.ADODB.Exploit.Gen"&lt;br /&gt;shell.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Mlwr-13"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Gamania.gen!B"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/LineDLL-B, [FILE:0001]:Mal/LineDLL-B, Mal/EncPk-AP"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     HBEDV        ], "DR/Delphi.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/Malware"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Delphi.Gen"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-4274178450631022321?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/4274178450631022321/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=4274178450631022321' title='2 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4274178450631022321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4274178450631022321'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/12/blog-post_12.html' title='高雄市觀光協會網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_JNaO8YWc9rQ/R1-wmj20UzI/AAAAAAAAA9E/3PVpUkqqX6A/s72-c/khhta_home_20071212.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-496618001784370701</id><published>2007-12-12T16:23:00.000+08:00</published><updated>2007-12-12T16:35:35.535+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>台安醫院網站又被植入惡意連結</title><content type='html'>&lt;span style="color: rgb(255, 0, 0);"&gt;注意：此網站被植入惡意連結的時間已經很久了，都不見他們有改善的情形，如果各位還上此網站的話，後果自行負責。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;台安醫院網站又被植入惡意連結，此惡意程式為 Trojan W32/Lineage.AYTD，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R1-bhD20UxI/AAAAAAAAA80/_A2OAsrrBPk/s1600-h/embo_home_20071212.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R1-bhD20UxI/AAAAAAAAA80/_A2OAsrrBPk/s320/embo_home_20071212.png" alt="" id="BLOGGER_PHOTO_ID_5143000291753612050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R1-b3j20UyI/AAAAAAAAA88/ZbF-oOdNTdk/s1600-h/embo_malurl_20071212.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R1-b3j20UyI/AAAAAAAAA88/ZbF-oOdNTdk/s320/embo_malurl_20071212.png" alt="" id="BLOGGER_PHOTO_ID_5143000678300668706" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\Web\printers\images\ndmai.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\717[1].c&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\h[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\614003[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\614woai[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\717003[1].htm&lt;br /&gt;C:\microsofts.vbs&lt;br /&gt;C:\NTDETECT.EXE&lt;br /&gt;C:\WINDOWS\Web\printers\images\ndmai.dll&lt;br /&gt;C:\WINDOWS\Web\printers\images\ndmai.exe&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{7152C68A-D93C-49BF-AFEF-6B4576849A7E}-C:\WINDOWS\Web\printers\images\ndmai.dll&lt;br /&gt;    &lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/12/12 @ 12:38)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;717[1].c:&lt;br /&gt;[ Trend ], "EXPL_ANICMOO.GEN"&lt;br /&gt;ndmai.dll:&lt;br /&gt;[ Trend ], "Possible_Infostl"&lt;br /&gt;ndmai.dll:&lt;br /&gt;[ Trend ], "Possible_Infostl"&lt;br /&gt;614woai[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Mlwr-13"&lt;br /&gt; [     Symantec     ], "Infostealer.Lineage"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/LineDLL-B, Mal/EncPk-AP"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.Lineage.ACN trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.Lineage.UZH"&lt;br /&gt; [     Norman       ], "Trojan W32/Lineage.AYTD"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Lineage.AFS"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.Lineage.UZH"&lt;br /&gt;614003[1].htm:&lt;br /&gt; [     McAfee       ], "Exploit-ObscuredHtml"&lt;br /&gt; [     McAfee_Beta  ], "Exploit-ObscuredHtml"&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Grisoft      ], "Virus found JS/Downloader.Agent"&lt;br /&gt;h[1].htm:&lt;br /&gt; [     McAfee       ], "ObfuscatedHtml"&lt;br /&gt; [     McAfee_Beta  ], "ObfuscatedHtml"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;microsofts.vbs:&lt;br /&gt; [     Microsoft    ], "[-&gt;(UTF-16LE)]:Virus:VBS/VBSWGbased.gen"&lt;br /&gt;ndmai.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Mlwr-13"&lt;br /&gt; [     Symantec     ], "Infostealer.Lineage"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/LineDLL-B, Mal/EncPk-AP"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.Lineage.ACN trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.Lineage.UZH"&lt;br /&gt; [     Norman       ], "Trojan W32/Lineage.AYTD"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Lineage.AFS"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.Lineage.UZH"&lt;br /&gt;NTDETECT.EXE:&lt;br /&gt; [     Microsoft    ], "[-&gt;(UTF-16LE)]:Virus:VBS/VBSWGbased.gen"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-496618001784370701?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/496618001784370701/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=496618001784370701' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/496618001784370701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/496618001784370701'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/12/blog-post.html' title='台安醫院網站又被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_JNaO8YWc9rQ/R1-bhD20UxI/AAAAAAAAA80/_A2OAsrrBPk/s72-c/embo_home_20071212.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-5356957932065450552</id><published>2007-11-30T11:06:00.000+08:00</published><updated>2007-11-30T11:57:10.844+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>新竹市文化局網站被植入惡意連結</title><content type='html'>新竹市文化局網站被植入惡意連結，此惡意程式為 Backdoor:Win32/PcClient，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: 匿名網友)&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R09-8tR4FII/AAAAAAAAA8k/6CnspdkbwBk/s1600-R/hcccb_gov_home_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R09-8tR4FII/AAAAAAAAA8k/hyTRlW6hGnI/s320/hcccb_gov_home_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138465281264850050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R09_QNR4FJI/AAAAAAAAA8s/E2KVLhnZ2bs/s1600-R/hcccb_gov_malurl_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R09_QNR4FJI/AAAAAAAAA8s/8vS3l7vf81c/s320/hcccb_gov_malurl_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138465616272299154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\system32\ncepjn.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: ymutexfy&lt;br /&gt;DISPLAY: ymutexfy&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\ncepjn.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\g913995[1]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\mainpic02[1].jpg&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\cpro8[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\go[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ma[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\tengrui8[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1449166[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\14[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\8[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\hcccb.gov[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\huohu[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1026[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\cpro1[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\g913995[1].htm&lt;br /&gt;C:\WINDOWS\system32\000462c8.inf&lt;br /&gt;C:\WINDOWS\system32\drivers\ncepjn.sys&lt;br /&gt;C:\WINDOWS\system32\ncepjn.dll&lt;br /&gt;C:\wwwcuteqqcn.pif&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/29 @ 16:01)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;14[1].htm:&lt;br /&gt;[     McAfee       ], "[00000060.js]:Obfuscated Script.d !!"&lt;br /&gt;[     McAfee_Beta  ], "[00000060.js]:Obfuscated Script.d !!"&lt;br /&gt;[     HBEDV        ], "JS/Dldr.Agent.afg"&lt;br /&gt;[     Rising       ], "Trojan.DL.Script.JS.Agent.lrx"&lt;br /&gt;[     Grisoft      ], "Virus found Downloader.Small"&lt;br /&gt;[     Authentium   ], "JS/IFrameBoF.H"&lt;br /&gt;[     WebWasher    ], "Script.Dldr.Agent.afg"&lt;br /&gt;ncepjn.sys:&lt;br /&gt;[     HBEDV        ], "HEUR/Damaged"&lt;br /&gt;[     Grisoft      ], "Virus identified Obfustat.VXS"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ncepjn.dll:&lt;br /&gt;[     Microsoft    ], "Backdoor:Win32/PcClient"&lt;br /&gt;[     Alwil        ], "Win32:Agent-MDR [Trj]"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "HEUR/Malware"&lt;br /&gt;[     Ikarus       ], "Backdoor.Win32.PcClient.LH"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;wwwcuteqqcn.pif:&lt;br /&gt;[     Alwil        ], "Win32:Agent-EPC [Trj]"&lt;br /&gt;[     Ikarus       ], "Backdoor.Win32.PcClient.yw"&lt;br /&gt;[     Grisoft      ], "Virus found BackDoor.PcClient"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;g913995[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;8[1].htm:&lt;br /&gt;[     eAladdin     ], "JS.Small.au (Non-Removable)"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;1026[1].exe:&lt;br /&gt;[     Alwil        ], "Win32:Agent-EPC [Trj]"&lt;br /&gt;[     Ikarus       ], "Backdoor.Win32.PcClient.yw"&lt;br /&gt;[     Grisoft      ], "Virus found BackDoor.PcClient"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;tengrui8[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt;[     Norman       ], "Security Risk HTML/Exploit!IFrame.A"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ma[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt;[     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt;[     Norman       ], "Security Risk HTML/Exploit!IFrame.A"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-5356957932065450552?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/5356957932065450552/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=5356957932065450552' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5356957932065450552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5356957932065450552'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_6007.html' title='新竹市文化局網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_JNaO8YWc9rQ/R09-8tR4FII/AAAAAAAAA8k/hyTRlW6hGnI/s72-c/hcccb_gov_home_20071130.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-1834212382327948518</id><published>2007-11-30T10:49:00.000+08:00</published><updated>2007-11-30T11:09:11.885+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>元照網路書店網站被植入惡意連結</title><content type='html'>元照網路書店網站被植入惡意連結，此惡意程式為 TROJ_HARNIG.CW，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: Jimau)&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R097D9R4FEI/AAAAAAAAA8E/TdQiubDsMWQ/s1600-R/angle_home_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R097D9R4FEI/AAAAAAAAA8E/a1X9o-EmiY4/s320/angle_home_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138461007772390466" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在 index.asp (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R097bNR4FFI/AAAAAAAAA8M/kbkMjSS1t4M/s1600-R/angle_malurl_encoded_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R097bNR4FFI/AAAAAAAAA8M/SMh6SsnRQgg/s320/angle_malurl_encoded_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138461407204349010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;解碼後為：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R097wtR4FHI/AAAAAAAAA8c/tHIBy_R784c/s1600-R/angle_malurl_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R097wtR4FHI/AAAAAAAAA8c/IUZuLULCvhA/s320/angle_malurl_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138461776571536498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\WINDOWS\system32\com\SMSS.EXE&lt;br /&gt;C:\WINDOWS\system32\com\LSASS.EXE&lt;br /&gt;C:\WINDOWS\system32\drivers\alg.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\system32\Com\LSASS.EXE&lt;br /&gt;C:\WINDOWS\system32\Com\netcfg.dll&lt;br /&gt;C:\WINDOWS\system32\Com\SMSS.EXE&lt;br /&gt;C:\WINDOWS\system32\dnsq.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\AUTORUN.INF&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tzgl.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\~s.bat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1378348[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\468[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\468[2].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\5[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\6[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\goto[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\HOOK[1].dll&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\100932[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1388306[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\4[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\a6[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\a9[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\dd[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\flash[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1492703[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a2[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a4[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\a5[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\count[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\head[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\r[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\Stop[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\3[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\a10[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\a11[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\a1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\a7[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\svchost[1].exe&lt;br /&gt;C:\pagefile.pif&lt;br /&gt;C:\WINDOWS\system32\000.cfg0&lt;br /&gt;C:\WINDOWS\system32\Com\LSASS.EXE&lt;br /&gt;C:\WINDOWS\system32\Com\netcfg.000&lt;br /&gt;C:\WINDOWS\system32\Com\netcfg.dll&lt;br /&gt;C:\WINDOWS\system32\Com\SMSS.EXE&lt;br /&gt;C:\WINDOWS\system32\dnsq.dll&lt;br /&gt;C:\WINDOWS\system32\dnsq.dll.log&lt;br /&gt;C:\WINDOWS\system32\drivers\alg.exe&lt;br /&gt;C:\WINDOWS\system32\drivers\alg.exe.log&lt;br /&gt;C:\WINDOWS\system32\drivers\npf.sys.log&lt;br /&gt;C:\WINDOWS\system32\ntfsus.exe&lt;br /&gt;C:\WINDOWS\system32\ntfsus.exe.log&lt;br /&gt;C:\WINDOWS\system32\packet.dll.log&lt;br /&gt;C:\WINDOWS\system32\pthreadVC.dll.log&lt;br /&gt;C:\WINDOWS\system32\wpcap.dll.log&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{450EC9C4-0F7F-407F-B084-D1147FE9DDCC}-C:\WINDOWS\system32\com\netcfg.dll&lt;br /&gt;{D9901239-34A2-448D-A000-3705544ECE9D}-C:\WINDOWS\system32\com\netcfg.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/29 @ 12:27)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;a4[1].htm:&lt;br /&gt;[ Trend ], "EXPL_EXECOD.A."&lt;br /&gt;a1[1].htm:&lt;br /&gt;[ Trend ], "VBS_PSYME.BCC"&lt;br /&gt;SMSS.EXE:&lt;br /&gt;[ Trend ], "TROJ_HARNIG.CW"&lt;br /&gt;a10[1].htm:&lt;br /&gt;[ Trend ], "HTML_SHELLCOD.AV"&lt;br /&gt;a6[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;a5[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;a2[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;TINTSETP.EXE:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ImScInst.exe:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;Stop[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Kaspersky    ], "PAK:FSG"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Trojan Harnig.gen1"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ntfsus.log:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Kaspersky    ], "PAK:FSG"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Trojan Harnig.gen1"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ntfsus.exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Kaspersky    ], "PAK:FSG"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Trojan Harnig.gen1"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;HOOK[1].dll:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;dnsq.log:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;dnsq.dll:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;wpcap.log:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;svchost[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Kaspersky    ], "PAK:FSG"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Security Risk Suspicious_F.gen"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;alg.exe.log:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Kaspersky    ], "PAK:FSG"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Security Risk Suspicious_F.gen"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;alg.exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Kaspersky    ], "PAK:FSG"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Security Risk Suspicious_F.gen"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;pthreadVC.log:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;packet.log:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;npf.sys.log:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;000.cfg0-pe&lt;br /&gt;[     Sophos       ], "[FILE:0001]:Mal/Packer"&lt;br /&gt;[     Ikarus       ], "Trojan.Win32.Agent.czg"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;netcfg.dll:&lt;br /&gt;[     Ikarus       ], "Trojan.Win32.Agent.czh"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;netcfg.000:&lt;br /&gt;[     Ikarus       ], "Trojan.Win32.Agent.czh"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;r[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;tzgl.exe:&lt;br /&gt;[     Sophos       ], "[FILE:0001]:Mal/Packer"&lt;br /&gt;[     Ikarus       ], "Trojan.Win32.Agent.czg"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;pagefile.pif:&lt;br /&gt;[     Sophos       ], "[FILE:0001]:Mal/Packer"&lt;br /&gt;[     Ikarus       ], "Trojan.Win32.Agent.czg"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;LSASS.exe:&lt;br /&gt;[     Sophos       ], "[FILE:0001]:Mal/Packer"&lt;br /&gt;[     Ikarus       ], "Trojan.Win32.Agent.czg"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;a11[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;a9[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Possible_Hifrm-3"&lt;br /&gt;[     Microsoft    ], "[-&gt;(SCRIPT0001)-&gt;(EmbeddedCode)]:Exploit:Win32/Senglot.A"&lt;br /&gt;[     McAfee       ], "JS/Exploit-BO.gen"&lt;br /&gt;[     McAfee_Beta  ], "JS/Exploit-BO.gen"&lt;br /&gt;[     Sophos       ], "Mal/JSShell-A"&lt;br /&gt;[     HBEDV        ], "HTML/Shellcode.Gen"&lt;br /&gt;[     Norman       ], "Trojan HTML/IFrameBof.A"&lt;br /&gt;[     Ikarus       ], "Exploit.HTML.IframeBof"&lt;br /&gt;[     WebWasher    ], "Script.Shellcode.Gen"&lt;br /&gt;a7[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-1834212382327948518?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/1834212382327948518/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=1834212382327948518' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1834212382327948518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/1834212382327948518'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_5307.html' title='元照網路書店網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R097D9R4FEI/AAAAAAAAA8E/a1X9o-EmiY4/s72-c/angle_home_20071130.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-5790045104895143065</id><published>2007-11-30T10:38:00.000+08:00</published><updated>2007-11-30T10:50:07.238+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='安全漏洞'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><category scheme='http://www.blogger.com/atom/ns#' term='網站遭駭'/><title type='text'>國立台灣師範大學國語教學中心網站遭駭且被植入惡意程式</title><content type='html'>國立台灣師範大學國語教學中心網站遭駭且被植入惡意程式，不過，&lt;span style="font-weight: bold;"&gt;此惡意程式已經無法下載&lt;/span&gt;。在這裡要注意的是這個網站有可能被植入惡意連結或惡意程式碼，所以，他們的網管應該要找出系統或軟體的安全漏洞，然後，儘快修補這些漏洞，而不是只是移除/修改那些遭駭的檔案。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;首頁：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R094fNR4E_I/AAAAAAAAA7c/WBbsuLg3wsI/s1600-R/mtc_ntnu_edu_home_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R094fNR4E_I/AAAAAAAAA7c/LQtCbte5OvY/s320/mtc_ntnu_edu_home_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138458177388942322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;遭駭之網頁：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R09479R4FAI/AAAAAAAAA7k/bPKj4G4IPgY/s1600-R/mtc_ntnu_edu_hacked_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R09479R4FAI/AAAAAAAAA7k/wSoP8iJbBYs/s320/mtc_ntnu_edu_hacked_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138458671310181378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Google Search的結果(遭駭次數蠻多，還不改善)：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R095aNR4FBI/AAAAAAAAA7s/_rYS56jlCTs/s1600-R/mtc_ntnu_edu_google_search_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R095aNR4FBI/AAAAAAAAA7s/UkfH7B4dStY/s320/mtc_ntnu_edu_google_search_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138459191001224210" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意程式連結為(已失效，但原來之網址好像是正常網站)：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R095k9R4FCI/AAAAAAAAA70/jdICZa2k6cI/s1600-R/mtc_ntnu_edu_malurl_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R095k9R4FCI/AAAAAAAAA70/9lHMzE8PfdQ/s320/mtc_ntnu_edu_malurl_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138459375684817954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0957dR4FDI/AAAAAAAAA78/I65ErBMowos/s1600-R/balancascapital_home_20071130.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0957dR4FDI/AAAAAAAAA78/4IIJ1EnESJI/s320/balancascapital_home_20071130.png" alt="" id="BLOGGER_PHOTO_ID_5138459762231874610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-5790045104895143065?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/5790045104895143065/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=5790045104895143065' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5790045104895143065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/5790045104895143065'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_30.html' title='國立台灣師範大學國語教學中心網站遭駭且被植入惡意程式'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_JNaO8YWc9rQ/R094fNR4E_I/AAAAAAAAA7c/LQtCbte5OvY/s72-c/mtc_ntnu_edu_home_20071130.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2571551498184879182</id><published>2007-11-28T16:17:00.000+08:00</published><updated>2007-11-28T16:31:48.453+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>台北市雜誌商業同業公會又被植入惡意連結</title><content type='html'>台北市雜誌商業同業公會又被植入惡意連結，此惡意程式為 W32/Lineage.GLV.worm，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: Kao)&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R00ky9R4E9I/AAAAAAAAA7M/GEr14iS64pc/s1600-h/magazine_home_20071128.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R00ky9R4E9I/AAAAAAAAA7M/GEr14iS64pc/s320/magazine_home_20071128.png" alt="" id="BLOGGER_PHOTO_ID_5137803207761204178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁及中英文首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R00lCtR4E-I/AAAAAAAAA7U/wEuWe-IRzFc/s1600-h/magazine_malurl_20071128.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R00lCtR4E-I/AAAAAAAAA7U/wEuWe-IRzFc/s320/magazine_malurl_20071128.png" alt="" id="BLOGGER_PHOTO_ID_5137803478344143842" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\124327MM.DLL&lt;br /&gt;C:\WINDOWS\124327WL.DLL&lt;br /&gt;C:\WINDOWS\124327WO.DLL&lt;br /&gt;C:\WINDOWS\system32\cmdbcs.dll&lt;br /&gt;C:\WINDOWS\system32\DbgHlp32.dll&lt;br /&gt;C:\WINDOWS\system32\gdchdi32.dll&lt;br /&gt;C:\WINDOWS\system32\gddji32.dll&lt;br /&gt;C:\WINDOWS\system32\gdfyi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdgji32.dll&lt;br /&gt;C:\WINDOWS\system32\gdjzi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdqji32.dll&lt;br /&gt;C:\WINDOWS\system32\gdqqhxi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdtli32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwdi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwli32.dll&lt;br /&gt;C:\WINDOWS\system32\gdxwtwi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdzxi32.dll&lt;br /&gt;C:\WINDOWS\system32\GenProtect.dll&lt;br /&gt;C:\WINDOWS\system32\LotusHlp.dll&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\NVDispDrv.dll&lt;br /&gt;C:\WINDOWS\system32\videodevice.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: PciHardDisk&lt;br /&gt;DISPLAY: PciHardDisk&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\pcidisk.sys&lt;br /&gt;&lt;br /&gt;NAME: comint32&lt;br /&gt;DISPLAY: comint32&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\DRIVERS\comint32.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYLOADER.EXE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MSDEG32.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp89.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp8C.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp8D.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp98.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp9B.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp9C.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp9D.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA0.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA1.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA4.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpAD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\fy[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\go[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\jh[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\jz[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\mh[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\pps[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\wl[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\zx[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\cs[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\new05[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\tl[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\wm2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\xw[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zt[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\014[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\11[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\ch[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\cq[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\d3[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\hx[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\my2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\qj[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1299644[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\dh[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\dj[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\haha[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\ki[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\wd1[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\wow[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\zy[1].exe&lt;br /&gt;C:\Program Files\conime0.exe&lt;br /&gt;C:\WINDOWS\124327L.exe&lt;br /&gt;C:\WINDOWS\124327M.exe&lt;br /&gt;C:\WINDOWS\124327MM.DLL&lt;br /&gt;C:\WINDOWS\124327W.exe&lt;br /&gt;C:\WINDOWS\124327WL.DLL&lt;br /&gt;C:\WINDOWS\124327WO.DLL&lt;br /&gt;C:\WINDOWS\cmdbcs.exe&lt;br /&gt;C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;C:\WINDOWS\GenProtect.exE&lt;br /&gt;C:\WINDOWS\LotusHlp.exe&lt;br /&gt;C:\WINDOWS\NVDispDRV.EXE&lt;br /&gt;C:\WINDOWS\system32\cmdbcs.dll&lt;br /&gt;C:\WINDOWS\system32\Com\comrepl32.exe&lt;br /&gt;C:\WINDOWS\system32\config\AppEventw.cfg&lt;br /&gt;C:\WINDOWS\system32\DbgHlp32.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\comint32.sys&lt;br /&gt;C:\WINDOWS\system32\drivers\pcibus.sys&lt;br /&gt;C:\WINDOWS\system32\gdchdi32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdchdi32.dll&lt;br /&gt;C:\WINDOWS\system32\gddji32.cfg&lt;br /&gt;C:\WINDOWS\system32\gddji32.dll&lt;br /&gt;C:\WINDOWS\system32\gdfyi32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdfyi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdgji32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdgji32.dll&lt;br /&gt;C:\WINDOWS\system32\gdjzi32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdjzi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdqji32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdqji32.dll&lt;br /&gt;C:\WINDOWS\system32\gdqqhxi32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdqqhxi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdtli32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdtli32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwdi32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdwdi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwli32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdwli32.dll&lt;br /&gt;C:\WINDOWS\system32\gdxwtwi32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdxwtwi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdzhtui32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdzhtui32.dll&lt;br /&gt;C:\WINDOWS\system32\gdzxi32.cfg&lt;br /&gt;C:\WINDOWS\system32\gdzxi32.dll&lt;br /&gt;C:\WINDOWS\system32\GenProtect.dll&lt;br /&gt;C:\WINDOWS\system32\LotusHlp.dll&lt;br /&gt;C:\WINDOWS\system32\LYLOADER.EXE&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\MSDEG32.DLL&lt;br /&gt;C:\WINDOWS\system32\NVDispDrv.dll&lt;br /&gt;C:\WINDOWS\system32\videodevice.dll&lt;br /&gt;&lt;br /&gt;[Added LSP]&lt;br /&gt;ID: 1016&lt;br /&gt;NAME: MSAPI Tcpip [UDP/IP]&lt;br /&gt;&lt;br /&gt;ID: 1017&lt;br /&gt;NAME: MSAPI Tcpip [TCP/IP]&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=GenProtect&lt;br /&gt;Data=C:\WINDOWS\GenProtect.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=cmdbcs&lt;br /&gt;Data=C:\WINDOWS\cmdbcs.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysM&lt;br /&gt;Data=C:\WINDOWS\124327M.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysW&lt;br /&gt;Data=C:\WINDOWS\124327L.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSys&lt;br /&gt;Data=C:\WINDOWS\124327W.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=NVDispDrv&lt;br /&gt;Data=C:\WINDOWS\NVDispDRV.EXE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=DbgHlp32&lt;br /&gt;Data=C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=LotusHlp&lt;br /&gt;Data=C:\WINDOWS\LotusHlp.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/28 @ 02:35)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;pcibus.sys:&lt;br /&gt; [     Symantec     ], "W32.Fujacks.L"&lt;br /&gt; [     Microsoft    ], "Exploit:Win32/Siveras.E"&lt;br /&gt; [     Sophos       ], "[FILE:0000\FILE:0000]:Mal/Behav-160"&lt;br /&gt; [     Panda        ], "W32/Lineage.GLV.worm"&lt;br /&gt; [     Panda_Beta   ], "W32/Lineage.GLV.worm"&lt;br /&gt; [     Nod32        ], "a variant of Win32/Jalous worm"&lt;br /&gt; [     Fortinet     ], "W32/DcomRpc.BK!worm"&lt;br /&gt; [     HBEDV        ], "TR/Dldr.Agent.45056"&lt;br /&gt; [     Norman       ], "Trojan W32/DLoader.EHRE"&lt;br /&gt; [     Rising       ], "Trojan.Win32.Mnless.znb"&lt;br /&gt; [     Ikarus       ], "Worm.Win32.Downloader.bk"&lt;br /&gt; [     Grisoft      ], "Trojan horse Dropper.Small.29.AR"&lt;br /&gt; [     quickheal    ], "Worm.Downloader.bk"&lt;br /&gt; [     WebWasher    ], "Trojan.Dldr.Agent.45056"&lt;br /&gt;014[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.005"&lt;br /&gt; [     Alpha_Gen    ], "Possible_HUPIGON"&lt;br /&gt; [     Symantec     ], "W32.Fujacks.L"&lt;br /&gt; [     Microsoft    ], "[-&gt;(NSPack)]:Exploit:Win32/Siveras.E"&lt;br /&gt; [     Kaspersky    ], "PAK:NSPack"&lt;br /&gt; [     McAfee       ], "New Malware.aq !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aq !!"&lt;br /&gt; [     Sophos       ], "[FILE:0000\FILE:0000\FILE:0000]:Mal/Behav-160, Mal/Packer"&lt;br /&gt; [     Nod32        ], "Win32/Jalous.O worm"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dldr.Agent.45056"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_N.gen"&lt;br /&gt; [     Ikarus       ], "Packed.Win32.Klone.af"&lt;br /&gt; [     Grisoft      ], "Trojan horse Dropper.Generic.SIN"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     quickheal    ], "Worm.Downloader.bi"&lt;br /&gt; [     vba32        ], "Worm.Win32.Downloader.bi"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dldr.Agent.45056"&lt;br /&gt;pps[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Possible_EncScr"&lt;br /&gt; [     Beta_Gen     ], "Possible_EncScr"&lt;br /&gt; [     HBEDV        ], "EXP/RealPlay.B"&lt;br /&gt; [     Rising       ], "Hack.Exploit.Script.JS.Agent.bz"&lt;br /&gt; [     Authentium   ], "JS/RealPlay.B"&lt;br /&gt; [     WebWasher    ], "Exploit.RealPlay.B"&lt;br /&gt;new05[1].htm:&lt;br /&gt; [     Sophos       ], "Mal/Iframe-A"&lt;br /&gt; [     Rising       ], "Trojan.DL.Script.JS.Agent.lst"&lt;br /&gt;haha[1].htm:&lt;br /&gt; [     Rising       ], "Trojan.Script.JS.Agent.m"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;11[1].js:&lt;br /&gt; [     HBEDV        ], "JS/Dldr.Agent.YA"&lt;br /&gt; [     WebWasher    ], "Script.Dldr.Agent.YA"&lt;br /&gt;tmpAD.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.7"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.7"&lt;br /&gt;gdfyi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Delf.uv"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.ZFW"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;gdchdi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Delf.uv"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;fy[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Delf.uv"&lt;br /&gt; [     Grisoft      ], "Trojan horse SHeur.ADQI"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.iub"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;comint32.sys:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;ch[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     Grisoft      ], "Trojan horse SHeur.ADQG"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;gdjzi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Symantec     ], "Trojan Horse"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.NHF!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.CrashSystem.C"&lt;br /&gt;NVDispDrv.dll:&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.ihi"&lt;br /&gt; [     McAfee       ], "PWS-Zhengtu.dll"&lt;br /&gt; [     McAfee_Beta  ], "PWS-Zhengtu.dll"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GLX"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GLX"&lt;br /&gt; [     Alwil        ], "Win32:OnLineGames-BHW [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.IHI!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ihi"&lt;br /&gt; [     Norman       ], "Trojan W32/OnLineGames.WLG"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.akv"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TNE"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.ihi"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ihi"&lt;br /&gt; [     bitdefender  ], "Generic.Malware.PWS.7EF9E12D"&lt;br /&gt;tmpA1.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;tmpA0.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.4"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.4"&lt;br /&gt;tl[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse SHeur.ADQH"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;gdtli32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.ZFV"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;tmp9D.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;tmp9C.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.13"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.13"&lt;br /&gt;tmp9B.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.4"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.4"&lt;br /&gt;hx[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.7"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.QQHX.tsg"&lt;br /&gt; [     Ikarus       ], "Backdoor.Win32.Rbot.aeu"&lt;br /&gt; [     Grisoft      ], "Trojan horse SHeur.ADQJ"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.7"&lt;br /&gt;gdqqhxi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.7"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.ZFF"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.7"&lt;br /&gt;wl[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.2"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSA"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.2"&lt;br /&gt;tmp98.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;gdwli32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.2"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSD"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.2"&lt;br /&gt;wm2[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPK"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.IQQ!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TND"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.fb"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.CrashSystem.C"&lt;br /&gt;tmpA4.tmp:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Spibe!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnlineGames.QSG!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/PSW.Wow.adu.2"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Dropper.Win32.Agent.ane"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.THU"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.Wow.adu.2"&lt;br /&gt;gdgji32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Symantec     ], "Trojan Horse"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.X.dll"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.j"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.j"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.IKY!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.YYY"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.iqq"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.CrashSystem.C"&lt;br /&gt;gddji32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.j"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.j"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.ZGF"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.CrashSystem.C"&lt;br /&gt;dj[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     Grisoft      ], "Trojan horse SHeur.ADQO"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     quickheal    ], "TrojanDownloader.Zlob.gen"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.CrashSystem.C"&lt;br /&gt;tmp8D.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.12"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.12"&lt;br /&gt;tmp8C.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;qj[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Grisoft      ], "Trojan horse SHeur.ADQK"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl"&lt;br /&gt;gdqji32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.ZEY"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl"&lt;br /&gt;zx[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.9"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSA"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.9"&lt;br /&gt;tmp89.tmp:&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NIU trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.12"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TSL"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.12"&lt;br /&gt;gdzxi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.9"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.9"&lt;br /&gt;124327WO.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     McAfee       ], "New DLL-b !!"&lt;br /&gt; [     McAfee_Beta  ], "New DLL-b !!"&lt;br /&gt; [     Sophos       ], "Mal/Behav-010"&lt;br /&gt; [     Panda        ], "Trj/Legmir.ATW"&lt;br /&gt; [     Panda_Beta   ], "Trj/Legmir.ATW"&lt;br /&gt; [     Alwil        ], "Win32:Lmir-OK [Trj]"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.Legendmir.NFF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "Trojan W32/DLoader.EGIF"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.hlu"&lt;br /&gt; [     Grisoft      ], "Virus found PSW.OnlineGames"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;124327W.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Lmir.boy"&lt;br /&gt; [     McAfee       ], "[000056d4.EXE]:New DLL-b !!"&lt;br /&gt; [     McAfee_Beta  ], "[000056d4.EXE]:New DLL-b !!"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/Behav-010"&lt;br /&gt; [     Panda        ], "Trj/Wow.RN"&lt;br /&gt; [     Panda_Beta   ], "Trj/Wow.RN"&lt;br /&gt; [     Alwil        ], "Win32:Lmir-OK [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Zuten.AO"&lt;br /&gt; [     Nod32        ], "Win32/PSW.WOW.WU trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.IOY!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.LMir.yys"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.WOW.vd"&lt;br /&gt; [     Ewido        ], "Trojan.Lmir.boy"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.XIC"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Lmir.boy"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.16"&lt;br /&gt; [     virusbuster  ], "Trojan.DR.Lmir.Gen.4"&lt;br /&gt; [     Authentium   ], "W32/Blocker-based!Maximus"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt; [     bitdefender  ], "Trojan.PWS.Lmir.ULP"&lt;br /&gt;124327MM.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Lemir.G"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Lmir.BMO"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.ieg"&lt;br /&gt; [     McAfee       ], "PWS-LegMir"&lt;br /&gt; [     McAfee_Beta  ], "PWS-LegMir"&lt;br /&gt; [     Sophos       ], "Mal/Behav-010"&lt;br /&gt; [     Panda        ], "Trj/Legmir.ATU"&lt;br /&gt; [     Panda_Beta   ], "Trj/Legmir.ATU"&lt;br /&gt; [     Alwil        ], "Win32:Lmir-OK [Trj]"&lt;br /&gt; [     Nod32        ], "Win32/PSW.Legendmir.NFF trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.IEG!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "Trojan W32/DLoader.EGES"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.LMir.yyy"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.ieg"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Legendmir.IXE"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.ieg"&lt;br /&gt; [     vba32        ], "Trojan-PSW.Win32.OnLineGames.ieg"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;124327M.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Symantec     ], "Infostealer.Lemir.G"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Lmir.boy"&lt;br /&gt; [     McAfee       ], "[000056d4.EXE]:PWS-LegMir"&lt;br /&gt; [     McAfee_Beta  ], "[000056d4.EXE]:PWS-LegMir"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/Behav-010"&lt;br /&gt; [     Panda        ], "Trj/Legmir.ATU"&lt;br /&gt; [     Panda_Beta   ], "Trj/Legmir.ATU"&lt;br /&gt; [     Alwil        ], "Win32:Lmir-OK [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Zuten.AO"&lt;br /&gt; [     Nod32        ], "Win32/PSW.WOW.WU trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.IOY!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.LMir.yys"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.WOW.vd"&lt;br /&gt; [     Ewido        ], "Trojan.Lmir.boy"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.XIC"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Lmir.boy"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.16"&lt;br /&gt; [     virusbuster  ], "Trojan.DR.Lmir.Gen.4"&lt;br /&gt; [     Authentium   ], "W32/Blocker-based!Maximus"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt; [     bitdefender  ], "Trojan.PWS.Lmir.ULP"&lt;br /&gt;cmdbcs.dll:&lt;br /&gt; [     Alwil        ], "Win32:OnLineGames-BHW [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.NFL!tr.pws"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.amm"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.OnLineGames.BHW"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TTF"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.inw"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     virusbuster  ], "Trojan.OnlineGames.Gen.43"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.6CE89BFA"&lt;br /&gt;jh[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.005"&lt;br /&gt; [     Kaspersky    ], "PAK:NSPack, PAK:PE_Patch"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.INW!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_N.gen"&lt;br /&gt; [     Ikarus       ], "Packed.Win32.Klone.af"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.6545F469"&lt;br /&gt;cmdbcs.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.005"&lt;br /&gt; [     Kaspersky    ], "PAK:NSPack, PAK:PE_Patch"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.INW!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_N.gen"&lt;br /&gt; [     Ikarus       ], "Packed.Win32.Klone.af"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.6545F469"&lt;br /&gt;wd1[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     Grisoft      ], "Trojan horse SHeur.ADQR"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;gdwdi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.Generic5.ZGI"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;zt[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)-&gt;[RSRCEmb]]:VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.12"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TTI"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.12"&lt;br /&gt;gdzhtui32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.ivl.12"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TTJ"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.PSW.OnlineGames.ivl.12"&lt;br /&gt;my2[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Lmir.BMQ"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GMN"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GMN"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TOL"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.isb"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "Trojan-PWS.Games.4"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.F769E0BB"&lt;br /&gt;GenProtect.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Lmir.BMQ"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GMN"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GMN"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TOL"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.isb"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "Trojan-PWS.Games.4"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.F769E0BB"&lt;br /&gt;GenProtect.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Lmir.BMQ"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GMN"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GMN"&lt;br /&gt; [     Alwil        ], "Win32:OnLineGames-BHW [Trj]"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.IQW!tr.pws"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aqc"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     Grisoft      ], "Trojan horse PSW.OnlineGames.TOM"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;LYMANGR.DLL:&lt;br /&gt;[ Trend ], "TSPY_ONLINEG.LYE"&lt;br /&gt;LYLOADER.EXE:&lt;br /&gt;[ Trend ], "TSPY_ONLINEG.LYE"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2571551498184879182?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2571551498184879182/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2571551498184879182' title='2 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2571551498184879182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2571551498184879182'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_28.html' title='台北市雜誌商業同業公會又被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_JNaO8YWc9rQ/R00ky9R4E9I/AAAAAAAAA7M/GEr14iS64pc/s72-c/magazine_home_20071128.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8615938976807455905</id><published>2007-11-27T12:53:00.000+08:00</published><updated>2007-11-30T11:17:58.225+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>台灣安全設備與服務產業協會網站被植入惡意連結</title><content type='html'>台灣安全設備與服務產業協會網站被植入惡意連結，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0uj9dR4E7I/AAAAAAAAA64/UkaSlqlz5JE/s1600-h/tssia_home_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0uj9dR4E7I/AAAAAAAAA64/UkaSlqlz5JE/s320/tssia_home_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137380076173136818" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在 news01.asp (其他頁面可能要仔細檢查一下囉) 中的&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;/span&gt;：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R0uksNR4E8I/AAAAAAAAA7A/78ALLf2zD6c/s1600-h/tssia_malurl_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R0uksNR4E8I/AAAAAAAAA7A/78ALLf2zD6c/s320/tssia_malurl_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137380879332021186" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\Help\F3A94B4F83BD.DLL&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Desktop\2.bat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\m[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\h[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\stat[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\news01[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\gmsex[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\main[1].js&lt;br /&gt;C:\WINDOWS\Help\F3A94B4F83BD.DLL&lt;br /&gt;C:\WINDOWS\Help\F3A94B4F83BD.EXE&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{2B5174CE-5BFF-4FC3-B9BD-34EF88004AB1}-C:\WINDOWS\HELP\F3A94B4F83BD.DLL&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/28 @ 02:04)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;F3A94B4F83BD.DLL:&lt;br /&gt;[ Trend ], "TROJ_AGENT.AGAC"&lt;br /&gt;F3A94B4F83BD.DLL:&lt;br /&gt;[ Trend ], "Possible_Infostl"&lt;br /&gt;F3A94B4F83BD.EXE:&lt;br /&gt;[ Trend ], "TROJ_AGENT.AGAC"&lt;br /&gt;gmsex[1].exe:&lt;br /&gt;[ Trend ], "ROJ_AGENT.AGAC"&lt;br /&gt;m[1].htm:&lt;br /&gt;[ Trend ], "VBS_PSYME.AXC"&lt;br /&gt;h[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Sophos       ], "Mal/Iframe-A"&lt;br /&gt; [     Norman       ], "Security Risk HTML/Exploit!IFrame.A"&lt;br /&gt;news01[1].htm:&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;yahoo.js:&lt;br /&gt; [     HBEDV        ], "JS/Agent.acg"&lt;br /&gt; [     vba32        ], "Exploit.HTML.Ashell.a"&lt;br /&gt; [     WebWasher    ], "Script.Agent.acg"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8615938976807455905?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8615938976807455905/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8615938976807455905' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8615938976807455905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8615938976807455905'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_27.html' title='台灣安全設備與服務產業協會網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0uj9dR4E7I/AAAAAAAAA64/UkaSlqlz5JE/s72-c/tssia_home_20071126.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2265299917520611643</id><published>2007-11-26T13:04:00.000+08:00</published><updated>2007-11-26T13:19:18.556+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>高雄縣政府水利局網站被植入惡意連結</title><content type='html'>高雄縣政府水利局網站被植入惡意連結，最近有瀏覽這個網頁的網友 (最好認真檢查，因為它植入很多惡意檔案)，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：此惡意程式執行後，會產生很多惡意的執行程序，很容易造成系統當機。&lt;/span&gt;&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0pVg9R4E2I/AAAAAAAAA6Q/Pd1MQldc_ZE/s1600-h/water_home_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0pVg9R4E2I/AAAAAAAAA6Q/Pd1MQldc_ZE/s320/water_home_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137012349663187810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;/span&gt;：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pV6tR4E4I/AAAAAAAAA6g/LMIFxwHutjE/s1600-h/water_malurl_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pV6tR4E4I/AAAAAAAAA6g/LMIFxwHutjE/s320/water_malurl_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137012792044819330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pWDtR4E5I/AAAAAAAAA6o/5z1Ytt7_EcY/s1600-h/water_malcode_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pWDtR4E5I/AAAAAAAAA6o/5z1Ytt7_EcY/s320/water_malcode_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137012946663642002" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後的畫面為 (現在好像不能執行，不知為什麼？)：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0pWs9R4E6I/AAAAAAAAA6w/f2pJoyo2gfs/s1600-h/water_avi_capture_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0pWs9R4E6I/AAAAAAAAA6w/f2pJoyo2gfs/s320/water_avi_capture_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137013655333245858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2265299917520611643?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2265299917520611643/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2265299917520611643' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2265299917520611643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2265299917520611643'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_344.html' title='高雄縣政府水利局網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0pVg9R4E2I/AAAAAAAAA6Q/Pd1MQldc_ZE/s72-c/water_home_20071126.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8418227554911205946</id><published>2007-11-26T12:55:00.000+08:00</published><updated>2007-11-26T13:03:40.916+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>女人國女性購物社群入口網站又被植入惡意連結</title><content type='html'>女人國女性購物社群入口網站又被植入惡意連結，此惡意程式為 Trojan-PSW.Win32.OnLineGames&lt;div style="direction: ltr;"&gt;&lt;wbr&gt;.dr&lt;/div&gt;，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;br /&gt;&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0pSLNR4EzI/AAAAAAAAA54/yTzD8zvD49k/s1600-h/iamlady_home_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0pSLNR4EzI/AAAAAAAAA54/yTzD8zvD49k/s320/iamlady_home_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137008677466149682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的 (&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;放置在她們自己的網站中&lt;/span&gt;)：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pSmtR4E1I/AAAAAAAAA6I/V5DWKVlZjMw/s1600-h/iamlady_malurl_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pSmtR4E1I/AAAAAAAAA6I/V5DWKVlZjMw/s320/iamlady_malurl_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137009149912552274" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added service]&lt;br /&gt;NAME: Winsysser&lt;br /&gt;DISPLAY: WindowsServer&lt;br /&gt;FILE: C:\WINDOWS\system32\ddos.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\~V5SFDYCLNTKs.ExE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\~V5SFDYCLNTKs.VbS&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\bot[1].exe&lt;br /&gt;C:\WINDOWS\system32\ddos.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/23 @ 17:28)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;bo0k.htm:&lt;br /&gt;[     Alpha_Gen    ], "Possible_EncScr"&lt;br /&gt;[     Beta_Gen     ], "Possible_EncScr"&lt;br /&gt;[     McAfee       ], "[0000001a.vbs]:VBS/Psyme"&lt;br /&gt;[     McAfee_Beta  ], "[0000001a.vbs]:VBS/Psyme"&lt;br /&gt;[     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;bot[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "Possible_HUPIGON"&lt;br /&gt;[     Microsoft    ], "[-&gt;(Upack)]:VirTool:Win32/DelfInject.gen!L"&lt;br /&gt;[     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.dr"&lt;br /&gt;[     McAfee       ], "BackDoor-ALC"&lt;br /&gt;[     McAfee_Beta  ], "BackDoor-ALC"&lt;br /&gt;[     Sophos       ], "Mal/Behav-058"&lt;br /&gt;[     Panda        ], "Bck/Antilam.AN"&lt;br /&gt;[     Panda_Beta   ], "Bck/Antilam.AN"&lt;br /&gt;[     Nod32        ], "Win32/Delf.NEA trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Crypt.CFI.Gen"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Ikarus       ], "Trojan-Spy.Win32.Banker.ahy"&lt;br /&gt;[     Ewido        ], "Backdoor.Delf.aow"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Trojan.Crypt.CFI.Gen"&lt;br /&gt;[     bitdefender  ], "Backdoor.Delf.HAR"&lt;br /&gt;ddos.exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "Possible_HUPIGON"&lt;br /&gt;[     Microsoft    ], "[-&gt;(Upack)]:VirTool:Win32/DelfInject.gen!L"&lt;br /&gt;[     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.dr"&lt;br /&gt;[     McAfee       ], "BackDoor-ALC"&lt;br /&gt;[     McAfee_Beta  ], "BackDoor-ALC"&lt;br /&gt;[     Sophos       ], "Mal/Behav-058"&lt;br /&gt;[     Panda        ], "Bck/Antilam.AN"&lt;br /&gt;[     Panda_Beta   ], "Bck/Antilam.AN"&lt;br /&gt;[     Nod32        ], "Win32/Delf.NEA trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Crypt.CFI.Gen"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Ikarus       ], "Trojan-Spy.Win32.Banker.ahy"&lt;br /&gt;[     Ewido        ], "Backdoor.Delf.aow"&lt;br /&gt;[     eAladdin     ], "Suspicious File [100]"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.14"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Trojan.Crypt.CFI.Gen"&lt;br /&gt;[     bitdefender  ], "Backdoor.Delf.HAR"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8418227554911205946?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8418227554911205946/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8418227554911205946' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8418227554911205946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8418227554911205946'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_9882.html' title='女人國女性購物社群入口網站又被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0pSLNR4EzI/AAAAAAAAA54/yTzD8zvD49k/s72-c/iamlady_home_20071126.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-4057554727935024123</id><published>2007-11-26T12:46:00.000+08:00</published><updated>2007-11-26T12:53:43.324+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>台灣小冠鸚鵡俱樂部被植入惡意連結</title><content type='html'>台灣小冠鸚鵡俱樂部被植入惡意連結，此惡意程式為 TSPY_LINEAGE.GLP，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pQItR4ExI/AAAAAAAAA5o/aW_DuygEARY/s1600-h/tccs_home_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pQItR4ExI/AAAAAAAAA5o/aW_DuygEARY/s320/tccs_home_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137006435493221138" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pQTtR4EyI/AAAAAAAAA5w/EmkpICC7zIk/s1600-h/tccs_malurl_20071126.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pQTtR4EyI/AAAAAAAAA5w/EmkpICC7zIk/s320/tccs_malurl_20071126.png" alt="" id="BLOGGER_PHOTO_ID_5137006624471782178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe&lt;br /&gt;C:\WINDOWS\Web\printers\images\ndmai.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\614001[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\g[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\2004[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\717001[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\ah[1].c&lt;br /&gt;C:\WINDOWS\Web\printers\images\ndmai.dll&lt;br /&gt;C:\WINDOWS\Web\printers\images\ndmai.exe&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{7152C68A-D93C-49BF-AFEF-6B4576849A7E}-C:\WINDOWS\Web\printers\images\ndmai.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/23 @ 17:30)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;717001[1].htm:&lt;br /&gt;[ Trend ]: "JS_AGENT.AAJP"&lt;br /&gt;ah[1].c:&lt;br /&gt;[ Trend ]: "EXPL_ANICMOO.GEN"&lt;br /&gt;ndmai.dll:&lt;br /&gt;[ Trend ]: "Possible_Infostl"&lt;br /&gt;ndmai.exe:&lt;br /&gt;[ Trend ]: "TSPY_LINEAGE.GLP"&lt;br /&gt;svchost.exe:&lt;br /&gt;[ Trend ]: "TSPY_LINEAGE.GLP"&lt;br /&gt;2004[1].exe:&lt;br /&gt;[ Trend ]: "SPY_LINEAGE.GLP"&lt;br /&gt;614001[1].htm:&lt;br /&gt;[     Kaspersky    ], "Trojan-Downloader.JS.Psyme.ub"&lt;br /&gt;[     McAfee       ], "VBS/Psyme"&lt;br /&gt;[     McAfee_Beta  ], "VBS/Psyme"&lt;br /&gt;[     Sophos       ], "Mal/Psyme-A"&lt;br /&gt;[     HBEDV        ], "HTML/ADODB.Exploit.Gen"&lt;br /&gt;[     Rising       ], "Trojan.DL.Script.VBS.Agent.xiz"&lt;br /&gt;[     WebWasher    ], "Script.ADODB.Exploit.Gen"&lt;br /&gt;[     bitdefender  ], "Generic.XPL.ADODB.8324063C"&lt;br /&gt;g[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;g[1].htm:&lt;br /&gt;[     McAfee       ], "ObfuscatedHtml"&lt;br /&gt;[     McAfee_Beta  ], "ObfuscatedHtml"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;11181239.rar:&lt;br /&gt;[     Alpha_Gen    ], "Possible_Hifrm"&lt;br /&gt;[     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt;[     Sophos       ], "Mal/Iframe-C"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-4057554727935024123?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/4057554727935024123/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=4057554727935024123' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4057554727935024123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/4057554727935024123'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_26.html' title='台灣小冠鸚鵡俱樂部被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0pQItR4ExI/AAAAAAAAA5o/aW_DuygEARY/s72-c/tccs_home_20071126.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-991393576174348092</id><published>2007-11-23T17:29:00.000+08:00</published><updated>2007-11-23T17:37:12.814+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='安全漏洞'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><category scheme='http://www.blogger.com/atom/ns#' term='網站遭駭'/><title type='text'>新都里餐廳網站遭駭</title><content type='html'>新都里餐廳網站遭駭，在這裡要注意的是這個網站有可能被植入惡意連結或惡意程式碼，所以，他們的網管應該要找出系統或軟體的安全漏洞，然後，儘快修補這些漏洞，而不是只是移除/修改那些遭駭的檔案。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;遭駭前首頁：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0aduUEHeyI/AAAAAAAAA5Q/Mwwo0qQu8p4/s1600-h/shintori_home_20071123.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0aduUEHeyI/AAAAAAAAA5Q/Mwwo0qQu8p4/s320/shintori_home_20071123.png" alt="" id="BLOGGER_PHOTO_ID_5135965844048149282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;遭駭後首頁：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0aeR0EHezI/AAAAAAAAA5Y/m_ubwEgp36g/s1600-h/shintori_hacked_20071123.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/R0aeR0EHezI/AAAAAAAAA5Y/m_ubwEgp36g/s320/shintori_hacked_20071123.png" alt="" id="BLOGGER_PHOTO_ID_5135966453933505330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0aejUEHe0I/AAAAAAAAA5g/tSEUK4s4v6E/s1600-h/shintori_hacked_20071123-1.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0aejUEHe0I/AAAAAAAAA5g/tSEUK4s4v6E/s320/shintori_hacked_20071123-1.png" alt="" id="BLOGGER_PHOTO_ID_5135966754581216066" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;至於詳細的資訊，請參考 &lt;a href="http://turk-h.org/defacement/view/237861/shintori.com.tw/"&gt;Turk-h&lt;/a&gt;。&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-991393576174348092?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/991393576174348092/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=991393576174348092' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/991393576174348092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/991393576174348092'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_23.html' title='新都里餐廳網站遭駭'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0aduUEHeyI/AAAAAAAAA5Q/Mwwo0qQu8p4/s72-c/shintori_home_20071123.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8828264752372659880</id><published>2007-11-20T09:24:00.000+08:00</published><updated>2007-11-20T10:00:35.566+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>政大統計系系友會網站被植入惡意連結</title><content type='html'>政大統計系系友會網站被植入惡意連結，此惡意程式為 Infostealer.Gampass，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0I5JUEHewI/AAAAAAAAA5A/JIowpbE7eRE/s1600-h/stat_nccu_edu_home_20071120.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0I5JUEHewI/AAAAAAAAA5A/JIowpbE7eRE/s320/stat_nccu_edu_home_20071120.png" alt="" id="BLOGGER_PHOTO_ID_5134729357323369218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在 news.asp (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R0I5akEHexI/AAAAAAAAA5I/vVVrzXtvqWU/s1600-h/stat_nccu_edu_malurl_20071120.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/R0I5akEHexI/AAAAAAAAA5I/vVVrzXtvqWU/s320/stat_nccu_edu_malurl_20071120.png" alt="" id="BLOGGER_PHOTO_ID_5134729653676112658" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[Added process]&lt;br /&gt;C:\Program Files\4.exe&lt;br /&gt;C:\Program Files\6.exe&lt;br /&gt;C:\Program Files\10.exe&lt;br /&gt;C:\WINDOWS\124327L.exe&lt;br /&gt;C:\WINDOWS\Logo1_.exe&lt;br /&gt;C:\Program Files\2.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvSys_54.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys&lt;br /&gt;C:\WINDOWS\system32\avwgemn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxfmn.dll&lt;br /&gt;C:\WINDOWS\system32\csavpw0.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\DVBBack01.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack02.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack03.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack04.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack05.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack06.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack07.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack08.dll&lt;br /&gt;C:\WINDOWS\system32\gdwli32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwmi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdzxi32.dll&lt;br /&gt;C:\WINDOWS\system32\kaqhizy.dll&lt;br /&gt;C:\WINDOWS\system32\kawdczy.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch01.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch03.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch04.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch05.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch06.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch07.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxjma.dll&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\naktcmvdmv.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr01.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr02.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr03.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr04.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr05.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr06.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr07.dll&lt;br /&gt;C:\WINDOWS\system32\qqhxatl.dll&lt;br /&gt;C:\WINDOWS\system32\qqsgatl.dll&lt;br /&gt;C:\WINDOWS\system32\ratbjpi.dll&lt;br /&gt;C:\WINDOWS\system32\rsmyhpm.dll&lt;br /&gt;C:\WINDOWS\system32\sidjdzy.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink01.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink02.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink03.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink04.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink05.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink06.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink07.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink08.dll&lt;br /&gt;C:\WINDOWS\system32\sqmapi32.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl01.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl02.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl03.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl04.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl05.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl06.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl07.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl08.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl09.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl10.dll&lt;br /&gt;C:\WINDOWS\system32\videodevice.dll&lt;br /&gt;C:\WINDOWS\system32\WinForm.dll&lt;br /&gt;C:\WINDOWS\system32\ymveoxgpyi.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: PciHardDisk&lt;br /&gt;DISPLAY: PciHardDisk&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\pcidisk.sys-1&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\autorun.inf&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aAA.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aAB.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aAC.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aAD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aAE.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aAF.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aFF.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\1a5e_appcompat.txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\3762C5.dmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\37A9E0.dmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\382C3F.dmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\3848FF.dmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\3853FB.dmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\3857E3.dmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\38591C.dmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\920e_appcompat.txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a1.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a15.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a18.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a20.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a4.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a6.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a7.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\c798_appcompat.txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\d487_appcompat.txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\d5cc_appcompat.txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\d849_appcompat.txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\dcb2_appcompat.txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYLOADER.EXE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MSDEG32.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp9F.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpA6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpBC.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpBD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpBF.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC1.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpC9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpCD.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD0.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpD9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpDE.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE6.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpE9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpEA.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpED.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmpF9.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\_uninsep.bat&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\10[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1153797[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1299644[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\17[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\18[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\21[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\2[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\3[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\4[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\7[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\88[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ad[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\bb[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\g3[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\go[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\htm[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\sha1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft02[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft03[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft04[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft09[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft10[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft12[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft13[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft15[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft18[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\soft20[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\web.2008yi[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\xx.9365[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\014[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\014[2].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1358616[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\19[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\3[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\881[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\884[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\8[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\boc.sbb22[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ms33[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\new82[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\old[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\pps[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft01[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft01[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft03[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft06[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft07[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft09[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft11[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft14[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft17[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft19[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\soft20[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\web[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\x[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zs[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zu[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\014[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1428891[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\4[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\5[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\8819[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\882[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\883[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\9[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\bf[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\newbala[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\news[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\sha1[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\soft10[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\stat[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\zu[3].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\11[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\12[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\13[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1402795[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\14[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1[1].gif&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\6619038[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\6[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\882[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\888down[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\ac[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\du66[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\dyy[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\g14[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\haha[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\nn[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft00[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft05[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft07[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft08[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft12[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft13[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft15[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft18[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\soft19[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\text[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\web.2008yi[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\xx.9365[1].htm&lt;br /&gt;C:\PegeFile.pif&lt;br /&gt;C:\Program Files\10.exe&lt;br /&gt;C:\Program Files\12.exe&lt;br /&gt;C:\Program Files\19.exe&lt;br /&gt;C:\Program Files\2.exe&lt;br /&gt;C:\Program Files\21.exe&lt;br /&gt;C:\Program Files\3.exe&lt;br /&gt;C:\Program Files\4.exe&lt;br /&gt;C:\Program Files\6.exe&lt;br /&gt;C:\Program Files\7.exeCC:\Program Files\8.exe&lt;br /&gt;C:\Program Files\Internet Explorer\10Sy.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.bak&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.bkk&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvSys_54.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvSys_54.Tao&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NvWin_5.Jmp&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\SysWin7k.Jmp&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Tao&lt;br /&gt;C:\WINDOWS\124327L.exe&lt;br /&gt;C:\WINDOWS\124327M.exe&lt;br /&gt;C:\WINDOWS\124327MM.DLL&lt;br /&gt;C:\WINDOWS\124327WL.DLL&lt;br /&gt;C:\WINDOWS\555888&lt;br /&gt;C:\WINDOWS\AVPSrv.exE&lt;br /&gt;C:\WINDOWS\cmdbcs.exe&lt;br /&gt;C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;C:\WINDOWS\Dll.dll&lt;br /&gt;C:\WINDOWS\Fonts\ardaase.fon&lt;br /&gt;C:\WINDOWS\Fonts\avzxfin.dll&lt;br /&gt;C:\WINDOWS\Fonts\cadaafx.fon&lt;br /&gt;C:\WINDOWS\Fonts\chtiaur.fon&lt;br /&gt;C:\WINDOWS\Fonts\enhuafx.fon&lt;br /&gt;C:\WINDOWS\Fonts\enweafx.fon&lt;br /&gt;C:\WINDOWS\Fonts\gemoand.fon&lt;br /&gt;C:\WINDOWS\Fonts\kvdxjcf.dll&lt;br /&gt;C:\WINDOWS\Fonts\msguasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mswuasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mszhasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\ratbjni.dll&lt;br /&gt;C:\WINDOWS\Fonts\sidjdcs.dll&lt;br /&gt;C:\WINDOWS\GenProtect.exe&lt;br /&gt;C:\WINDOWS\Kvsc3.exE&lt;br /&gt;C:\WINDOWS\llllllab&lt;br /&gt;C:\WINDOWS\Logo1_.exe&lt;br /&gt;C:\WINDOWS\mppds.exe&lt;br /&gt;C:\WINDOWS\MsIMMs32.exE&lt;br /&gt;C:\WINDOWS\MsPrint32D.exe&lt;br /&gt;C:\WINDOWS\swchost.exe&lt;br /&gt;C:\WINDOWS\system32\asview32.dll&lt;br /&gt;C:\WINDOWS\system32\asvliuliu32.dll&lt;br /&gt;C:\WINDOWS\system32\AVPSrv.dll&lt;br /&gt;C:\WINDOWS\system32\avwgein.dll&lt;br /&gt;C:\WINDOWS\system32\avwgemn.dll&lt;br /&gt;C:\WINDOWS\system32\avwgest.exe&lt;br /&gt;C:\WINDOWS\system32\avwldin.dll&lt;br /&gt;C:\WINDOWS\system32\avwldmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwldst.exe&lt;br /&gt;C:\WINDOWS\system32\avzxfmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxfst.exe&lt;br /&gt;C:\WINDOWS\system32\bpfuxa.dll&lt;br /&gt;C:\WINDOWS\system32\cmdbcs.dll&lt;br /&gt;C:\WINDOWS\system32\Com\comrepl32.exe&lt;br /&gt;C:\WINDOWS\system32\config\AppEventw.cfg&lt;br /&gt;C:\WINDOWS\system32\csavpw0.dll&lt;br /&gt;C:\WINDOWS\system32\cselnf.dll&lt;br /&gt;C:\WINDOWS\system32\DbgHlp32.dll&lt;br /&gt;C:\WINDOWS\system32\djatl.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\8761CCDC.sys&lt;br /&gt;C:\WINDOWS\system32\drivers\pcibus.sys&lt;br /&gt;C:\WINDOWS\system32\drivers\scvhost.exe&lt;br /&gt;C:\WINDOWS\system32\drivers\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\DVBBack01.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack02.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack03.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack04.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack05.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack06.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack07.dll&lt;br /&gt;C:\WINDOWS\system32\DVBBack08.dll&lt;br /&gt;C:\WINDOWS\system32\ewgqyirajt.dll&lt;br /&gt;C:\WINDOWS\system32\feibgp.dll&lt;br /&gt;C:\WINDOWS\system32\fngvgs.dll&lt;br /&gt;C:\WINDOWS\system32\gdwli32.dll&lt;br /&gt;C:\WINDOWS\system32\gdwmi32.dll&lt;br /&gt;C:\WINDOWS\system32\gdzxi32.dll&lt;br /&gt;C:\WINDOWS\system32\GenProtect.dll&lt;br /&gt;C:\WINDOWS\system32\gzvjnw.dll&lt;br /&gt;C:\WINDOWS\system32\iqxxie.dll&lt;br /&gt;C:\WINDOWS\system32\kaqhiaz.exe&lt;br /&gt;C:\WINDOWS\system32\kaqhics.dll&lt;br /&gt;C:\WINDOWS\system32\kaqhizy.dll&lt;br /&gt;C:\WINDOWS\system32\kawdczy.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch01.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch02.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch03.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch04.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch05.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch06.dll&lt;br /&gt;C:\WINDOWS\system32\KVBatch07.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxjis.exe&lt;br /&gt;C:\WINDOWS\system32\kvdxjma.dll&lt;br /&gt;C:\WINDOWS\system32\Kvsc3.dll&lt;br /&gt;C:\WINDOWS\system32\LYLOADER.EXE&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\mppds.dll&lt;br /&gt;C:\WINDOWS\system32\MSDEG32.DLL&lt;br /&gt;C:\WINDOWS\system32\MsIMMs32.dll&lt;br /&gt;C:\WINDOWS\system32\MsPrint32D.dll&lt;br /&gt;C:\WINDOWS\system32\myirclucmv.dll&lt;br /&gt;C:\WINDOWS\system32\naktcmvdmv.dll&lt;br /&gt;C:\WINDOWS\system32\nslkupi.exe&lt;br /&gt;C:\WINDOWS\system32\ntsokele.exe&lt;br /&gt;C:\WINDOWS\system32\ProcSvr01.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr02.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr03.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr04.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr05.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr06.dll&lt;br /&gt;C:\WINDOWS\system32\ProcSvr07.dll&lt;br /&gt;C:\WINDOWS\system32\qqhxatl.dll&lt;br /&gt;C:\WINDOWS\system32\qqsgatl.dll&lt;br /&gt;C:\WINDOWS\system32\ratbjpi.dll&lt;br /&gt;C:\WINDOWS\system32\ratbjtl.exe&lt;br /&gt;C:\WINDOWS\system32\rsmyhfg.dll&lt;br /&gt;C:\WINDOWS\system32\rsmyhpm.dll&lt;br /&gt;C:\WINDOWS\system32\rsmyhsp.exe&lt;br /&gt;C:\WINDOWS\system32\sidjdaz.exe&lt;br /&gt;C:\WINDOWS\system32\sidjdzy.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink01.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink02.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink03.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink04.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink05.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink06.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink07.dll&lt;br /&gt;C:\WINDOWS\system32\SQLLink08.dll&lt;br /&gt;C:\WINDOWS\system32\sqmapi32.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl01.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl02.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl03.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl04.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl05.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl06.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl07.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl08.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl09.dll&lt;br /&gt;C:\WINDOWS\system32\SVCCtrl10.dll&lt;br /&gt;C:\WINDOWS\system32\sysbl.exe&lt;br /&gt;C:\WINDOWS\system32\upxdnd.dll&lt;br /&gt;C:\WINDOWS\system32\videodevice.dll&lt;br /&gt;C:\WINDOWS\system32\vktcmvenwf.dll&lt;br /&gt;C:\WINDOWS\system32\WinForm.dll&lt;br /&gt;C:\WINDOWS\system32\winsock32.dll&lt;br /&gt;C:\WINDOWS\system32\xywsfu.dll&lt;br /&gt;C:\WINDOWS\system32\ymveoxgpyi.dll&lt;br /&gt;C:\WINDOWS\system32\yoyhrajsbk.dll&lt;br /&gt;C:\WINDOWS\system32\yzbhjx.dll&lt;br /&gt;C:\WINDOWS\upxdnd.exe&lt;br /&gt;C:\WINDOWS\WinForm.exE&lt;br /&gt;C:\WINDOWS\~tmp2896.exe&lt;br /&gt;C:\WINDOWS\~tmp5936.exe&lt;br /&gt;C:\WINDOWS\~tmp786.exe&lt;br /&gt;C:\WINDOWS\~tmp9464.exe&lt;br /&gt;C:\WINDOWS\~tmp9792.exe&lt;br /&gt;&lt;br /&gt;[Added LSP]&lt;br /&gt;ID: 1025&lt;br /&gt;NAME: MSAPI Tcpip [TCP/IP]&lt;br /&gt;&lt;br /&gt;ID: 1029&lt;br /&gt;NAME: MSAPI Tcpip [UDP/IP]&lt;br /&gt;&lt;br /&gt;ID: 1030&lt;br /&gt;NAME: MSAPI Tcpip [TCP/IP]&lt;br /&gt;   &lt;br /&gt;[Added registry]   &lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={0EA66AD2-CF26-2E23-532B-B292E22F3266}&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={8E32FA58-3453-FA2D-BC49-F340348ACCE8}&lt;br /&gt;Data=rsmyhpm.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={6C8BC750-B3E7-4B4A-AC7A-454E6FB9770A}&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={A87755CE-D2D1-4580-8A99-ECCCFC9F5CC9}&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={AC87A354-ABC3-DEDE-FF33-3213FD7447CA}&lt;br /&gt;Data =kvdxjma.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={4960356A-458E-DE24-BD50-268F589A56A4}&lt;br /&gt;Data=avwldmn.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={5A1247C1-53DA-FF43-ABD3-345F323A48D5}&lt;br /&gt;Data=avwgemn.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={A6650011-3344-6688-4899-345FABCD156A}&lt;br /&gt;Data=ratbjpi.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={38907901-1416-3389-9981-372178569983}&lt;br /&gt;Data=kawdczy.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={97D81718-1314-5200-2597-587901018079}&lt;br /&gt;Data=kaqhizy.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={48847374-8323-FADC-B443-4732ABCD3784}&lt;br /&gt;Data=sidjdzy.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={6859245F-345D-BC13-AC4F-145D47DA34F6}&lt;br /&gt;Data=avzxfmn.dll&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={8DFA2904-9664-43AE-8929-4347554D24B6}&lt;br /&gt;Data=Extr rising hook CS&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={B0E4D1E9-3CE5-48A1-8DF0-6463E046E7EF}&lt;br /&gt;   &lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={A12C8D43-AC10-4C17-9136-E3E2FC9B3D21}&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks&lt;br /&gt;Value={A2AC7E3B-30BE-466f-8BAB-1FF9DADD8C7D}&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=upxdnd&lt;br /&gt;Data=C:\WINDOWS\upxdnd.exe&lt;br /&gt;   &lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=mppds&lt;br /&gt;Data=C:\WINDOWS\mppds.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=cmdbcs&lt;br /&gt;Data=C:\WINDOWS\cmdbcs.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysM&lt;br /&gt;Data=C:\WINDOWS\124327M.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=KVP&lt;br /&gt;Data=C:\WINDOWS\system32\drivers\svchost.exe&lt;br /&gt;   &lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=GenProtect&lt;br /&gt;Data=C:\WINDOWS\GenProtect.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=DbgHlp32&lt;br /&gt;Data=C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=MsPrint32D&lt;br /&gt;Data=C:\WINDOWS\MsPrint32D.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysW&lt;br /&gt;Data=C:\WINDOWS\swchost.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=MsIMMs32&lt;br /&gt;Data=C:\WINDOWS\MsIMMs32.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=Kvsc3&lt;br /&gt;Data=C:\WINDOWS\Kvsc3.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=AVPSrv&lt;br /&gt;Data=C:\WINDOWS\AVPSrv.exE&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinForm&lt;br /&gt;Data=C:\WINDOWS\WinForm.exE&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/19 @ 14:14)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;xx.9365[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;xywsfu.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.iax"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnlineGames.SUM!tr.pws"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aha"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.C1B879DE"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ymveoxgpyi.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPH"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, PAK:PE_Patch.MaskPE, Trojan-PSW.Win32.OnLineGames.hnt"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.p"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.p"&lt;br /&gt; [     Sophos       ], "Mal/Behav-160"&lt;br /&gt; [     CAV          ], "Win32/Dowque.TE"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.GJV trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.hnt"&lt;br /&gt; [     Norman       ], "Trojan W32/Smalltroj.BNNK"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Agent.jp"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hnt"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     Authentium   ], "W32/Threat-SysVenFakU-based!Maximus"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.WoW.3D61ACDF"&lt;br /&gt; [     CAV Beta     ], "Win32/Dowque.TE"&lt;br /&gt;yoyhrajsbk.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPH"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, PAK:PE_Patch.MaskPE, Trojan-PSW.Win32.OnLineGames.hnt"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.p"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.p"&lt;br /&gt; [     Sophos       ], "Mal/Behav-160"&lt;br /&gt; [     CAV          ], "Win32/Dowque.TE"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.GJV trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.hnt"&lt;br /&gt; [     Norman       ], "Trojan W32/Smalltroj.BNNK"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Agent.jp"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hnt"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     Authentium   ], "W32/Threat-SysVenFakU-based!Maximus"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.WoW.3D61ACDF"&lt;br /&gt; [     CAV Beta     ], "Win32/Dowque.TE"&lt;br /&gt;yzbhjx.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.gsx"&lt;br /&gt; [     McAfee       ], "PWS-Zhengtu.gen"&lt;br /&gt; [     McAfee_Beta  ], "PWS-Zhengtu.gen"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.tw"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.gsx"&lt;br /&gt; [     Ewido        ], "Trojan.OnLineGames.gsx"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.gsx"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.B5204919"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;zu[3].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;_uninsep.bat:&lt;br /&gt; [     Alpha_Gen    ], "AP_DELME"&lt;br /&gt; [     Beta_Gen     ], "AP_DELME"&lt;br /&gt;1[1].htm:&lt;br /&gt; [     McAfee       ], "VBS/Psyme"&lt;br /&gt; [     McAfee_Beta  ], "VBS/Psyme"&lt;br /&gt; [     Sophos       ], "Mal/Psyme-A"&lt;br /&gt; [     HBEDV        ], "HTML/ADODB.Exploit.Gen"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.XPL.ADODB.E9AD757A"&lt;br /&gt;1[2].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     McAfee       ], "VBS/Psyme"&lt;br /&gt; [     McAfee_Beta  ], "VBS/Psyme"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HTML/ADODB.Exploit.Gen"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.XPL.ADODB.CFD45297"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;2[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;3[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;4[1].htm:&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;10Sy.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Shelx"&lt;br /&gt; [     Symantec     ], "W32.Gammima.AG"&lt;br /&gt; [     Kaspersky    ], "PAK:UPX, Trojan-PSW.Win32.QQPass.alx"&lt;br /&gt; [     McAfee       ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     McAfee_Beta  ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     CAV          ], "Win32/QQPass!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     HBEDV        ], "DR/Delphi.Gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Nilage.bga"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     quickheal    ], "Win32.Trojan-PSW.QQPass.wm"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWStealer.8FAD2DC8"&lt;br /&gt; [     CAV Beta     ], "Win32/QQPass!generic"&lt;br /&gt;11[1].js:&lt;br /&gt; [     HBEDV        ], "JS/Dldr.Agent.YA"&lt;br /&gt;014[1].js:&lt;br /&gt; [     Alpha_Gen    ], "Possible_EncScr"&lt;br /&gt; [     Beta_Gen     ], "Possible_EncScr"&lt;br /&gt;88[1].js:&lt;br /&gt; [     Alpha_Gen    ], "Possible_EncScr"&lt;br /&gt; [     Beta_Gen     ], "Possible_EncScr"&lt;br /&gt;881[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     McAfee       ], "VBS/Psyme"&lt;br /&gt; [     McAfee_Beta  ], "VBS/Psyme"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HTML/ADODB.Exploit.Gen"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.XPL.ADODB.E127D904"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;882[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, PAK:PE_Patch, Trojan-PSW.Win32.OnLineGames.idg"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.D673289C"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;882[1].htm:&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;8819[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.7B745937"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;124327M.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Lmir.boy"&lt;br /&gt; [     McAfee       ], "[000056d4.EXE]:PWS-LegMir"&lt;br /&gt; [     McAfee_Beta  ], "[000056d4.EXE]:PWS-LegMir"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/Behav-010"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.WOW.WU trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.LMir.yys"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.WOW.vd"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.16"&lt;br /&gt; [     Authentium   ], "W32/Blocker-based!Maximus"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt; [     bitdefender  ], "BehavesLike:Win32.ExplorerHijack"&lt;br /&gt;124327MM.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Lemir.G"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Lmir.BMR"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Lmir.boy"&lt;br /&gt; [     McAfee       ], "PWS-LegMir"&lt;br /&gt; [     McAfee_Beta  ], "PWS-LegMir"&lt;br /&gt; [     Sophos       ], "Mal/Behav-010"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.Legendmir.NFF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.LMir.yys"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Lmir.OK"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;555888:&lt;br /&gt; [     Symantec     ], "Infostealer.Lemir.G"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Lmir.BMR"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Lmir.boy"&lt;br /&gt; [     McAfee       ], "PWS-LegMir"&lt;br /&gt; [     McAfee_Beta  ], "PWS-LegMir"&lt;br /&gt; [     Sophos       ], "Mal/Behav-010"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.Legendmir.NFF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.LMir.yys"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Lmir.OK"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt;1358616[1].js:&lt;br /&gt; [     HBEDV        ], "JS/Iframe.B"&lt;br /&gt;6619038[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;a1.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Microsoft    ], "[-&gt;(FSG-v2.0)]:Trojan:Win32/Anomaly.gen!B"&lt;br /&gt; [     Kaspersky    ], "PAK:FSG, PAK:PEPatch"&lt;br /&gt; [     Sophos       ], "Mal/EncPk-AP"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Agent.43569"&lt;br /&gt; [     Norman       ], "Security Risk Suspicious_F.gen"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Delf.CSK"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;a4.exe:&lt;br /&gt; [     Alpha_Gen    ], "BASE_BANLOAD-A2"&lt;br /&gt; [     Beta_Gen     ], "AP_Banld-1"&lt;br /&gt; [     Kaspersky    ], "Trojan-Downloader.Win32.Delf.aas"&lt;br /&gt; [     McAfee       ], "Generic Downloader.c"&lt;br /&gt; [     McAfee_Beta  ], "Generic Downloader.c"&lt;br /&gt; [     CAV          ], "Win32/Kemdorm.B"&lt;br /&gt; [     Nod32        ], "Win32/TrojanDownloader.SMW.A trojan"&lt;br /&gt; [     Fortinet     ], "W32/Delf.AAS!tr.dldr"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/FileInfector"&lt;br /&gt; [     Rising       ], "Trojan.DL.Delf.xxb"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Delf.aas"&lt;br /&gt; [     eAladdin     ], "Win32.Agent.xi"&lt;br /&gt; [     quickheal    ], "TrojanDownloader.Delf.vw"&lt;br /&gt; [     Authentium   ], "W32/NewMalware-LSU-based!Maximus"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt; [     bitdefender  ], "Trojan.Downloader.OH"&lt;br /&gt; [     CAV Beta     ], "Win32/Kemdorm.B"&lt;br /&gt;a6.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Shelx"&lt;br /&gt; [     Symantec     ], "W32.Gammima.AG"&lt;br /&gt; [     Kaspersky    ], "PAK:UPX, Trojan-PSW.Win32.QQPass.alx"&lt;br /&gt; [     McAfee       ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     McAfee_Beta  ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     CAV          ], "Win32/QQPass!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     HBEDV        ], "DR/Delphi.Gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Nilage.bga"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     quickheal    ], "Win32.Trojan-PSW.QQPass.wm"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWStealer.8FAD2DC8"&lt;br /&gt; [     CAV Beta     ], "Win32/QQPass!generic"&lt;br /&gt;ac[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;autorun.inf:&lt;br /&gt; [     Alpha_Gen    ], "Possible_Otorun1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Otorun1"&lt;br /&gt; [     McAfee       ], "Generic!atr"&lt;br /&gt; [     McAfee_Beta  ], "Generic!atr"&lt;br /&gt; [     CAV          ], "INF/Rodvir.Y"&lt;br /&gt; [     Nod32        ], "Win32/AutoRun.NAB virus"&lt;br /&gt; [     Ikarus       ], "Trojan.Autorun.F"&lt;br /&gt; [     bitdefender  ], "Trojan.Autorun.F"&lt;br /&gt; [     CAV Beta     ], "INF/Rodvir.Y"&lt;br /&gt;AVPSrv.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hhn"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GGK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GGK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnlineGames.SUM!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.SO2Game.d"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     Ewido        ], "Trojan.OnLineGames.hhn"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hhn"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.CD352155"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;avwgemn.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "Trojan:Win32/Delf.AT!dll"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.icf"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.a.dll"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.a.dll"&lt;br /&gt; [     Sophos       ], "Mal/Gampass-A"&lt;br /&gt; [     CAV          ], "Win32/Storark!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.FDY trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Trojan OnLineGames.gen34"&lt;br /&gt; [     Ikarus       ], "BehavesLikeTrojan.WUDisable"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "BehavesLike:Trojan.WUDisable"&lt;br /&gt; [     CAV Beta     ], "Win32/Storark!generic"&lt;br /&gt;avwgest.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:Trojan:Win32/SystemHijack.gen"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.icf"&lt;br /&gt; [     McAfee       ], "New Malware.n !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.n !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Storark!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.FDY trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Delf.uv"&lt;br /&gt; [     Ewido        ], "Trojan.OnLineGames.eza"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "Win32.Trojan-PSW.OnLineGames.gux"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.Malware.SBdldg.C2F0B86A"&lt;br /&gt; [     CAV Beta     ], "Win32/Storark!generic"&lt;br /&gt;avzxfmn.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "Trojan:Win32/Delf.AT!dll"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hcx"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.i"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.i"&lt;br /&gt; [     Sophos       ], "Mal/Gampass-A"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Storark!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.FDY trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnLineGa.gcp"&lt;br /&gt; [     Norman       ], "Trojan W32/Smalltroj.BMYL"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.wh"&lt;br /&gt; [     Ikarus       ], "BehavesLikeTrojan.WUDisable"&lt;br /&gt; [     Ewido        ], "Trojan.OnLineGames.hcx"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hcx"&lt;br /&gt; [     vba32        ], "Trojan-PSW.Win32.OnLineGames.hcx"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.PWS.OnlineGames.NMT"&lt;br /&gt; [     CAV Beta     ], "Win32/Storark!generic"&lt;br /&gt;bf[1].htm:&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;boc.sbb22[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;bpfuxa.dll:&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.iai"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aht"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.ibz"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;cmdbcs.dll:&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.73006256"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;comrepl32.exe:&lt;br /&gt; [     Kaspersky    ], "Worm.Win32.Downloader.at"&lt;br /&gt; [     Panda        ], "Trj/Downloader.RER"&lt;br /&gt; [     Panda_Beta   ], "Trj/Downloader.RER"&lt;br /&gt; [     Nod32        ], "Win32/Jalous.M worm"&lt;br /&gt; [     Rising       ], "Trojan.Win32.Agent.zzl"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.Inject.ES"&lt;br /&gt;cselnf.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Lmir.BMQ"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.icp"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.icp"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aiz"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DbgHlp32.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnlineGames.SUM!tr.pws"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.9F7D5E5E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DbgHlp32.exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.7B745937"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;djatl.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;du66[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Symantec     ], "Downloader"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;DVBBack01.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DVBBack02.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DVBBack03.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DVBBack04.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DVBBack05.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DVBBack06.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DVBBack07.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DVBBack08.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyf"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJD"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJD"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeo"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.979D208E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;dyy[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;ewgqyirajt.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPH"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, PAK:PE_Patch.MaskPE, Trojan-PSW.Win32.OnLineGames.hnt"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.p"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.p"&lt;br /&gt; [     Sophos       ], "Mal/Behav-160"&lt;br /&gt; [     CAV          ], "Win32/Dowque.TE"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.GJV trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.hnt"&lt;br /&gt; [     Norman       ], "Trojan W32/Smalltroj.BNNK"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Agent.jp"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hnt"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     Authentium   ], "W32/Threat-SysVenFakU-based!Maximus"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.WoW.3D61ACDF"&lt;br /&gt; [     CAV Beta     ], "Win32/Dowque.TE"&lt;br /&gt;feibgp.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnlineGames.SUM!tr.pws"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.9F7D5E5E"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;fngvgs.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Lmir.BMQ"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.icp"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.icp"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aiz"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;g3[1].htm:-escape&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;gdwli32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;gdwmi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;gdzxi32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.j"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.j"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Suspicious file"&lt;br /&gt; [     Panda_Beta   ], "Suspicious file"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;GenProtect.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Lmir.BMQ"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJL"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJL"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.ahc"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPWS.OnLineGames.gen"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.PWS.OnLineGames.NHL"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;go[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;gzvjnw.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.iax"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnlineGames.SUM!tr.pws"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aha"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.C1B879DE"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;haha[1].htm:&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;htm[2].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;iqxxie.dll:&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.idg"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.ibz"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;kaqhizy.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "Trojan:Win32/Delf.AT!dll"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.idb"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.q"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.q"&lt;br /&gt; [     CAV          ], "Win32/Storark!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.FDY trojan"&lt;br /&gt; [     Norman       ], "Trojan OnLineGames.gen34"&lt;br /&gt; [     Ikarus       ], "BehavesLikeTrojan.WUDisable"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Dld.Agent.3ED364A8"&lt;br /&gt; [     CAV Beta     ], "Win32/Storark!generic"&lt;br /&gt;KVBatch01.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Nilage.bue"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJC"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJC"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NII trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aem"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Nilage.bty"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.8785A033"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;KVBatch02.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Nilage.bue"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJC"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJC"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NII trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aem"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Nilage.bty"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.8785A033"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;KVBatch03.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Nilage.bue"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJC"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJC"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NII trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aem"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Nilage.bty"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.8785A033"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;KVBatch04.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Nilage.bue"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJC"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJC"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NII trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aem"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Nilage.bty"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.8785A033"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;KVBatch05.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Nilage.bue"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJC"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJC"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NII trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aem"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Nilage.bty"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.8785A033"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;KVBatch06.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Nilage.bue"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJC"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJC"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NII trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aem"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Nilage.bty"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.8785A033"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;KVBatch07.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.Nilage.bue"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJC"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJC"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NII trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aem"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     quickheal    ], "TrojanPSW.Nilage.bty"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.8785A033"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;kvdxjma.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "Trojan:Win32/Delf.AT!dll"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.idh"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.i"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.i"&lt;br /&gt; [     CAV          ], "Win32/Storark!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.FDY trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Trojan OnLineGames.gen34"&lt;br /&gt; [     Ikarus       ], "BehavesLikeTrojan.WUDisable"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "BehavesLike:Trojan.WUDisable"&lt;br /&gt; [     CAV Beta     ], "Win32/Storark!generic"&lt;br /&gt;llllllab:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Aspack v2.12)]:Trojan:Win32/SystemHijack.gen"&lt;br /&gt; [     Kaspersky    ], "PAK:ASPack, Trojan-PSW.Win32.Lmir.boy"&lt;br /&gt; [     McAfee       ], "[0000b6d4.EXE]:PWS-LegMir"&lt;br /&gt; [     McAfee_Beta  ], "[0000b6d4.EXE]:PWS-LegMir"&lt;br /&gt; [     Sophos       ], "[FILE:0000]:Mal/Behav-010"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.WOW.WU trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "[Heuristic Sandbox detection]:Virus W32/Malware"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.WOW.vd"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.16"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.6590ADAF"&lt;br /&gt;mppds.dll:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Wowsteal.XQ"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.iaf"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.ahq"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.es"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.3CF9FCB6"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;mppds.exe:&lt;br /&gt; [     Microsoft    ], "Trojan:Win32/Frethog.V"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.iat"&lt;br /&gt; [     Sophos       ], "Mal/Dropper-P"&lt;br /&gt; [     Panda        ], "Trj/Lineage.FWB"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.FWB"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.ahw"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.DEC6BA02"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ms33[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;MSDEG32.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.hpp"&lt;br /&gt; [     McAfee       ], "PWS-LegMir.dll"&lt;br /&gt; [     McAfee_Beta  ], "PWS-LegMir.dll"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJM"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJM"&lt;br /&gt; [     CAV          ], "Win32/Lolyda!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.DVV trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.Online.gyo.2"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Generic.PWS.Games.3"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hpp"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.3.BFA150F9"&lt;br /&gt; [     CAV Beta     ], "Win32/Lolyda!generic"&lt;br /&gt;MsPrint32D.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hcv"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GGK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GGK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.HCV!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnLineGa.hcv"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.QQSG.z"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.hcv"&lt;br /&gt; [     Ewido        ], "Trojan.OnLineGames.hcv"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hcv"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.Malware.dldPWS.BA9B9194"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;myirclucmv.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPH"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, PAK:PE_Patch.MaskPE, Trojan-PSW.Win32.OnLineGames.hnt"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.p"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.p"&lt;br /&gt; [     Sophos       ], "Mal/Behav-160"&lt;br /&gt; [     CAV          ], "Win32/Dowque.TE"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.GJV trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.hnt"&lt;br /&gt; [     Norman       ], "Trojan W32/Smalltroj.BNNK"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Agent.jp"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hnt"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     Authentium   ], "W32/Threat-SysVenFakU-based!Maximus"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.WoW.3D61ACDF"&lt;br /&gt; [     CAV Beta     ], "Win32/Dowque.TE"&lt;br /&gt;naktcmvdmv.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPH"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.iab"&lt;br /&gt; [     Sophos       ], "Mal/Behav-160"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.GJV trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.OnlineGames.iab"&lt;br /&gt; [     Norman       ], "Trojan W32/OnLineGames.VFL"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Agent.jp"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     Authentium   ], "W32/Threat-SysVenFakU-based!Maximus"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.WoW.02019683"&lt;br /&gt;new82[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Sophos       ], "Mal/Iframe-A"&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt;newbala[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     Authentium   ], "HTML/IFrame"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;nn[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;NvSys_54.Sys:&lt;br /&gt; [     Microsoft    ], "PWS:Win32/QQGame.B.dll"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.QQPass.alx"&lt;br /&gt; [     McAfee       ], "PWS-QQGame"&lt;br /&gt; [     McAfee_Beta  ], "PWS-QQGame"&lt;br /&gt; [     CAV          ], "Win32/QQPass!generic"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Trojan W32/QQPass.gen5"&lt;br /&gt; [     Rising       ], "Worm.Win32.PaBug.dt"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Nilage.bga"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     Authentium   ], "W32/InfoStealer!Generic"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWStealer.D5472FD3"&lt;br /&gt; [     CAV Beta     ], "Win32/QQPass!generic"&lt;br /&gt;NvSys_54.Tao&lt;br /&gt; [     Microsoft    ], "PWS:Win32/QQGame.B.dll"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.QQPass.alx"&lt;br /&gt; [     McAfee       ], "PWS-QQGame"&lt;br /&gt; [     McAfee_Beta  ], "PWS-QQGame"&lt;br /&gt; [     CAV          ], "Win32/QQPass!generic"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Norman       ], "Trojan W32/QQPass.gen5"&lt;br /&gt; [     Rising       ], "Worm.Win32.PaBug.dt"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Nilage.bga"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     Authentium   ], "W32/InfoStealer!Generic"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Generic.PWStealer.D5472FD3"&lt;br /&gt; [     CAV Beta     ], "Win32/QQPass!generic"&lt;br /&gt;NvWin_5.Jmp&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Shelx"&lt;br /&gt; [     Symantec     ], "W32.Gammima.AG"&lt;br /&gt; [     Kaspersky    ], "PAK:UPX, Trojan-PSW.Win32.QQPass.alx"&lt;br /&gt; [     McAfee       ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     McAfee_Beta  ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     CAV          ], "Win32/QQPass!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     HBEDV        ], "DR/Delphi.Gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Nilage.bga"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     quickheal    ], "Win32.Trojan-PSW.QQPass.wm"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWStealer.8FAD2DC8"&lt;br /&gt; [     CAV Beta     ], "Win32/QQPass!generic"&lt;br /&gt;old[1].js:&lt;br /&gt; [     Alpha_Gen    ], "Possible_EncScr"&lt;br /&gt; [     Beta_Gen     ], "Possible_EncScr"&lt;br /&gt; [     Kaspersky    ], "PAK:JSPack, PAK:JSPack, unknown format."&lt;br /&gt;pcibus.sys:&lt;br /&gt; [     Symantec     ], "W32.Fujacks.L"&lt;br /&gt; [     Kaspersky    ], "Worm.Win32.Downloader.aw"&lt;br /&gt; [     Sophos       ], "[FILE:0000\FILE:0000]:Mal/Behav-160"&lt;br /&gt; [     Panda        ], "Trj/Downloader.RER"&lt;br /&gt; [     Panda_Beta   ], "Trj/Downloader.RER"&lt;br /&gt; [     Nod32        ], "Win32/Jalous.M worm"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dldr.Agent.45056"&lt;br /&gt; [     Norman       ], "Trojan W32/Malware.BGGP"&lt;br /&gt; [     Rising       ], "Trojan.Win32.Mnless.zjb"&lt;br /&gt; [     Ikarus       ], "Worm.Win32.Downloader.aw"&lt;br /&gt; [     quickheal    ], "Worm.Downloader.aw"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.Exploit.Dcomrpc.AW"&lt;br /&gt;pps[1].htm:-eval&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     Beta_Gen     ], "Possible_EncScr"&lt;br /&gt; [     Microsoft    ], "[-&gt;(IframeRefI)]:Exploit:HTML/IframeRef.gen"&lt;br /&gt; [     Kaspersky    ], "Trojan-Clicker.HTML.IFrame.cw"&lt;br /&gt; [     Sophos       ], "Troj/Fujif-Gen"&lt;br /&gt; [     CAV          ], "HTML/Sauratol.B virus. "&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Rising       ], "Trojan.DL.Ieframe.co"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.IFrame.W"&lt;br /&gt; [     CAV Beta     ], "HTML/Sauratol.B virus. "&lt;br /&gt;ProcSvr01.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyi"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GIS"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GIS"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.afs"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.E8CA9FC5"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ProcSvr02.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyi"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GIS"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GIS"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.afs"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.E8CA9FC5"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ProcSvr03.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyi"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GIS"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GIS"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.afs"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.E8CA9FC5"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ProcSvr04.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyi"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GIS"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GIS"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.afs"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.E8CA9FC5"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ProcSvr05.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyi"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GIS"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GIS"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.afs"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.E8CA9FC5"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ProcSvr06.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyi"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GIS"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GIS"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.afs"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.E8CA9FC5"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;ProcSvr07.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyi"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GIS"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GIS"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.afs"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.E8CA9FC5"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;qqhxatl.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.Generic.64525"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;qqsgatl.dll:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Crypt-6"&lt;br /&gt; [     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt; [     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.hkz"&lt;br /&gt; [     McAfee       ], "PWS-OnlineGames.r"&lt;br /&gt; [     McAfee_Beta  ], "PWS-OnlineGames.r"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt; [     Fortinet     ], "W32/OnLineGames.HKZ!tr.pws"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Small.br"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.hkz"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.Generic.72308"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;sha1[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;soft01[1].exe:&lt;br /&gt; [     Microsoft    ], "Trojan:Win32/Frethog.V"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.iat"&lt;br /&gt; [     Sophos       ], "Mal/Dropper-P"&lt;br /&gt; [     Panda        ], "Trj/Lineage.FWB"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.FWB"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.ahw"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.1.DEC6BA02"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;soft03[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Lmir.BMQ"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.iap"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJP"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJP"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.YA trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Virus W32/Viking.EQ"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Agent.hz"&lt;br /&gt; [     eAladdin     ], "Suspicious File [108]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.BE33B294"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;soft06[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, PAK:PE_Patch, Trojan-PSW.Win32.OnLineGames.gti"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GDZ"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GDZ"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt; [     Norman       ], "Trojan W32/Zlob.ASQV"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     quickheal    ], "TrojanPSW.OnLineGames.gti"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.495BF3B4"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;soft07[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPK"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hqh"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Pux.d"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.AVKill.AR"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;soft09[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, PAK:PE_Patch, Trojan-PSW.Win32.OnLineGames.iau"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt; [     eAladdin     ], "Suspicious File [104]"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWS.Games.4.4E40F482"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;soft10[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "Possible_Shelx"&lt;br /&gt; [     Symantec     ], "W32.Gammima.AG"&lt;br /&gt; [     Kaspersky    ], "PAK:UPX, Trojan-PSW.Win32.QQPass.alx"&lt;br /&gt; [     McAfee       ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     McAfee_Beta  ], "[0000a4f8.EXE]:PWS-QQGame"&lt;br /&gt; [     CAV          ], "Win32/QQPass!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     HBEDV        ], "DR/Delphi.Gen"&lt;br /&gt; [     Ikarus       ], "Trojan-PWS.Win32.Nilage.bga"&lt;br /&gt; [     eAladdin     ], "Suspicious File [101]"&lt;br /&gt; [     quickheal    ], "Win32.Trojan-PSW.QQPass.wm"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.7"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Gen"&lt;br /&gt; [     bitdefender  ], "Generic.PWStealer.8FAD2DC8"&lt;br /&gt; [     CAV Beta     ], "Win32/QQPass!generic"&lt;br /&gt;soft13[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Lmir.BMO"&lt;br /&gt; [     Kaspersky    ], "PAK:UPack, Trojan-Downloader.Win32.Delf.axx"&lt;br /&gt; [     McAfee       ], "New Malware.n !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.n !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     Nod32        ], "a variant of Win32/PSW.WOW.WU trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/Delphi.Downloader.Gen"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Dropper.Win32.Agent.ane"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     quickheal    ], "Win32.Trojan-PSW.QQPass.xw"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.16"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "Trojan.Delphi.Downloader.Gen"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.PWS.Games.4.D58E055D"&lt;br /&gt;soft14[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPK"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hqh"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/PSW.Onlineg.KC.2"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Downloader.Win32.Pux.d"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     vba32        ], "Trojan-PSW.Win32.OnLineGames.hqh"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.AVKill.AR"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;soft15[1].exe:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt; [     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/OnLineGames.CPK"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hqh"&lt;br /&gt; [     McAfee       ], "New Malware.aj !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt; [     Sophos       ], "Mal/Packer"&lt;br /&gt; [     CAV          ], "Win32/Zuten!generic"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt; [     Fortinet     ], "suspicious"&lt;br /&gt; [     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt; [     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt; [     Ikarus       ], "Trojan-Spy.Win32.Delf.PD"&lt;br /&gt; [     eAladdin     ], "Suspicious File [100]"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Trojan.AVKill.AR"&lt;br /&gt; [     CAV Beta     ], "Win32/Zuten!generic"&lt;br /&gt;SQLLink01.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.666E4001"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;SQLLink02.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.666E4001"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;SQLLink03.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.666E4001"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;SQLLink04.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.666E4001"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;SQLLink05.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.666E4001"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;SQLLink06.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.666E4001"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;SQLLink07.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt; [     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "DeepScan:Generic.Onlinegames.2.666E4001"&lt;br /&gt; [     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;SQLLink08.dll:&lt;br /&gt; [     Symantec     ], "Infostealer.Gampass"&lt;br /&gt; [     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt; [     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.hyr"&lt;br /&gt; [     Sophos       ], "Mal/Behav-156"&lt;br /&gt; [     Panda        ], "Trj/Lineage.GJK"&lt;br /&gt; [     Panda_Beta   ], "Trj/Lineage.GJK"&lt;br /&gt; [     CAV          ], "Win32/Frethog!generic"&lt;br /&gt; [     Nod32        ], "Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt; [     HBEDV        ], "HEUR/Malware"&lt;br /&gt; [     Rising       ], "Trojan.PSW.Win32.GameOnline.aeq"&lt;br /&gt; [     Ikarus       ], "Virus.Win32.Nilage.JY"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8828264752372659880?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8828264752372659880/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8828264752372659880' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8828264752372659880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8828264752372659880'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_2721.html' title='政大統計系系友會網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0I5JUEHewI/AAAAAAAAA5A/JIowpbE7eRE/s72-c/stat_nccu_edu_home_20071120.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8554169317093153132</id><published>2007-11-20T09:11:00.000+08:00</published><updated>2007-11-20T09:25:16.716+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>僑光應用華語文系網站被植入惡意連結</title><content type='html'>僑光應用華語文系網站被植入惡意連結，此惡意程式為 Trojan-PSW.Win32.OnLineGames&lt;div style="direction: ltr;"&gt;&lt;wbr&gt;.idg，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;/div&gt;&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0I0lEEHeuI/AAAAAAAAA4w/0DsaCqbQHZc/s1600-h/ocit_edu_tw_home_20071120.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0I0lEEHeuI/AAAAAAAAA4w/0DsaCqbQHZc/s320/ocit_edu_tw_home_20071120.png" alt="" id="BLOGGER_PHOTO_ID_5134724336506600162" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0I0yUEHevI/AAAAAAAAA44/hVjYHU8YhUc/s1600-h/ocit_edu_malurl_20071120.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/R0I0yUEHevI/AAAAAAAAA44/hVjYHU8YhUc/s320/ocit_edu_malurl_20071120.png" alt="" id="BLOGGER_PHOTO_ID_5134724564139866866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\DbgHlp32.dll&lt;br /&gt;C:\WINDOWS\system32\upxdnd.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: PciHardDisk&lt;br /&gt;DISPLAY: PciHardDisk&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\pcidisk.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\Microsoft.vbs&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\2[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\e19[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ee1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ee2[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\go[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\sa[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\xm22[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\3[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\4[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\click[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\eeecom[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\mianeeecom[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\psasnbf[1].gif&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1364595[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\6[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\ac[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\bb[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\cj[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\e2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\e[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\login[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1358616[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\5[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\7[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\bf[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\common[1].htm&lt;br /&gt;C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;C:\WINDOWS\system32\Com\comrepl32.exe&lt;br /&gt;C:\WINDOWS\system32\CRYPSERV.EXE&lt;br /&gt;C:\WINDOWS\system32\DbgHlp32.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\pcibus.sys&lt;br /&gt;C:\WINDOWS\system32\upxdnd.dll&lt;br /&gt;C:\WINDOWS\upxdnd.exe&lt;br /&gt;C:\WINDOWS\~tmp9493.exe&lt;br /&gt;C:\WINDOWS\~tmp9591.exe&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=upxdnd&lt;br /&gt;Data=C:\WINDOWS\upxdnd.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=DbgHlp32&lt;br /&gt;Data=C:\WINDOWS\DbgHlp32.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/19 @ 13:50)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;e[1].js:&lt;br /&gt;[     Kaspersky    ], "Trojan-Downloader.JS.Small.ie"&lt;br /&gt;ee1[1].htm:&lt;br /&gt;[     McAfee       ], "VBS/Psyme"&lt;br /&gt;[     McAfee_Beta  ], "VBS/Psyme"&lt;br /&gt;[     Sophos       ], "Mal/Psyme-A"&lt;br /&gt;[     HBEDV        ], "HTML/ADODB.Exploit.Gen"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;[     bitdefender  ], "Generic.XPL.ADODB.D6239DC6"&lt;br /&gt;ee2[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;Microsoft.vbs:&lt;br /&gt;[     Kaspersky    ], "Trojan.VBS.Runner.o"&lt;br /&gt;[     HBEDV        ], "VBS/Runner.O.3"&lt;br /&gt;[     Ewido        ], "Trojan.Runner.o"&lt;br /&gt;[     vba32        ], "Trojan.VBS.Runner.o"&lt;br /&gt;[     Authentium   ], "VBS/WSRunner.I"&lt;br /&gt;[     WebWasher    ], "Script.Runner.O.3"&lt;br /&gt;pcibus.sys:&lt;br /&gt;[     Symantec     ], "W32.Fujacks.L"&lt;br /&gt;[     Microsoft    ], "Exploit:Win32/Siveras.E"&lt;br /&gt;[     Kaspersky    ], "Worm.Win32.Downloader.ay"&lt;br /&gt;[     Sophos       ], "[FILE:0000\FILE:0000]:Mal/Behav-160"&lt;br /&gt;[     Nod32        ], "a variant of Win32/Jalous worm"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Dldr.Agent.45056"&lt;br /&gt;[     Rising       ], "Trojan.Win32.Mnless.zjf"&lt;br /&gt;[     Ikarus       ], "Worm.Win32.Downloader.ay"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;upxdnd.dll:&lt;br /&gt;[     Kaspersky    ], "Trojan-PSW.Win32.OnLineGames.idg"&lt;br /&gt;[     CAV          ], "Win32/Frethog!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.HCV trojan"&lt;br /&gt;[     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt;[     Ikarus       ], "Trojan-PWS.Win32.OnLineGames.ibz"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.12"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;[     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;upxdnd.exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, PAK:PE_Patch, Trojan-PSW.Win32.OnLineGames.idg"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     Panda_Beta   ], "Suspicious file"&lt;br /&gt;[     CAV          ], "Win32/Frethog!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt;[     eAladdin     ], "Suspicious File [104]"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt;[     bitdefender  ], "Generic.PWS.Games.4.D673289C"&lt;br /&gt;[     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;xm22[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;5[1].htm:&lt;br /&gt;[     Ewido        ], "Trojan.Concon.b"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;7[1].htm:&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;1358616[1].js:&lt;br /&gt;[     HBEDV        ], "JS/Iframe.B"&lt;br /&gt;ac[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-2"&lt;br /&gt;[     Beta_Gen     ], "Possible_Hifrm"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;bb[1].js:&lt;br /&gt;[     HBEDV        ], "JS/Iframe.894"&lt;br /&gt;bf[1].htm:&lt;br /&gt;[     Kaspersky    ], "Trojan-Downloader.JS.Agent.aec"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;click[1].htm:&lt;br /&gt;[     Sophos       ], "Mal/Iframe-A"&lt;br /&gt;common[1].htm:&lt;br /&gt;[     Alpha_Gen    ], "Heur_Infrm-1"&lt;br /&gt;[     Sophos       ], "Mal/Iframe-A"&lt;br /&gt;[     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt;comrepl32.exe:&lt;br /&gt;[     Kaspersky    ], "Worm.Win32.Downloader.ay"&lt;br /&gt;[     Nod32        ], "a variant of Win32/Jalous worm"&lt;br /&gt;[     Rising       ], "Trojan.Win32.Mnless.zjg"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;DbgHlp32.dll:&lt;br /&gt;[     Microsoft    ], "PWS:Win32/Frethog.gen!B"&lt;br /&gt;[     CAV          ], "Win32/Frethog!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt;[     Fortinet     ], "W32/OnlineGames.SUM!tr.pws"&lt;br /&gt;[     HBEDV        ], "HEUR/Malware"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.1"&lt;br /&gt;[     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;[     bitdefender  ], "DeepScan:Generic.PWS.Games.1.9F7D5E5E"&lt;br /&gt;[     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;DbgHlp32.exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Behav-156"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     Panda_Beta   ], "Suspicious file"&lt;br /&gt;[     CAV          ], "Win32/Frethog!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt;[     eAladdin     ], "Suspicious File [104]"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt;[     bitdefender  ], "Generic.PWS.Games.4.7B745937"&lt;br /&gt;[     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;e2[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, PAK:PE_Patch, Trojan-PSW.Win32.OnLineGames.idg"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     Panda_Beta   ], "Suspicious file"&lt;br /&gt;[     CAV          ], "Win32/Frethog!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Spy.Gen"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt;[     eAladdin     ], "Suspicious File [104]"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt;[     bitdefender  ], "Generic.PWS.Games.4.D673289C"&lt;br /&gt;[     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;e19[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Microsoft    ], "[-&gt;(Upack)]:PWS:Win32/Frethog.gen!D"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Behav-156"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     Panda_Beta   ], "Suspicious file"&lt;br /&gt;[     CAV          ], "Win32/Frethog!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFL trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/Dropper.Gen"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Ikarus       ], "Trojan-Downloader.Win32.Zlob.and"&lt;br /&gt;[     eAladdin     ], "Suspicious File [104]"&lt;br /&gt;[     vba32        ], "MalwareScope.Trojan-PSW.Game.3"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     WebWasher    ], "Trojan.Dropper.Gen"&lt;br /&gt;[     bitdefender  ], "Generic.PWS.Games.4.7B745937"&lt;br /&gt;[     CAV Beta     ], "Win32/Frethog!generic"&lt;br /&gt;eeecom[1].exe:&lt;br /&gt;[ Trend ], "WORM_DLOADER.QFD"&lt;br /&gt;mianeeecom[1].exe:&lt;br /&gt;[ Trend ], "WORM_DLOADER.QFD"&lt;br /&gt;svchost.exe:&lt;br /&gt;[ Trend ], "WORM_DLOADER.QFD"&lt;br /&gt;~tmp9493.exe:&lt;br /&gt;[ Trend ], "WORM_DLOADER.QFD"&lt;br /&gt;~tmp9591.exe:&lt;br /&gt;[ Trend ], "WORM_DLOADER.QFD"&lt;br /&gt;1[1].htm:&lt;br /&gt;[ Trend ], "HTML_DLOADER.RUD"&lt;br /&gt;2[1].htm:&lt;br /&gt;[ Trend ], "JS_PSYME.BBA"&lt;br /&gt;4[1].htm:&lt;br /&gt;[ Trend ], "HTML_DLOADER.QZC"&lt;br /&gt;6[1].htm:&lt;br /&gt;[ Trend ], "VBS_PSYME.BAZ"&lt;br /&gt;cj[1].exe:&lt;br /&gt;[ Trend ], "Possible_Mlwr-15"&lt;br /&gt;CRYPSERV.EXE:&lt;br /&gt;[ Trend ], "ossible_Mlwr-15"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8554169317093153132?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8554169317093153132/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8554169317093153132' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8554169317093153132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8554169317093153132'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_20.html' title='僑光應用華語文系網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_JNaO8YWc9rQ/R0I0lEEHeuI/AAAAAAAAA4w/0DsaCqbQHZc/s72-c/ocit_edu_tw_home_20071120.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2633961998229883660</id><published>2007-11-14T09:05:00.000+08:00</published><updated>2007-11-14T09:18:17.898+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>中國國民黨網站又被植入惡意連結  :-(</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;注意：此惡意檔案放置在國民黨網站中，所以，『網站信譽評等技術』有可能失效。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;中國國民黨網站又被植入惡意連結，此惡意程式為 Backdoor.Win32.PcClient.bal 或 Rootkit/PcClient.FK，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/RzpLPJDuoyI/AAAAAAAAA4g/08FSshQsWGA/s1600-h/kmt_home_20071114.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/RzpLPJDuoyI/AAAAAAAAA4g/08FSshQsWGA/s320/kmt_home_20071114.png" alt="" id="BLOGGER_PHOTO_ID_5132497448843780898" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結/程式碼是放置在 main.asp (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/RzpLaJDuozI/AAAAAAAAA4o/WmcW5K1Kk_o/s1600-h/kmt_malurl_20071114.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/RzpLaJDuozI/AAAAAAAAA4o/WmcW5K1Kk_o/s320/kmt_malurl_20071114.png" alt="" id="BLOGGER_PHOTO_ID_5132497637822341938" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\system32\clrptm.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: yysjstwz&lt;br /&gt;DISPLAY: yysjstwz&lt;br /&gt;FILE: \??\C:\WINDOWS\system32\drivers\clrptm.sys&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\temp003[1].jpg&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\category1_1_1_4_3[1].htm&lt;br /&gt;C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb&lt;br /&gt;C:\WINDOWS\system32\clrptm.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\clrptm.sys&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/14 @ 09:00)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;clrptm.dll:&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, Backdoor.Win32.PcClient.bal"&lt;br /&gt; [     Sophos       ], "Mal/Behav-024"&lt;br /&gt; [     Nod32        ], "probably a variant of Win32/Genetik trojan"&lt;br /&gt; [     vba32        ], "Trojan-Downloader.Win32.Delf.ain"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Backdoor.Agent.YYF"&lt;br /&gt;clrptm.sys:&lt;br /&gt; [     Alpha_Gen    ], "Possible_Rootkit"&lt;br /&gt; [     Kaspersky    ], "Rootkit.Win32.Agent.iz"&lt;br /&gt; [     McAfee       ], "New Malware.an !!"&lt;br /&gt; [     McAfee_Beta  ], "New Malware.an !!"&lt;br /&gt; [     Panda        ], "Rootkit/PcClient.FK"&lt;br /&gt; [     Panda_Beta   ], "Rootkit/PcClient.FK"&lt;br /&gt; [     Nod32        ], "probably unknown NewHeur_PE virus [7]"&lt;br /&gt; [     HBEDV        ], "TR/Rootkit.Gen"&lt;br /&gt; [     Rising       ], "RootKit.Win32.Agent.nhx"&lt;br /&gt; [     quickheal    ], "Rootkit.Agent.iz"&lt;br /&gt; [     WebWasher    ], "Trojan.Rootkit.Gen"&lt;br /&gt;temp003[1].jpg:&lt;br /&gt; [     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt; [     Kaspersky    ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, Backdoor.Win32.PcClient.aid"&lt;br /&gt; [     Ikarus       ], "Backdoor.Win32.PcClient.yw"&lt;br /&gt; [     vba32        ], "Trojan.Win32.Agent.ckf"&lt;br /&gt; [     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt; [     bitdefender  ], "Backdoor.Generic.25313"&lt;br /&gt;category1_1_1_4_3[1].htm:&lt;br /&gt; [     Alpha_Gen    ], "Possible_EncScr"&lt;br /&gt; [     Beta_Gen     ], "Possible_EncScr"&lt;br /&gt; [     Microsoft    ], "[-&gt;(SCRIPT0001)]:Worm:VBS/VBSWG.gen"&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     WebWasher    ], "BlockReason.46 (suspicious)"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2633961998229883660?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2633961998229883660/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2633961998229883660' title='4 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2633961998229883660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2633961998229883660'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_14.html' title='中國國民黨網站又被植入惡意連結  :-('/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_JNaO8YWc9rQ/RzpLPJDuoyI/AAAAAAAAA4g/08FSshQsWGA/s72-c/kmt_home_20071114.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-2632598194089220484</id><published>2007-11-12T23:21:00.000+08:00</published><updated>2007-11-12T23:30:32.620+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>幸運草網站又被植入惡意連結</title><content type='html'>幸運草網站又被植入惡意連結，此惡意程式為 TROJ_GENETIK.GM，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/RzhwoJDuowI/AAAAAAAAA4Q/JVs7aLo-JRg/s1600-h/clover-gold_home_20071112.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/RzhwoJDuowI/AAAAAAAAA4Q/JVs7aLo-JRg/s320/clover-gold_home_20071112.png" alt="" id="BLOGGER_PHOTO_ID_5131975610317316866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_JNaO8YWc9rQ/Rzhw2JDuoxI/AAAAAAAAA4Y/tZ4DJOIBBnk/s1600-h/clover-gold_malurl_20071112.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_JNaO8YWc9rQ/Rzhw2JDuoxI/AAAAAAAAA4Y/tZ4DJOIBBnk/s320/clover-gold_malurl_20071112.png" alt="" id="BLOGGER_PHOTO_ID_5131975850835485458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\WINDOWS\system32\msavpw0.dll&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\cn_Ajax[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\cn[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\cn[1].exe&lt;br /&gt;C:\WINDOWS\system32\msavpw0.dll&lt;br /&gt;&lt;br /&gt;[ Added COM/BHO ]&lt;br /&gt;{86AAC8D7-BA19-48AC-9269-3C76A52642EC}-C:\WINDOWS\system32\msavpw0.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/08 @ 13:39)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;msavpw0.dll:&lt;br /&gt;[ Trend ], "Possible_Strat-6"&lt;br /&gt;cn[1].exe:&lt;br /&gt;[ Trend ], "TROJ_GENETIK.GM"&lt;br /&gt;cn_Ajax[1].htm:&lt;br /&gt; [     Microsoft    ], "[-&gt;(SCRIPT0000)-&gt;(EmbeddedCode)-&gt;(SCRIPT0000)]:TrojanDownloader:VBS/Agent.EI"&lt;br /&gt; [     Fortinet     ], "VBS/Small.DR!tr.dldr"&lt;br /&gt; [     HBEDV        ], "HEUR/Exploit.HTML"&lt;br /&gt; [     Ewido        ], "Downloader.Agent.m"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-2632598194089220484?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/2632598194089220484/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=2632598194089220484' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2632598194089220484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/2632598194089220484'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_12.html' title='幸運草網站又被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JNaO8YWc9rQ/RzhwoJDuowI/AAAAAAAAA4Q/JVs7aLo-JRg/s72-c/clover-gold_home_20071112.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-726931347669132810</id><published>2007-11-08T10:31:00.000+08:00</published><updated>2007-11-08T11:01:46.509+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='安全漏洞'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><category scheme='http://www.blogger.com/atom/ns#' term='網站遭駭'/><title type='text'>心態不改  難保不會再被入侵</title><content type='html'>&lt;a href="http://www.libertytimes.com.tw/2007/new/nov/7/today-complain4.htm"&gt;這則新聞&lt;/a&gt;說明了現在大部分遭入侵企業的心態：&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;blockquote&gt;&lt;span style="color: rgb(51, 51, 255); font-style: italic;"&gt;此則新聞部分內容：&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255); font-style: italic;"&gt;〔記者吳幸樺／台南報導〕&lt;br /&gt;[...] 成大表示，由於這兩天圖書館進行評鑑，暫時將防火牆鬆綁，才會被駭客入侵，幸好駭客的目的只是惡作劇，並未損及電腦資料庫。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255); font-style: italic;"&gt;成功大學表示，這兩天學校在辦評鑑，地點就在圖書館，必須接收大批資料，將防火牆暫時鬆綁，沒想到竟給了駭客入侵的機會。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;&lt;span style="font-style: italic;"&gt;成大表示，[...]，幸好只是無傷的惡作劇，未造成資料被盜或系統受損。&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;ul&gt;&lt;li&gt;黑手遮天、粉飾太平：因為某種原因，所以，導致被入侵。意思是說，那些被入侵的企業根本沒有建立『資安事件標準處理程序』。&lt;/li&gt;&lt;li&gt;使用者的資料沒有被竊取：誰可以驗證他們所說的話呢？最好能立法強制企業須接受有能力之公正單位檢視，並公佈結果。&lt;br /&gt;&lt;/li&gt;&lt;li&gt;很少檢視系統有安全漏洞：根本沒有能力調查到底系統是如何被入侵？&lt;/li&gt;&lt;li&gt;我們已經安裝了相關的資安軟體：關鍵的問題不在到底安裝了多少資安軟體，而是在於會不會使用這些資安軟體，或是會不會分析這些資安軟體所產生的記錄檔。&lt;/li&gt;&lt;li&gt;...&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-726931347669132810?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/726931347669132810/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=726931347669132810' title='3 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/726931347669132810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/726931347669132810'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post_08.html' title='心態不改  難保不會再被入侵'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-8434595739974149429</id><published>2007-11-08T09:39:00.000+08:00</published><updated>2007-11-08T09:59:43.339+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>尖端科技軍事雜誌網站被植入惡意連結</title><content type='html'>尖端科技軍事雜誌網站被植入惡意連結，此惡意程式為 Trojan-PSW.Win32.OnLineGames&lt;div style="direction: ltr;"&gt;&lt;wbr&gt;.guz&lt;/div&gt;，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: Jimau)&lt;br /&gt;&lt;br /&gt;&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/RzJpc5DuouI/AAAAAAAAA4A/VyiYwt-uNuU/s1600-h/dtmonline_home_20071107.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/RzJpc5DuouI/AAAAAAAAA4A/VyiYwt-uNuU/s320/dtmonline_home_20071107.png" alt="" id="BLOGGER_PHOTO_ID_5130278870602130146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結是放置在 index.asp (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_JNaO8YWc9rQ/RzJpsJDuovI/AAAAAAAAA4I/GTxH7VNIZc4/s1600-h/dtmonline_malurl_20071107.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_JNaO8YWc9rQ/RzJpsJDuovI/AAAAAAAAA4I/GTxH7VNIZc4/s320/dtmonline_malurl_20071107.png" alt="" id="BLOGGER_PHOTO_ID_5130279132595135218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;[Added process]&lt;br /&gt;C:\WINDOWS\system32\kawdcaz.exe&lt;br /&gt;C:\WINDOWS\swchost.exe&lt;br /&gt;C:\WINDOWS\IGM.exe&lt;br /&gt;C:\WINDOWS\IGW.exe&lt;br /&gt;C:\WINDOWS\system32\avzxest.exe&lt;br /&gt;C:\WINDOWS\system32\kapjdaz.exe&lt;br /&gt;C:\WINDOWS\system32\raqjdtl.exe&lt;br /&gt;C:\WINDOWS\system32\avwldst.exe&lt;br /&gt;C:\WINDOWS\system32\ratbgtl.exe&lt;br /&gt;C:\WINDOWS\system32\avwgest.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\avwgemn.dll&lt;br /&gt;C:\WINDOWS\system32\avwldmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxemn.dll&lt;br /&gt;C:\WINDOWS\system32\dh3atl.dll&lt;br /&gt;C:\WINDOWS\system32\dhatl.dll&lt;br /&gt;C:\WINDOWS\system32\djatl.dll&lt;br /&gt;C:\WINDOWS\system32\jzatl.dll&lt;br /&gt;C:\WINDOWS\system32\kapjdzy.dll&lt;br /&gt;C:\WINDOWS\system32\kawdczy.dll&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\myatl.dll&lt;br /&gt;C:\WINDOWS\system32\qqhxatl.dll&lt;br /&gt;C:\WINDOWS\system32\raqjdpi.dll&lt;br /&gt;C:\WINDOWS\system32\raqjdtl.exe&lt;br /&gt;C:\WINDOWS\system32\ratbgpi.dll&lt;br /&gt;C:\WINDOWS\system32\ratbgtl.exe&lt;br /&gt;C:\WINDOWS\system32\rxjhatl.dll&lt;br /&gt;C:\WINDOWS\system32\sqmapi32.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: WS2IFSL (正常的服務)&lt;br /&gt;DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment&lt;br /&gt;FILE: \SystemRoot\System32\drivers\ws2ifsl.sys&lt;br /&gt;&lt;br /&gt;NAME: Wdswsdewn&lt;br /&gt;DISPLAY: Telephotsgoogle&lt;br /&gt;FILE: C:\WINDOWS\system32\serdst.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYLOADER.EXE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MSDEG32.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp87.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\014[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\11[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\15[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\19[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\3[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\7[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\13[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\17[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\5[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\9[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\0[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\12[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\16[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\4[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\8[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\10[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1299644[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\14[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\18[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\6[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\ki[1].htm&lt;br /&gt;C:\WINDOWS\136741MM.DLL&lt;br /&gt;C:\WINDOWS\136741WL.DLL&lt;br /&gt;C:\WINDOWS\136741WO.DLL&lt;br /&gt;C:\WINDOWS\Fonts\chqiaur.fon&lt;br /&gt;C:\WINDOWS\Fonts\chtiaur.fon&lt;br /&gt;C:\WINDOWS\Fonts\enpoafx.fon&lt;br /&gt;C:\WINDOWS\Fonts\enweafx.fon&lt;br /&gt;C:\WINDOWS\Fonts\msguasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mswuasd.fon&lt;br /&gt;C:\WINDOWS\Fonts\mszhasd.fon&lt;br /&gt;C:\WINDOWS\IGM.exe&lt;br /&gt;C:\WINDOWS\IGW.exe&lt;br /&gt;C:\WINDOWS\swchost.exe&lt;br /&gt;C:\WINDOWS\system32\0.exe&lt;br /&gt;C:\WINDOWS\system32\avwgein.dll&lt;br /&gt;C:\WINDOWS\system32\avwgemn.dll&lt;br /&gt;C:\WINDOWS\system32\avwgest.exe&lt;br /&gt;C:\WINDOWS\system32\avwldin.dll&lt;br /&gt;C:\WINDOWS\system32\avwldmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwldst.exe&lt;br /&gt;C:\WINDOWS\system32\avzxein.dll&lt;br /&gt;C:\WINDOWS\system32\avzxemn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxest.exe&lt;br /&gt;C:\WINDOWS\system32\dh3atl.dll&lt;br /&gt;C:\WINDOWS\system32\dhatl.dll&lt;br /&gt;C:\WINDOWS\system32\djatl.dll&lt;br /&gt;C:\WINDOWS\system32\jzatl.dll&lt;br /&gt;C:\WINDOWS\system32\kapjdaz.exe&lt;br /&gt;C:\WINDOWS\system32\kapjdcs.dll&lt;br /&gt;C:\WINDOWS\system32\kapjdzy.dll&lt;br /&gt;C:\WINDOWS\system32\kawdcaz.exe&lt;br /&gt;C:\WINDOWS\system32\kawdccs.dll&lt;br /&gt;C:\WINDOWS\system32\kawdczy.dll&lt;br /&gt;C:\WINDOWS\system32\LYLOADER.EXE&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\MSDEG32.DLL&lt;br /&gt;C:\WINDOWS\system32\mseam.sys&lt;br /&gt;C:\WINDOWS\system32\myatl.dll&lt;br /&gt;C:\WINDOWS\system32\qqhxatl.dll&lt;br /&gt;C:\WINDOWS\system32\raqjdni.dll&lt;br /&gt;C:\WINDOWS\system32\raqjdpi.dll&lt;br /&gt;C:\WINDOWS\system32\raqjdtl.exe&lt;br /&gt;C:\WINDOWS\system32\ratbgni.dll&lt;br /&gt;C:\WINDOWS\system32\ratbgpi.dll&lt;br /&gt;C:\WINDOWS\system32\ratbgtl.exe&lt;br /&gt;C:\WINDOWS\system32\rxjhatl.dll&lt;br /&gt;C:\WINDOWS\system32\serdst.exe&lt;br /&gt;C:\WINDOWS\system32\sqmapi32.dll&lt;br /&gt;C:\WINDOWS\system32\zhtuatl.dll&lt;br /&gt;&lt;br /&gt;[Added LSP]&lt;br /&gt;ID: 1026&lt;br /&gt;NAME: MSAPI Tcpip [UDP/IP] (C:\WINDOWS\system32\sqmapi32.dll)&lt;br /&gt;&lt;br /&gt;ID: 1027&lt;br /&gt;NAME: MSAPI Tcpip [TCP/IP] (C:\WINDOWS\system32\sqmapi32.dll)&lt;br /&gt;&lt;br /&gt;[Added COM/BHO]&lt;br /&gt;{38907901-1416-3389-9981-372178569983}-C:\WINDOWS\system32\kawdczy.dll&lt;br /&gt;{44783410-4F90-34A0-7820-3230ACD05F44}-C:\WINDOWS\system32\raqjdpi.dll&lt;br /&gt;{4960356A-458E-DE24-BD50-268F589A56A4}-C:\WINDOWS\system32\avwldmn.dll&lt;br /&gt;{4A321487-4977-D98A-C8D5-6488257545A4}-C:\WINDOWS\system32\kapjdzy.dll&lt;br /&gt;{5859245F-345D-BC13-AC4F-145D47DA34F5}-C:\WINDOWS\system32\avzxemn.dll&lt;br /&gt;{5A1247C1-53DA-FF43-ABD3-345F323A48D5}-C:\WINDOWS\system32\avwgemn.dll&lt;br /&gt;{76650011-3344-6688-4899-345FABCD1567}-C:\WINDOWS\system32\ratbgpi.dll&lt;br /&gt;&lt;br /&gt;[Added registry]&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysM&lt;br /&gt;Data=C:\WINDOWS\IGM.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSysW&lt;br /&gt;Data=C:\WINDOWS\swchost.exe&lt;br /&gt;&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Value=WinSys&lt;br /&gt;Data=C:\WINDOWS\IGW.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;到目前為止 (2007/11/07 @ 13:35)，下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考)：&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;mseam.sys:&lt;br /&gt;[     Symantec     ], "Infostealer"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NFC trojan"&lt;br /&gt;sqmapi32.dll:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt;[     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt;[     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.guz"&lt;br /&gt;[     McAfee       ], "PWS-OnlineGames.j"&lt;br /&gt;[     McAfee_Beta  ], "PWS-OnlineGames.j"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     CAV          ], "Win32/Spibe!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     CAV Beta     ], "Win32/Spibe!generic"&lt;br /&gt;tmp87.tmp:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt;[     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt;[     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.WOW.adu"&lt;br /&gt;[     McAfee       ], "PWS-OnlineGames.j"&lt;br /&gt;[     McAfee_Beta  ], "PWS-OnlineGames.j"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Panda        ], "Suspicious file"&lt;br /&gt;[     CAV          ], "Win32/Spibe!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.NHF trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/PSW.Wow.adu"&lt;br /&gt;[     Norman       ], "Trojan W32/Agent.DASF"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     CAV Beta     ], "Win32/Spibe!generic"&lt;br /&gt;2[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, Trojan-PSW.Win32.WOW.adu"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "[FILE:0000]:Mal/Packer, Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Zuten!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;3[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "[FILE:0000]:Mal/Packer, Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Zuten!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/PSW.Onlineg.KC.2"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;5[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Zuten!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;12[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, Trojan-PSW.Win32.OnLineGames.gyu"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "[FILE:0000]:Mal/Packer, Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Zuten!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/PSW.Onlineg.KC.2"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;14[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "[FILE:0000]:Mal/Packer, Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Zuten!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/PSW.Onlineg.KC.2"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;17[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Zuten!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt;[     Norman       ], "Trojan W32/Delf.AYPE"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;18[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "[FILE:0000]:Mal/Packer, Mal/Packer"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/PSW.Onlineg.KC.2"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;19[1].exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "[FILE:0000]:Mal/Packer, Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Zuten!generic"&lt;br /&gt;[     Nod32        ], "probably a variant of Win32/PSW.OnLineGames.NGU trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/CrashSystem.C"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;LYLOADER.exe:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.006"&lt;br /&gt;[     Alpha_Gen    ], "AP_MALPK-2"&lt;br /&gt;[     Beta_Gen     ], "AP_MALPK-2"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Microsoft    ], "[-&gt;(Upack)]:TrojanSpy:Win32/Agent.HZ"&lt;br /&gt;[     Kaspersky    ], "PAK:PE_Patch, PAK:UPack, Trojan-PSW.Win32.OnLineGames.gym"&lt;br /&gt;[     McAfee       ], "New Malware.aj !!"&lt;br /&gt;[     McAfee_Beta  ], "New Malware.aj !!"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     Panda        ], "Trj/Lineage.gen"&lt;br /&gt;[     Panda_Beta   ], "Trj/Lineage.gen"&lt;br /&gt;[     CAV          ], "Win32/Lolyda!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.Agent.NEC trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/PSW.Online.agb.2"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     CAV Beta     ], "Win32/Lolyda!generic"&lt;br /&gt;LYMANGR.DLL:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt;[     Symantec     ], "Infostealer.Gampass"&lt;br /&gt;[     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt;[     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.gyn"&lt;br /&gt;[     McAfee       ], "Generic PWS.j"&lt;br /&gt;[     McAfee_Beta  ], "Generic PWS.j"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Lolyda!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.DTR trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     HBEDV        ], "TR/PSW.Online.agb.2"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     CAV Beta     ], "Win32/Lolyda!generic"&lt;br /&gt;MSDEG32.DLL:&lt;br /&gt;[     IntelliTrap  ], "PAK_Generic.001"&lt;br /&gt;[     Beta_Gen     ], "Possible_Crypt-6"&lt;br /&gt;[     Microsoft    ], "VirTool:Win32/Obfuscator.C"&lt;br /&gt;[     Kaspersky    ], "PAK:UPack, Trojan-PSW.Win32.OnLineGames.gyo"&lt;br /&gt;[     Sophos       ], "Mal/Packer"&lt;br /&gt;[     CAV          ], "Win32/Lolyda!generic"&lt;br /&gt;[     Nod32        ], "a variant of Win32/PSW.OnLineGames.DVV trojan"&lt;br /&gt;[     Fortinet     ], "suspicious"&lt;br /&gt;[     Norman       ], "Security Risk W32/Suspicious_U.gen"&lt;br /&gt;[     Sunbelt      ], "VIPRE.Suspicious"&lt;br /&gt;[     CAV Beta     ], "Win32/Lolyda!generic"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2979908129018178067-8434595739974149429?l=rogerspeaking.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rogerspeaking.blogspot.com/feeds/8434595739974149429/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2979908129018178067&amp;postID=8434595739974149429' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8434595739974149429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2979908129018178067/posts/default/8434595739974149429'/><link rel='alternate' type='text/html' href='http://rogerspeaking.blogspot.com/2007/11/blog-post.html' title='尖端科技軍事雜誌網站被植入惡意連結'/><author><name>Roger Chiu</name><uri>http://www.blogger.com/profile/14616629338243439273</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_JNaO8YWc9rQ/RzJpc5DuouI/AAAAAAAAA4A/VyiYwt-uNuU/s72-c/dtmonline_home_20071107.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2979908129018178067.post-4849846519145744026</id><published>2007-10-21T22:49:00.000+08:00</published><updated>2007-10-21T23:56:14.304+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='網站安全'/><title type='text'>電線電纜產業服務網被植入惡意連結</title><content type='html'>電線電纜產業服務網被植入惡意連結，此惡意程式為 PE_LOOKED.GEN、BKDR_HUPIGON.EVG 和其他惡意程式，最近有瀏覽這個網頁的網友，應該要盡速檢查自己的電腦，請各位暫時不要瀏覽這個網站，以免中毒。(Credit: 匿名網友)&lt;div id="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_JNaO8YWc9rQ/RxtpsxTvTpI/AAAAAAAAA3w/qKo9PK4drIY/s1600-h/taiwancable_home_20071019.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_JNaO8YWc9rQ/RxtpsxTvTpI/AAAAAAAAA3w/qKo9PK4drIY/s320/taiwancable_home_20071019.png" alt="" id="BLOGGER_PHOTO_ID_5123805218935361170" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的：&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_JNaO8YWc9rQ/Rxtp-RTvTqI/AAAAAAAAA34/1taknPWySOM/s1600-h/taiwancable_malurl_20071019.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_JNaO8YWc9rQ/Rxtp-RTvTqI/AAAAAAAAA34/1taknPWySOM/s320/taiwancable_malurl_20071019.png" alt="" id="BLOGGER_PHOTO_ID_5123805519583071906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;執行之後，有下面的行為：&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;[Added process]&lt;br /&gt;C:\WINDOWS\system32\ntvdm.exe&lt;br /&gt;C:\WINDOWS\ctfmon.exe&lt;br /&gt;C:\WINDOWS\IGW.exe&lt;br /&gt;C:\DOCUME~1\ADMINI~1\JOPEN.EXE&lt;br /&gt;C:\WINDOWS\system32\nslkupi.exe&lt;br /&gt;C:\WINDOWS\Logo1_.exe&lt;br /&gt;C:\WINDOWS\IGM.exe&lt;br /&gt;C:\WINDOWS\system32\119.exe&lt;br /&gt;&lt;br /&gt;[DLL injection]&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NinSys74.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\WinSys8s.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\SMSS.EXE&lt;br /&gt;C:\Program Files\NetMeeting\avpwl.dat&lt;br /&gt;C:\WINDOWS\Dll.dll&lt;br /&gt;C:\WINDOWS\system32\5E9F0D5.DLL&lt;br /&gt;C:\WINDOWS\system32\avwgcmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwgdmn.dll&lt;br /&gt;C:\WINDOWS\system32\avwlcmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxdmn.dll&lt;br /&gt;C:\WINDOWS\system32\avzxemn.dll&lt;br /&gt;C:\WINDOWS\system32\cqatl.dll&lt;br /&gt;C:\WINDOWS\system32\DbgHlp32.dll&lt;br /&gt;C:\WINDOWS\system32\djatl.dll&lt;br /&gt;C:\WINDOWS\system32\drivers\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\gjatl.dll&lt;br /&gt;C:\WINDOWS\system32\kapjbzy.dll&lt;br /&gt;C:\WINDOWS\system32\kaqhfzy.dll&lt;br /&gt;C:\WINDOWS\system32\kawdbzy.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxdma.dll&lt;br /&gt;C:\WINDOWS\system32\kvdxscma.dll&lt;br /&gt;C:\WINDOWS\system32\kvmxfma.dll&lt;br /&gt;C:\WINDOWS\system32\LYMANGR.DLL&lt;br /&gt;C:\WINDOWS\system32\MsPrint32D.dll&lt;br /&gt;C:\WINDOWS\system32\NVDispDrv.dll&lt;br /&gt;C:\WINDOWS\system32\qdshm.dll&lt;br /&gt;C:\WINDOWS\system32\qdshm.dll&lt;br /&gt;C:\WINDOWS\system32\raqjbpi.dll&lt;br /&gt;C:\WINDOWS\system32\rsjzbpm.dll&lt;br /&gt;C:\WINDOWS\system32\rsmyepm.dll&lt;br /&gt;C:\WINDOWS\system32\rsmyfpm.dll&lt;br /&gt;C:\WINDOWS\system32\rsztdpm.dll&lt;br /&gt;C:\WINDOWS\system32\rxjhatl.dll&lt;br /&gt;C:\WINDOWS\system32\sidjazy.dll&lt;br /&gt;C:\WINDOWS\system32\sqmapi32.dll&lt;br /&gt;C:\WINDOWS\system32\twdnwy.dll&lt;br /&gt;C:\WINDOWS\system32\vqjcws.dll&lt;br /&gt;C:\WINDOWS\system32\wdrkzq.dll&lt;br /&gt;C:\WINDOWS\system32\WinForm.dll&lt;br /&gt;C:\WINDOWS\system32\wiscoxgpyhq.dll&lt;br /&gt;C:\WINDOWS\system32\wiscoxgpyhq.dll&lt;br /&gt;C:\WINDOWS\system32\wlatl.dll&lt;br /&gt;C:\WINDOWS\system32\yuhpyz.dll&lt;br /&gt;C:\WINDOWS\system32\zxatl.dll&lt;br /&gt;C:\WINDOWS\system32\zyuimd.dll&lt;br /&gt;&lt;br /&gt;[Added service]&lt;br /&gt;NAME: 2FED61CD&lt;br /&gt;DISPLAY: 2FED61CD&lt;br /&gt;FILE: C:\WINDOWS\system32\AE9C6AE4.EXE -d&lt;br /&gt;&lt;br /&gt;NAME: Rasautol&lt;br /&gt;DISPLAY: Remote Help Session Manager&lt;br /&gt;FILE: C:\WINDOWS\system32\ntsokele.exe&lt;br /&gt;&lt;br /&gt;NAME: WS2IFSL (正常)&lt;br /&gt;DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment&lt;br /&gt;FILE: \SystemRoot\System32\drivers\ws2ifsl.sys&lt;br /&gt;&lt;br /&gt;NAME: Wdswsdewn&lt;br /&gt;DISPLAY: Telephotsgoogle&lt;br /&gt;FILE: C:\WINDOWS\system32\serdst.exe&lt;br /&gt;&lt;br /&gt;NAME: WindowsDown&lt;br /&gt;DISPLAY: Telephots google&lt;br /&gt;FILE: C:\WINDOWS\system32\servet.exe&lt;br /&gt;&lt;br /&gt;NAME: Windowsmns&lt;br /&gt;DISPLAY: Tele_google&lt;br /&gt;FILE: C:\WINDOWS\system32\MMSN.exe&lt;br /&gt;&lt;br /&gt;[Added file]&lt;br /&gt;C:\4NT\_desktop.ini&lt;br /&gt;C:\autorun.inf&lt;br /&gt;C:\Documents and Settings\Administrator\jopen.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\$$aBE.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a1.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a20.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\a6.exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYLOADER.EXE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\LYMANGR.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\MSDEG32.DLL&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp8B.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp8E.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp92.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp97.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp9B.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp9D.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\tmp9F.tmp&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\~V5SFDYCLNTKs.ExE&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temp\~V5SFDYCLNTKs.VbS&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\03[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\104[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\109[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\112[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\117[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\119[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\11[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1631[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1634[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1639[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\163a[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\163c[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\163d[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\163f[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\163i[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\163k[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\17[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\1[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\4[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\6[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\8[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\9038[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ax[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\CAKDABCD.htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\down[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\Hosts[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\index[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ma3[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\new82[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s223[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s3[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\stat[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s[3].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s[4].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\s[5].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\un460[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\vip[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\xx.9365[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\014[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\01[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\105[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\111[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\113[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\114[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1203774[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\12[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1367652[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\15[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1630[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1633[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1636[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\1637[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\163b[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\163c[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\163d[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\163f[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\163g[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\163j[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\19[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\3[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\5[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\888[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\9[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\a[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\CAQXOBG1.HTM&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\down1[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\down[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\dy[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\g1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\g3[1].gif&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ip[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ma1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ma2[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\pop[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\se[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\s[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\vc[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zaza[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\02[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\04[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\100[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\102[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1049603[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\107[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\110[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\112[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\113[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1153797[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\115[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\116[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\14[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1630[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1632[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1634[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1637[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1638[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1639[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\163e[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\163g[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\163j[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\168[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\18[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\bu1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\CAP8R4HT.HTM&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\de[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\du7[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\g1[1].gif&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\g3[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\hdsl[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\love[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\ripi[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\s5[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\s[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\s[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\web.2008yi[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\y[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\014[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\05[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\06[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\0[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\101[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\103[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\106[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\108[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\10[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\111[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\118[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1299644[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1329427[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\13[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1631[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1633[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1636[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1638[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\163a[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\163b[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\163e[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\163h[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\163i[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\163k[1].txt&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\16[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\1[1].js&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\7[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\down2[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\kl[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\live[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\s[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\s[2].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\s[3].htm&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\vip[1].exe&lt;br /&gt;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\x[1].htm&lt;br /&gt;C:\Documents and Settings\Administrator\ntuser.com&lt;br /&gt;C:\PegeFile.pif&lt;br /&gt;C:\Program Files\100.exe&lt;br /&gt;C:\Program Files\Hosts.exe&lt;br /&gt;C:\Program Files\Internet Explorer\13Sy.exe&lt;br /&gt;C:\Program Files\Internet Explorer\15Sy.exe&lt;br /&gt;C:\Program Files\Internet Explorer\9Sy.exe&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.bak&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.bkk&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NinSys74.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\NysWin75.Jmp&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\SysWin7s.Jmp&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\WinSys8s.Sys&lt;br /&gt;C:\Program Files\Internet Explorer\PLUGINS\WinSys8s.Tao&lt;br /&gt;C:\Program Files\Internet Explorer\RUNDLL32.exe&lt;br /&gt;C:\Program Files\Internet Explorer\SMSS.EXE&lt;br /&gt;C:\Program Files\NetMeeting\avpwl.dat&lt;br /&gt;C:\Program Files\NetMeeting\avpwl.exe&lt;br /&gt;C:\servet.exe&lt;br /&gt;C:\WINDOWS\124327MM.DLL&lt;br /&gt;C:\WINDOWS\124327WO.D
