


Archive for 11 æ, 2009
ãŠã€ã«ã¹å¯Ÿçã¯ã©ããŸã§ã»ã»ã»
Author: 管çè
å··ã§ã¯ãæ°åã€ã³ãã«ãšã³ã¶ã®æµè¡ã«ã¿ããªç¥çµãç ãæŸãŸããŠããããPCãžã®ãŠã€ã«ã¹ææã«ã¯ãªããªãæ°ã¥ããªãããããã»ã©å±æ©æããªãããã«æããã
å®éããŠã€ã«ã¹ã«ææããããã£ãŠãã£ãŠã©ããªåé¡ãããã®ããããããããªãã£ãŠã®ãæ£çŽãªææ³ã§ãããã
ãããªãªãããŠã€ã«ã¹ææããªïŒãã£ãŠæãããã®ããæã ã¡ã¢æžãããŠãããŸãã
jwgkvsq.vmx ãèªã¿èŸŒã¿äžã«ãšã©ãŒãçºçããŸããã
æå®ãããã¢ãžã¥ãŒã«ãèŠã€ãããŸããã
ã³ã³ãã£ãã«ãŒå¯Ÿçã«é¢ããçœæžïœUSBé¢é£ãŠã€ã«ã¹ã«æ³šæ ã«ããã°ãjwgkvsq.vmx ãšã¯ãUSBã¡ã¢ãªé¢é£ãŠã€ã«ã¹ã§ããã³ã³ãã£ãã«ãŒã§ããããã ã
ãŠã€ã«ã¹å¯Ÿçã€ã³ã¿ãŒãããã»ãã¥ãªã㣠G DATA:
http://gdata.co.jp/press/archives/2009/02/usb.htm- ä»¥äžæç² -
ã³ã³ãã£ãã«ãŒå¯Ÿçã«é¢ããçœæžïœUSBé¢é£ãŠã€ã«ã¹ã«æ³šæ 2009.2.25
ã G DATA Softwareæ ªåŒäŒç€ŸïŒä»£è¡šåç· åœ¹ïŒ Jag å±±æ¬ãæ¬ç€ŸïŒæ±äº¬éœå代ç°åºïŒã¯ããã12ãæã«ãããŠãæãå·§åŠã§å±éºåºŠãé«ãããã€ãäžçäžã§æ³šç®ãéããŠãããã«ãŠã§ã¢ïŒã¯ãŒã ïŒã®äžã€ã§ãããã³ã³ãã£ã«ãŒïŒConfickerïŒãã«ã€ããŠã以äžãçœæžã®åœ¢ã§ã¬ããŒãããããŸãã
ãã³ã³ãã£ãã«ãŒã¯ãä»åœãšæ¯ã¹ããšæ¥æ¬ã§ã¯ãŸã èããç®ç«ã€åãã«ã¯ãªã£ãŠããªããã®ã®ã 2009幎1æ22æ¥ã«ã¯èŠèŠåºã®ãªã³ã©ã€ã³ã·ã¹ãã ã®ç«¯æ«ã«äœ¿çšãããŠããPCããçºèŠããããªã©ãä»åŸãæŽãªãå¢å ã®æãããããŸãã®ã§ãååãªæ³šæãå¿ èŠã§ãã
ã³ã³ãã£ãã«ãŒã®çŸç¶
ãã³ã³ãã£ãã«ãŒãšã¯ãã¯ãŒã ã®äžçš®ã§ãæšå¹Ž10æã«MicrosoftããããæäŸãããWindowsã®RPCïŒïŒãªã¢ãŒã ããã·ãŒãžã£ã³ãŒã«ïŒãµãŒãã¹ã®è匱æ§ãMS08-067ããæªçšãããã«ãŠã§ã¢ã§ããå¥åãšããŠãããŠã³ã¢ãïŒDownadïŒãããŠã³ã¢ãã¢ããïŒDownadupïŒãããïŒKidoïŒãªã©ããããŸãã
ãMicrosoftããŠã€ã«ã¹è£œé è ã®é®æã«ã€ãªããæ å ±æäŸè ã«æžè³éãåºããšããçºè¡šãããããšã«ãããäžè¬çã«ããç¥ããããŠã€ã«ã¹ãšãªããŸããã
ãé¡äŒŒãããã®ã«ã2007幎ãã2008幎ã«ãããŠççºçã«æ¡æ£ããããªãŒãã©ã³ããšåŒã°ãããã«ãŠã§ã¢ããããŸããä»å¹Žã«å ¥ããšããªãŒãã©ã³ãããã³ã³ãã£ãã«ãŒãå¢å ããŠããŸãã
ãã³ã³ãã£ãã«ãŒã¯ãŸãã现工ãããã¯ãšãªãŒïŒåŠçèŠæ±ïŒãã³ã³ãã¥ãŒã¿ã«éä¿¡ããã³ã³ãã¥ãŒã¿ã«è匱æ§ãããã°ãäžæ£ã³ãŒããã³ã³ãã¥ãŒã¿ã«éãã€ããŸããææããã³ã³ãã¥ãŒã¿ã«ã¯HTTPãµãŒããã€ã³ã¹ããŒã«ããã现工ãããã¯ãšãªãŒãå Žåã«ãã£ãŠã¯ææãã¡ã€ã«ããä»ã®ã³ã³ãã¥ãŒã¿ã«éããŸãã
ãåœã¡ãã»ãŒãžã§ååãè²·ããããããªã¹ã±ã¢ãŠã§ã¢ãªã©ãã€ã³ã¹ããŒã«ãããå ŽåããããŸãã
ãã³ã³ãã£ãã«ãŒã¯ãåçŽãªãã¹ã¯ãŒãã§ããä¿è·ãããŠããªãããŒã«ã«ãããã¯ãŒã¯å ã§æ¡æ£ããUSBã¡ã¢ãªãå€ä»ãããŒããã£ã¹ã¯ãããžã¿ã«ã«ã¡ã©ãªã©ã®ãªãŒãã¹ã¿ãŒãæ©èœãæªçšããŸãã
ãçããã¹ã¯ãŒããšãªãŒãã¹ã¿ãŒãæ©èœããã®2ã€ã®ç¹åŸŽã掻çšããŠã³ã³ãã£ãã«ãŒã¯å·§ã¿ã«äžå»¶ããŠããã®ã§ãã
ãEU諞åœã§ã¯ãã§ã«ããã€ãã®ã±ã«ã³ãã«ã³å·ã«ããã3000å°ã®ææãçé ã«ããªãŒã¹ããªã¢ãã€ã®ãªã¹ã®ç é¢ããã©ã³ã¹æµ·è»ã®ã³ã³ãã¥ãŒã¿ãªã©ãæ°å€ãã®å Žæã§è¢«å®³ãèµ·ãã£ãŠããŸãã
ããŸãããããããããµãŒããšã®æ¥ç¶ãéåããªããããã³ã³ãã£ãã«ãŒã¯æ¥ä»ã䜿ã£ãŠããejzrcqqw.netããdoxkknuq.orgããytfvksowgul.orgããšãã£ããããªãã¡ã€ã³åãæ¥ã 250ã»ã©äœã£ãŠããŸãã
ãæè¿ã®ãã®ææã®åºãããèŠããšãã³ã³ãã£ãã«ãŒã®äœè ã¯ãæ°ããªããããããã®åºç€ãäœãããããšèããããŸãããããããããæäœããåŽã«ãšã£ãŠå€§éã®ææããã³ã³ãã¥ãŒã¿ã®ååšãšã¯ãæ»ææºåãæŽã£ãç¶æ ãæå³ããã®ã§ããææã®èŠæš¡
ãææã®èŠæš¡ã«ã€ããŠã¯ãçŸåšãå°ãªãèŠç©ãã£ãŠãæ°åäžå°ãå€ããã°æ°åäžå°ã®ã³ã³ãã¥ãŒã¿ãææããŠãããšäºæ³ãããŸãããããããã以äžã®æ£ç¢ºãªæ°åã®ææ¡ã¯å°é£ã§ãããªããªãã°ãå€ãã®ææããã³ã³ãã¥ãŒã¿ãã³ã³ãããŒã«ãµãŒããšæ¥ç¶ããæ°åã«æ°ããããŠããããäŒç€Ÿã®ãããã¯ãŒã¯å ã®è€æ°å°ã®ã³ã³ãã¥ãŒã¿ã1å°ãšèšç®ãããããšãããããã§ãã
ãæ£ç¢ºãªæ°åã¯åºãªããšããŠããä»åã®æ¡æ£ã®ä»æ¹ã¯ãã¡ãŒã«ãã€ã³ã¿ãŒããããéããææã ãã§ã¯ãªããUSBã¡ã¢ãªãªã©ãä»ããŠããããšããããæœåšçãªæææ°ã¯ãã£ãšå€ãå¯èœæ§ããããŸãã
ãããã¯ãUSBã¡ã¢ãªãããããç¯çœªè ãã¡ã«ãšã£ãŠãæ¡æ£ã®ããã®æçšãªéå ·ãšã¿ãªãããŠããããšãæå³ããŠããŸããå¯Ÿçæ¹æ³
ã2008幎10æã«ãMicrosoftã®çºè¡šã«ãã£ãŠãã³ã³ãã£ãã«ãŒãOSå ã®è匱æ§ãæªçšããããšããããšã倿ããŸãããããä»¥æ¥ Microsoftã¯ãé¢é£ã®ã¢ããããŒããæäŸããŠããŸãããå€ãã®ãããã¯ãŒã¯ç®¡çè ã¯é©åãªå¯Ÿå¿ããšãããšãã§ããææãèš±ããŠããŸãã
ããŸãããã1ã€ã®éèŠãªç¹ã¯ããããã¯ãŒã¯ãã¢ã«ãŠã³ãçšãã¹ã¯ãŒãã«ã12345ãããadminããzzzzzzããšãã£ããããªç°¡åãªãã¹ã¯ãŒããèšå®ããŠããå Žåããæå€ãšå€ããšããããšã§ãã
ãæŽã«ãå€ãã®äŒæ¥ã§ã¯USBã¡ã¢ãªã®å©çšãªã©ã«é¢ããèŠåãããã»ã©æç¢ºã«ãšã決ããŠããªãããšããã®ãæ¡æ£ãå©é·ãããŠããçç±ã®äžã€ã§ãã
ããªãŒãã¹ã¿ãŒãã®ã¡ã«ããºã ã¯ãã»ãšãã©ã®ã³ã³ãã¥ãŒã¿ã«ãããŠæå¹ã«åããã³ã³ãã£ãã«ãŒãUSBãŠã€ã«ã¹ãã¯ãããšããäžæ£ããã°ã©ã ã®æ¡æ£ã®åå ãšãªã£ãŠããŸããã¡ãŒã«ãã€ã³ã¿ãŒãããã«é¢ããã»ãã¥ãªãã£ã¯äžè¬çã«ã¯åŒ·åãããŠããã®ã§ã䜿ãåæãããããã«ããŒã¿ã®åãæž¡ãã§å©çšãããŠãã USBã¡ã¢ãªãææã«ãŒãã«çµã¿èŸŒãã ãšèšããã§ãããã
ããŸããOpenDNSã¯è峿·±ããµãŒãã¹ãæäŸããŠããŸããOpenDNSã¯ããããã¯ãŒã¯å ã®ã³ã³ãã£ãã«ãŒã«ææããã³ã³ãã¥ãŒã¿ãèªèããæ¥ã æ°ããçºçãããããããããã¡ã€ã³ãžã®ã¢ã¯ã»ã¹ããããã¯ãããµãŒãã¹ãæäŸããŠããŸãããã®ãµãŒãã¹ã«ãã£ãŠããŸã³ãPCã¯ææããŠããŸã£ããŸã³ãPC ã§ãã£ãŠãã仿ã人ããã®æç€ºããªããã°äŒæ¢ç¶æ ã«ããããšãã§ããŸããã³ã³ãã£ãã«ãŒã®æ€ç¥æ¹æ³
ãã¢ã³ããŠã€ã«ã¹è£œåã®ã¯ã¯ãã³ãææ°ã®ç¶æ ã«æŽæ°ãããŠããã°ãã³ã³ãã£ãã«ãŒã¯æ€åºããããšãå¯èœã§ããããããã·ã¹ãã å ã«ããã¯ãã¢ãæœãã§ãããè匱æ§ãéããããŠããªããã°ãææããå±éºããããŸãã
ãã³ã³ãã£ãã«ãŒã¯ãjwgkvsq.vmxãããvfgthjki.rstãããšãã£ããããªããã¡ã€ã«åã«ã©ã³ãã ãªæåã®çµã¿åããã䜿ãããã®ã§ãæ€åºã¯å°é£ã§ãã
ãã¬ãžã¹ããªã倿Žãããã®ã¯ã以äžã®ç®æã§ããHKEY _ LOCAL _ MACHINE\SYSTEM\CurrentControlSet\
Services\ [Random name for the service]
Image Path = â%System Root%\system32\svchost.exe -k netsvcsâHKEY _ LOCAL _ MACHINE\SYSTEM\CurrentControlSet\
Services\[Random name for the service]\Parameters
ServiceDll = â[Path and filename of the malware]âHKEY _ LOCAL _ MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\SvcHost
ã
ãäžèšã®ãããªã»ãã¥ãªãã£ãµãŒãã¹ãæ©èœããªãããšã§ãææã«æ°ã¥ãããšããããŸãã⢠Windows Security Center
⢠Windows AutoUpdate
⢠Windows Defender
⢠Error Reporting ServiceãããŠã€ã«ã¹ãããã¹ãã€ãŠã§ã¢ããšãã£ãæååãããã€ã¯ããœãããããG DATAããã¯ãããš ããã¢ã³ããŠã€ã«ã¹è£œåã®ååãªã©ã以äžã®æååã®ãããŠã§ããµã€ããžã®ã¢ã¯ã»ã¹ãã§ããªã㪠ããŸãã
ãvirusããspywareããmalwareããrootkitããdefenderããmicrosoftããsymantecããnortonããmcafeeããtrendmicroããsophosããpandaããetrustããnetworkassociatesããcomputerassociatesããf-secureããkasperskyããjottiããf-protããnod32ããesetããgrisoftããdrwebããcentralcommandããahnlabããesafeããavastããaviraããquickhealããcomodoããclamavããewidoããfortinetããgdataããhacksoftããhauriããikarusããk7computingããnormanããpctoolsããprevxããrisingããsecurecomputingããsunbeltããemsisoftããarcabitããcpsecureããspamhausããcastlecopsããthreatexpertããwilderssecurityããwindowsupdateã
ããããã¯ãŒã¯ç®¡çè ã¯ãããŒãçªå·455ã§å¢ãããã©ãã£ãã¯ã§ãææã³ã³ãã¥ãŒã¿ãã¿ã€ãã ããšãã§ããŸããææåŸã¯ãã³ã³ãã£ãã«ãŒã¯ææããã³ã³ãã¥ãŒã¿ã®IPã¢ãã¬ã¹ã以äžã®ãµã€ã ã®äžã€ããåŒã³åºãã調ã¹ãŸãã
⢠http://checkip.dyndns.org
⢠http://getmyip.co.uk
⢠http://www.getmyip.orgãã¢ããããŒãã®ã¢ãã¬ã¹ã¯ãæ¥ä»ã䜿ãããšã«ãã£ãŠã以äžã®ãã¡ã€ã³ããèšç®ãããŸãã
⢠ask.com
⢠baidu.com
⢠google.com
⢠msn.com
⢠www.w3.org
⢠yahoo.comããã®ãã¡ã€ã³ã«ã¢ã¯ã»ã¹ããã³ã³ãã¥ãŒã¿ã¯ãææã®å±éºæ§ããããŸãã
ã³ã³ãã£ãã«ãŒã®é€å»æ¹æ³
ãäžæŠã³ã³ãã£ãã«ãŒã«ææããã·ã¹ãã ãã¯ãªãŒã³ã«ããæ¹æ³ã«ã€ããŠã¯ã以äžã®Microsoftã® URLãåç §ããŠãã ãããhttp://www.microsoft.com/japan/protect/computer/viruses/worms/conficker.mspx
ãã³ã³ãã£ãã«ãŒã¯è€éãªæ§æã§ãã·ã¹ãã å ã®è€æ°ç®æãåææ»æããåé€äœæ¥ãæéãããã ãŸããããã§ãã¢ã³ããŠã€ã«ã¹è£œåãã€ã³ã¹ããŒã«ããŠã¹ãã£ã³ãããããããããã¯ãææ°ã㌠ãžã§ã³ã®MSRTïŒæªæ§ãœãããŠã§ã¢åé€ããŒã«ïŒã®å©çšããå§ãããŸãã
http://www.microsoft.com/japan/security/malwareremove/default.mspx
ãŸãšãïœã³ã³ãã£ãã«ãŒã«ææããªãããã«
ïŒïŒWindowsã®ã¢ããããŒããææ°ã®ãã®ã«ãã
ïŒïŒãŠãŒã¶ãŒã¢ã«ãŠã³ããšå ±æãã¡ã€ã«ã®ãã¹ã¯ãŒããè€éãªãã®ã«å€æŽãã
ïŒïŒG DATA補åãã¯ãããšãããŠã€ã«ã¹å¯Ÿçãœããã䜿çšãã
ïŒã¯ã¯ãã³ãææ°ã®ç¶æ ã«ããããŒããã£ã¹ã¯å šäœããŠã€ã«ã¹ã¹ãã£ã³ããïŒ
ïŒïŒUSBã¡ã¢ãªã䜿çšããåã«ãŠã€ã«ã¹ã¹ãã£ã³ããããG DATA Malware Whitepaper: Questions and Answers to Conficker
Copyright (c) 2009 G DATA Software AG
ãªã ãŒããã«ãã£ã¹ã¯ãæ¿ãããšããéåžžã§ããã°ã
ãã®ãã£ã¹ã¯ãŸãã¯ããã€ã¹ã«ã¯ãè€æ°ã®çš®é¡ã®ã³ã³ãã³ããå«ãŸããŠããŸãã
Windowsãå®è¡ããåäœãéžãã§ãã ããã
- ç»åãå°å·ãã
- åçã®å°å·ãŠã£ã¶ãŒã䜿çš
- ã€ã¡ãŒãžã®ã¹ã©ã€ã ã·ã§ãŒã衚瀺ãã
- Windows ãã¯ãã£ãšFAXãã¥ãŒã¢äœ¿çš
- ç»åãé²èЧãã
- ****䜿çš
- ãã©ã«ããéããŠãã¡ã€ã«ã衚瀺ãã
- ãšã¯ã¹ãããŒã©äœ¿çš
- äœãããªã
OK ãã£ã³ã»ã«
ãããã
ãã®ãã£ã¹ã¯ãŸãã¯ããã€ã¹ã«ã¯ãè€æ°ã®çš®é¡ã®ã³ã³ãã³ããå«ãŸããŠããŸãã
Windowsãå®è¡ããåäœãéžãã§ãã ããã
- ãã©ã«ããéããŠãã¡ã€ã«ã衚瀺ãã
- ããã€ã¹ã§æäŸãããããã°ã©ã 䜿çš
- ç»åãå°å·ãã
- åçã®å°å·ãŠã£ã¶ãŒã䜿çš
- ã€ã¡ãŒãžã®ã¹ã©ã€ã ã·ã§ãŒã衚瀺ãã
- Windows ãã¯ãã£ãšFAXãã¥ãŒã¢äœ¿çš
- ç»åãé²èЧãã
- ****䜿çš
- äœãããªã
OK ãã£ã³ã»ã«
ããã§åºãŠãã ããã€ã¹ã§æäŸãããããã°ã©ã 䜿çšãéžæããã¯ãªãã¯ããããšã§ ãŠã€ã«ã¹ææãè¡ããããã§ããïŒUSBå ã® autorun.inf ãåé¡ïŒïŒ
æåã«èšè¿°ãã RUNDLLãšã©ãŒã¯ãã¢ã³ããŠã€ã«ã¹ãœãããããã®å®è¡ãã¡ã€ã«ã®åãã忢ããŠãããã§ãã
read comments (0)ITpro: ã»ãã¥ãªãã£ã»ããŒã«ïŒãŠã€ã«ã¹å¯Ÿçã®æ å ±
Author: 管çè
ã»ãã¥ãªãã£ã»ããŒã«ïŒãŠã€ã«ã¹ ïŒ ITpro:
ã»ãã¥ãªãã£ã»ããŒã«ããããçªãææ°æ»æææ³ãšïŒå¯Ÿçè¡ãæ²èŒããã»ãã¥ãªãã£ã»ãµã€ãã
æ¥çµBP瀟ãéå¶ããïŒITãããã§ãã·ã§ãã«ã«åããç·åæ
å ±ãµã€ããITproããæäŸ
http://itpro.nikkeibp.co.jp/securityhole/index.html
ç¯çœªããŒã±ãããèæ¯ã«ïŒãŠã€ã«ã¹/ãããã¯æ¬¡ã ã«ç»å Žããããããå®æåºŠãé«ãïŒãŠãŒã¶ãŒãã ãŸããŠææãããæå£ãäžå±€å·§åŠã«ãªã£ãŠããããŠãŒã¶ãŒã«æ°ä»ãããã«ãŠã€ã«ã¹ãããããå¿ã³èŸŒãŸããïŒããã°âèŠããªãåâãé²ãã§ããã®ã§ããããŠãŒã¶ãŒãèªå·±é²è¡ããã«ã¯ïŒæ°ãããã匱æ§ãæ»ææ¹æ³ã®æ å ±ãçŽ æ©ããã£ãããïŒæ»æãžã®åããæŽããå¿ èŠããããæ¬ãµã€ãã§ã¯ïŒææ°ã®ãã匱æ§ãã€ã³ã·ãã³ãïŒãããã«é¢ããæ å ±ãããã¯ã¢ããããŠãç¥ããããã
Adobe Flash Player ã®ããŒãžã§ã³ãã§ãã¯
Author: 管çè
Adobe Flash Player ã®ããŒãžã§ã³ã¢ãããã©ã®PCã§ãããå¿ããããšã床ã ãããŸããããããªãšãä»ã€ã³ã¹ããŒã«ãããŠããããŒãžã§ã³ãææ¡ã§ããã°ãäœåãåã€ã³ã¹ããŒã«ãããªããŠãã¿ãŸãã
ããããããŒãžã§ã³ãã§ãã¯ã®ããŒãžãã©ããªã®ãæ¢ãã®ãé¢åãªã®ã§ã¡ã¢ãšããŠãæ§ããŠãããŸãã
Adobe Flash Player ããŒãžã§ã³ãã§ãã¯
http://www.adobe.com/jp/software/flash/about/

