| « | ÈýÔÂ 2010 | » | ||||
|---|---|---|---|---|---|---|
| Ò» | ¶þ | Èý | ËÄ | Îå | Áù | ÈÕ |
| 1 | 2 | 3 | 4 | 5 | 6 | 7 |
| 8 | 9 | 10 | 11 | 12 | 13 | 14 |
| 15 | 16 | 17 | 18 | 19 | 20 | 21 |
| 22 | 23 | 24 | 25 | 26 | 27 | 28 |
| 29 | 30 | 31 | ||||
´ó³ÉÌìϳöÊÖµÄרɱ¹¤¾ß,ÏÖÔÚÉý¼¶µ½ÁË1.6°æ
ÄÚÈÝ£º
UÅÌ(auto²¡¶¾)Àಡ¶¾·ÖÎöÓë½â¾ö·½°¸
À´×Ô´ó³ÉÌìÏÂ
²é¿´È«ÎÄ
ÄÚÈÝ£º¶ÔÓÚOffice¡¢rarµÈ¿ÉÖ´ÐÐÎļþ´ò²»¿ª£¬ÖÐÁËW32.Looked.AH
²ÉÓÃDr.WEBµÄ²¡¶¾²éɱ¹¤¾ß·Ç³£µÄºÃÓã¡
²é¿´È«ÎÄÄÚÈÝ£ºSymantec 10.0ÆóÒµ°æÒÔºóÔö¼ÓÁËPKIÈÏÖ¤¹¦ÄÜ£¬¿Í»§¶Ë¶¨ÒåÎÞ·¨¸üеĽâ¾ö ²é¿´È«ÎÄ
ÄÚÈÝ£º×î½üÍøÂçÄڵIJ¡¶¾¡¢Ä¾ÂíµÈÌØ±ð²þâ±£¬SymantecÔÚ²éɱÍ겡¶¾ÒԺ󣬲¿·Ö»úÆ÷³öÏÖ¡°ExeÎļþ¹ØÁªµÄ´íÎ󡱿ÉÖ´ÐÐÎļþ´ò²»¿ª£¬ÉÏÍøGoogleÁËһϣ¬ÔÚÆ®Ñ©µÄÍøÕ¾ÕÒµ½Á˽â¾öµÄ·½·¨£º
http://www.pxue.com/Html/23.html
²é¿´È«ÎÄÄÚÈÝ£ºÍøÄÚ±¬·¢ÁËoffice²¡¶¾ ²é¿´È«ÎÄ
ÄÚÈÝ£ºÕë¶ÔofficeÎĵµ·À²¡¶¾¹¥»÷µÄ×î¼Ñʵ¼ù
http://office.microsoft.com/en-us/assistance/HA011030692052.aspx
²é¿´È«ÎÄ
ÄÚÈÝ£º
ǰ¶Îʱ¼ä·¢ÏÖ×Ô¼ºµÄBlogµÄ¶ñÒâÀ¬»øÆÀÂÛ¿ì·ÉÁË£¬É¾¶¼É¾²»µô£¬ÕûµØÎÒµÄÍ·¶¼´óÁË£¬ÉÏÂÛ̳¿´ÁËһϣ¬°ÑÒ»¸ö²å¼þµÄ¹¦Äܸø´ò¿ªÁË£¬ÏÖÔÚ¿´Ã»ÎÊÌâÁË£¬ºÇºÇ£¬¾ÍÊÇÒ»¸öÆÀÂÛÑéÖ¤µÄ¹¦ÄÜ£¡
²»´í£¬Ê¡ÐÄÁË£¡
UÅ̵ÄÒ»ÖÖ¶ñÐÔ²¡¶¾£ºRavmone.exe ²é¿´È«ÎÄ
ÄÚÈÝ£ºÎ¢Èí×îз¢²¼ÁËÈý¸ö¸ßΣ©¶´ ²é¿´È«ÎÄ
ÄÚÈÝ£ºÊ¹ÓÃÃâ·Ñ¹¤¾ß±£»¤ÄãµÄ¸öÈ˵çÄÔ°²È« ²é¿´È«ÎÄ
ÄÚÈÝ£ºsober²¡¶¾µÄ±äÖÖÕýÔÚ½øÐÐÈ«Çò´«²¥£¬Çë×¢Òâ×öºÃ·À»¤¹¤×÷¡£
²é¿´È«ÎÄ
×î½üÓÐÍøÓÑËµÍøÄÚÖÐÁËÒ»ÖÖintec32.exeµÄ²¡¶¾£¬
goolgeÁËÒ»ÏÂTrendµÄÓ¢ÎÄÍøÕ¾ËµÁËÏêϸµÄ½â¾ö
·½·¨£¬ÕâÊÇÒ»ÖÖºóÃŲ¡¶¾¡£
From :
http://www.trendmicro.com.au/enterprise/vinfo
²é¿´È«ÎÄ
ÄÚÈÝ£º
11ÔÂ23ÈÕÏûÏ¢£¬¼ÆËã»ú°²È«Ñо¿×éÖ¯SANSÈÕ
ǰ·¢²¼ÁË2005Äê¡°20´ó»¥ÁªÍø°²È«Òþ»¼¡±ÅÅ
Ðаñ¡£¾Ý°ñµ¥ÏÔʾ£¬É±¶¾Èí¼þɨÃèÒýÇæ¡¢web
Ó¦Óá¢Î¢Èí²úÆ·£¬ÒÔ¼°Ë¼¿ÆÍøÂç²úÆ·Ëù´æÔÚµÄ
©¶´¾ù±»ÁÐÈë20´óÍþв֮ÁС£
½ø³ÌÎļþ: ctfmon or ctfmon.exe
½ø³ÌÃû³Æ: Alternative User Input Services
ÃèÊö: ¿ØÖÆAlternative User Input Text Processor (TIP)ºÍMicrosoft OfficeÓïÑÔÌõ¡£Ctfmon.exeÌṩÓïÒôʶ±ð¡¢ÊÖдʶ±ð¡¢¼üÅÌ¡¢·ÒëºÍÆäËüÓû§ÊäÈë¼¼ÊõµÄÖ§³Ö¡£
³£¼û´íÎó: N/A
ÊÇ·ñΪϵͳ½ø³Ì: ·ñ
ÔÚÏßɨÃèµØÖ·£º
Panda£º
http://www.pandasoftware.com/products/activescan.htm Ca etrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
רɱ¹¤¾ßÏÂÔØ
symantec http://www.symantec.com/avcenter/tools.list.html/
panda
http://www.pandasoftware.com/download/utilities/
΢Èí·¢²¼ÁË11Ô·ݰ²È«¹«¸æ£¬ÆäÖÐÓÐÒ»¸ö¸ßΣ©¶´£¡
http://www.microsoft.com/china/technet/security/bulletin/ms05-nov.mspx
hotfix×¢²á±íÖеÄλÖÃ
Hkey_local_machine:software:microsoft:Windows Nt:CurrentVersion:Hotfix
¹«Ë¾ÄÚ²¿×ÜÓÐÒ»²¿·ÖÈËÒÔΪ×Ô¼ººÜÅ£XµÄ£¬¶ÔÓÚ×Ô¼ºµÄµçÄÔ°²×°ÁËÆäËüµÄ·À²¡¶¾Èí¼þ£¬¶øÇÒ°Ñsymantec±áµÍµÄÒ»ÎÞÊÇ´¦£¬×÷ÎªÍøÂç·À²¡¶¾µÄ¹ÜÀíÔ±£¬¹«Ë¾ÌåÖÆµÄ²»½¡È«£¬¶ÔÓÚÕⲿ·Ö´óÒ¯¼¶ÈËÎï¹ÜÒ²¹Ü²»µÃ˵Ҳ˵²»µÃ£¬ÕæÊÇÎÞÄΣ¡¸üºÎ¿öÁ¬×Ô¼ºÐÅÏ¢ÖÐÐÄÄÚ²¿µÄÈË·À²¡¶¾Èí¼þ¶¼Ê¹ÓÃÁ˺ܶàµÄ°æ±¾¡£
²é¿´È«ÎÄ
Over the past several years Honeynets have demonstrated their value as a security mechanism, primarily to learn about the tools, tactics, and motives of the blackhat community. This information is critical for organizations to better understand and protect against the threats they face. One of the problems with Honeynets is they are resource intensive, difficult to build, and complex to maintain. Honeynets require a variety of both physical systems and security mechanisms to effectively deploy. However, the Honeynet Project has been researching a new possibility, virtual Honeynets. These systems share many of the values of traditional Honeynets, but have the advantages of running all the systems on a single system. This makes virtual Honeynets cheaper to build, easier to deploy, and simpler to maintain.
http://www.honeynet.org/papers/virtual/
ÊÔÓò쿴Æô¶¯¼ÓÔØÏîµÄÃâ·ÑÈí¼þAutorunsʱ·¢ÏÖÔÚ
HKLM_SOFTWARE_Microsoft_Windows_CurrentVersion_Run
ÏÂÓÐÒ»¸ö×ÔÆô¶¯ÏîExfilter £¬¶ÔÓ¦ÏîΪ
C:_Program Files_CNNIC_Cdn_cdnspie.dll
ÊôÓÚhookdll£¬ÊÇÖÐÎÄÓòÃûÐ¶ÔØºóµÄ×ÔÆô¶¯Ïî¡£
ZotobÀûÓÃ΢Èí¹«²¼µÄÑÏÖØÏµÍ³Â©¶´£¬Windows Plug and Play ·þÎñ©¶´ (MS05-039)£¬ ¹¥»÷TCP¶Ë¿Ú445£¬ºÍ³å»÷²¨¡¢Õñµ´²¨·½·¨ÀàËÆ£¬¹¥»÷´úÂëÏòÄ¿±êϵͳµÄ445¶Ë¿Ú·¢ËÍ©¶´´úÂ룬ʹĿ±êϵͳÔì³É»º³åÇøÒç³ö£¬Í¬Ê±ÔËÐв¡¶¾´úÂ룬½øÐд«²¥¡£ ²é¿´È«ÎÄ
ssl.exeÊôÓÚspywareÈ䳿
¹ØÓÚssl.exeÈçϽâÊÍ
W32/Cuebot-D ÊÇÍøÂçÈ䳿Óë±³ºóTrojan ¹¦ÄÜΪ´°¿Úƽ̨¡£
W32/Cuebot-D ÊÔͼ´«²¥Ê¹Óõļ¼Êõ°üÀ¨PnPÈõµãµÄ¿ª·¢ (MS05-039) ¡£
µ±µÚÒ»´ÎÔËÐÐW32/Cuebot-D ¸´ÖÆ< System>ssl.exe ºÍ´´ÔìÎļþ< Windows>Debugdcpromo.log ¡£
Õâ¸öÎļþssl.exe ±»¼Ç¼,×÷ΪһеÄϵͳ·þÎñ±»ÃüÃû" Ô´Óï¾ä¿â", Óë" ΢ÈíÔ´Óï¾ä¿â" ºÍÒ»¿ªÊ¼½×¶ÎÀàÐÍÏÔʾÃû×Ö×Ô¶¯, ËùÒÔËü×Ô¶¯µØ¿ªÊ¼ÔÚϵͳÆð¶¯Ê±¡£¼Ç¼Ìõ±»´´ÔìÈçÏÂ:
HKLMSYSTEMCurrentControlSetServicesssl
ÉèÖà ÈçÏÂ:
HKLMSOFTWAREMicrosoftOle
EnableDCOM
n
HKLMSYSTEMCurrentControlSetControlLsa
restrictanonymous
1
Ò»¸ö²¹¶¡ÎªPnP ²Ù×÷ϵͳÈõµã:ms-05039
ÔÚblogÖÐÐÂÔö¼ÓÁ˹ØÓÚ¶ñÒâÈí¼þ·À·¶µÄ°å¿é£¬ÒÔºó·À²¡¶¾¡¢È䳿¡¢Ä¾ÂíµÈµÄÏà¹ØÎÄÕ¼¼ÇÉ×öÒ»¸ö»ã×Ü¡£
˵Ã÷£º½éÉÜÁËÁ÷Ã¥Èí¼þµÄһЩÄÚÄ»ÏûÏ¢£¬ÖµµÃÒ»¿´¡£
Óɱ±¾©ÊÐÍøÂçÐÐÒµÐ»á½øÐÐǣͷµÄ¡°Á÷Ã¥Èí¼þ¡±ÍøÉϾٱ¨µ÷²é½á¹û×òÈÕÒý·¢ÁËÐùÈ»´ó²¨£¬¼¸´ó³öÏÖÔÚÃûµ¥Ö®Äڵij§ÉÌÒ²¸÷³ÖÒ»´Ê»¥½ÒÄÚÄ»¡£
²é¿´È«ÎÄ
ÀýÈçMS03-039 £¬´ú±í2003ÄêµÚ39¸öBug
¶ÔÓÚKB******£¬Q******»òÕßÀàËÆµÄ±íʾÕâ¸öÎÊÌâÔÚ֪ʶ¿âµÚ******ºÅÎÄÕÂÖÐÌÖÂÛ¹ý£¬Äã¿ÉÒÔͨ¹ýÁ´½Ó£º
http://support.microsoft.com/?id=****** Ö±½Ó·ÃÎÊ
ÐèҪעÒâµÄÊÇÏàÓ¦µÄ²¹¶¡³ÌÐòµÄÃüÃû¹æÔò£¬ÕâÀïÄÜ˵Ã÷²»ÉÙÎÊÌ⣬Äã¿ÉÒԲο¼ÕâÀ
http://support.microsoft.com/?id=816915
http://support.microsoft.com/?id=816916
http://support.microsoft.com/?id=822464
http://support.microsoft.com/?id=822499
http://support.microsoft.com/?id=822623
http://support.microsoft.com/?id=823419
²é¿´È«ÎÄ
ÄÚÈÝ£º ΢Èí×îз¢²¼ÁË12¸ö°²È«²¹¶¡£¬×¢Òâ¸üÐÂѽ£¡£¡£¡
²é¿´È«ÎÄ