batnikiã¯ãã¹ãŠéåžžã«ã·ã³ãã«ãªãã®ã®ããã«èŠããAUTOEXEC.BATãæªçšãããŠä»¥æ¥ãã»ãšãã©å¿ããããŠããããšãç解ããŠããŸãã ãããïŒ ãã®æçš¿ã§ã¯ããããã®ã¢ã€ãã¢ãã²ã£ããè¿ããŠããã¹ãŠãéã®ããã«èŠããããšãäŒããããšããŸãã ããã£ãŒã·ã£ãã¯ãã¬ã€ã³ãã¡ãã¯æ©èœã®ç¹ã§ãããã«è»œããŠåŒ·åã§ããããšã¯ã¹ããã€ãã¯åºæ¬ã«ããã«ãä»ããŠåé¡ãããããæªããããŸããã
ïŒæ³šæïŒ3 MBã®å³è§£ãããæèã®æµããšäžé£ã®ã¹ã¯ãªããïŒ
ã©ããã£ãŠããã«å°éããŸãããïŒ
2 GBã®RAMã®æå°ã·ã¹ãã èŠä»¶ãåããWindows 7 x64ã®ããã¯ã¹ã«ééããŸããïŒ ãããŠããããã®ã®ã¬ãã€ããã¹ãŠã«ããšã¯ã¹ããã€ãããã©ã€ããã€ãªã©ã®éå¢ãããŠãŒã¶ãŒãä¿è·ã§ããæ°ãããã€ãã®ã³ãŒãããªãã®ã§ã¯ãªãããšæã£ãŠããŸãã ã ããã¯ãMSã®5幎éã«ããããã¹ãŠã®OSã®æšåã§ãïŒ å°ãªããšãäœããã®ä¿è·ã®ããã®æ段ãå¿ èŠã§ããïŒ ããããããããç·šãæ¹æ³ããããŠæšæºçãªæ段ã§ããïŒ ããã£ã·ã£ãã®å©ããåããŠã ãããŠã©ããã£ãŠïŒ ãããç解ããã«ã¯ããã®ã·ãŒããæåŸãŸã§èªãå¿ èŠããããŸãã 8ïŒ
çè«
ãšã¯ã¹ããã€ãã¬ã¹ãã³ã¹ã®åçŽåãããçè«ã§ã¯ããã¹ãŠã¯æ¬¡ã®ããã«ãªããŸãã å®éã«ã¯ãããã¯ãã°ãã°æ¬¡ã®ããã«ãªããŸãïŒã€ã³ã¿ãŒãããããµãŒãã£ã³ããŠãããŠãŒã¶ãŒã¯ãæ£çŽã«ãããã³ã°ããããµã€ãã«ã¢ã¯ã»ã¹ããŸããããã§ãæçšãªæ å ±ãšãšãã«ãJavaScriptãŸãã¯JavaScriptãžã®ãªãã€ã¬ã¯ããæäŸãããŸã.USER-AGENTãåæããããšã§ããã©ã°ã€ã³ã«é¢ããæ å ±ãªã©ãæäŸãããŸã ãŠãŒã¶ãŒã«æ©èœãããšã¯ã¹ããã€ãããŠãŒã¶ãŒã«æäŸããŸãã ãã®åŸãããã€ã®æšéŠ¬ã¯ãŠãŒã¶ãŒã®ãã·ã³ã«ããŠã³ããŒããããèµ·åãããã·ã¹ãã ã«ç»é²ããããã®æ±ãä»äºãå§ããŸãã
Google Anti-Malware Teamããã®ç»åã®Drive-Byã«é¢ããç»åã®çŽå€±ã
ãããããªæµã®èšèªã§èªã
ïŒ-SGããžã¥ãªã¢ãæ£ããã次ã®æã®æå³ã®ç¯å²å ã§ããããæ確ã«ãªãããã«ããã®ã³ã¡ã³ããåé€ããŠãã ããã-ç·šéè ãæå³ã«åŸã£ãŠïŒã¯ãããèšæ¶ãå²ãåœãŠããåŸãäœãç解ã§ããŸãããã³ã¡ã³ããïŒ
ããå°ãæãäžãããšããã®ãããªãšã¯ã¹ããã€ãããã¯ã§ã¯ãå€ãã®å ŽåïŒã»ãšãã©ã®å ŽåïŒç ç²è ããã»ã¹äžã«ãã€ããŒããèªèº«ã«ã¡ã¢ãªãå²ãåœãŠãå¿ èŠãªã·ã¹ãã æ©èœãæ€çŽ¢ããã€ã³ã¿ãŒãããããããŒã«ã«ãšãªã¢ã«ãã¡ã€ã«ãä¿åããCreateProcessãŸãã¯ãããŸãã«ShellExecuteãå®è¡ããŸããç¹æš©ææ Œã®åé¡ã¯ãããŠã³ããŒããããã®ã«ãªãã€ã¬ã¯ããããŸãã ãã¹ãŠãåºæ¬çã«ã·ã³ãã«ã§æ確ã§ãã ãããŠãããã«ã€ããŠã©ãããã°ããã§ããïŒ åŒ±ç¹
æšæºããŒã«
Windows 7ã§ã¯ãããã°ã©ã ãå¶éãŸãã¯æ¡åŒµããæ¹æ³ãããã€ããããŸãã ããããæãäžè¬çãªæ段ã¯ã ACLãšããããçš®é¡ã®ããªã·ãŒã§ãã
Microsoftã®Visual SRPïŒãœãããŠã§ã¢å¶éããªã·ãŒïŒ
ååãšããŠãç¹å¥ãªãŠãŒã¶ãŒã¢ã«ãŠã³ããäœæããã·ã¹ãã ã«ç¹å¥ãªæš©å©ãå²ãåœãŠãæœåšçã«è匱ãªã¢ããªã±ãŒã·ã§ã³ããã®äžã«çœ®ãããšã¯èª°ã«ãšã£ãŠãç§å¯ã§ã¯ãããŸããã ããŠã¹ã§ã®5åéã®ã¿ãã·ã³ã°-ããã§å®äºã§ãã åé¡ã¯ãç¹ã«ç®¡çè ããããã¯ãŒã¯äžã®ãã¹ãŠã®ãã·ã³ã§ãããè¡ãå¿ èŠãããå ŽåããŸããªãŠãŒã¶ãŒããããè¡ãããšã§ãã ãããã£ãŠãããããã¡ã€ã«ãäœæããŠã¿ãŸããããããããã¡ã€ã«ã§ã¯ãã»ãŒåãããšãè¡ãã ãã§ãããã«äœ¿ãããããããã䜿ãããããªã£ãŠããŸãã
ããã£ã·ã£ã
åèšïŒããããã¡ã€ã«ã¯ãæšæºæš©éãæã€ãŠãŒã¶ãŒãäœæããç¹å®ã®ãœãããŠã§ã¢ã®ã¿ãå®è¡ããããã«ãããã®æš©éãå€æŽããæåŸã«ãŠãŒã¶ãŒã«ãšã£ãŠééçã§äŸ¿å©ãªãã®ã«ããå¿ èŠããããŸãã å§ããŸããã...
1.ãŠãŒã¶ãŒãäœæããŸãã æ¯åã
net user saferun_user Passw0rd /add
ããã§ã¯ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããäŸãšããŠç€ºããŠããŸããããããã¯ïŒ randomïŒ ã§åžéããå¿ èŠããããŸãããããã£ãŠããã¹ãŠã®ããããã¡ã€ã«ãŠãŒã¶ãŒããã·ã³äžã§åããŠãŒã¶ãŒåãšãã¹ã¯ãŒããæã£ãŠããããšãããããŸããã ãããŠãBackdoor.Bat.Hren.aã®ãããªãã®ã«ãªããŸããããŸã æ€åºããå¿ èŠããããŸã...ïŒïŒïŒ
2.æš©éãå€æŽããŸãã ãããšããã§ã«åé¡ããããŸã
次ã®ããã«ãPowerShellã䜿çšããŠAppLockerã«å®è¡æš©éãå²ãåœãŠãå¿ èŠããããŸãã
PS C:\> Get-ApplockerFileInformation -Directory 'C:\Program Files (x86)\Adobe\' -Recurse -FileType Exe | New-ApplockerPolicy -RuleType Publisher -User SafeRun_user -RuleNamePrefix Adobe -Optimize -Xml > Adoby.xml
PS C:\> Set-AppLockerPolicy âXmlPolicy Adoby.xml
ãã ãããã®allãªããããã¯ãã¹ãŠããWindows 7ã®UltimateããŒãžã§ã³ãšEnterpriseããŒãžã§ã³ã§ã®ã¿äœ¿çšå¯èœã§ããã ãããã£ãŠãWindows 7ã®ããŒã ããŒãžã§ã³ã®ä»£æ¿ãšããŠããã¢ã¬ã³ã¿ã«ã³ã³ãããŒã«ïŒ ãã©ãŒã©ã ãžã®ãªã³ã¯ -åè«ã§ã¯ãããŸããïŒã䜿çšã§ããŸããããã¯ãå®è¡å¯èœãªããã°ã©ã ã«é¢ããæ å ±ãä¿åããŸãã
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\UID\App Restrictions
ããã¯ãæ¿æ²»å®¶ãçã«ããããšãæå³ããŸããããã¯äžäŸ¿ã§ãããããç¹ã«Vistaããå§ãŸã£ãŠçŽ æŽãããICACLSããŒã ãç»å ŽãããããACLã䜿çšããŸãã ååãšããŠã以äžã«èšè¿°ãããŠãããã®ã¯ãã¹ãŠXCACLSã䜿çšããŠXPã«æ圱ã§ããŸãããããã©ã«ãã§ã¯XPã«ã¯ãã®ãããªã³ãã³ãã¯ãªãããªãœãŒã¹ãããããã±ãŒãžã«ã®ã¿å«ãŸããŠããŸãã
åèšã§ãWindows 7ã§ã¯ãã°ã«ãŒãã®ã¢ã¯ã»ã¹èš±å¯ã®ãããã§ãæåã«ãŠãŒã¶ãŒãæ¢å®ã®ã°ã«ãŒãããåé€ããŠãã©ãã§ããã¡ã€ã«ãäœæã§ããããã«å¶éããŸãã
net localgroup users saferun_user /delete
ãããŠä»ã芪æãªããŠãŒã¶ãŒã
icacls %USERPROFILE% /deny saferun_user:(OI)(IO)(WDAC,WO,X)
ïŒ-ãšãã£ã¿ãããªãã¯ãŸã äœãããã§ãã¯ããŠä¿®æ£ããããã«ç§ã«é Œãã ãããã³ã¡ã³ãã殺ãããšãå¿ããªãã§ãã ãããïŒ
ãã©ã¡ãŒã¿ãŒãïŒOIïŒïŒIOïŒãã¯ãæå®ããããã©ã«ããŒã«ãããã¹ãŠã®ãã¡ã€ã«ã芪ã®æš©éãç¶æ¿ããŠããããšã瀺ããŠããããã§ããããã¯å®éã«ã¯å®è¡ãæåŠããŸãã æš©å©ã»ãããæ©èœããããšã確èªããŸãã
C:\Users\Golovanov>runas /user: saferun_user cmd.exe
Enter the password for saferun_user:
Attempting to start cmd.exe as user âsaferun_user" ...
C:\Windows\system32> cd %temp%
C:\Users\saferun_user\AppData\Local\Temp>%windir%notepad.exe
C:\Users\saferun_user\AppData\Local\Temp>copy c:\windows\notepad.exe .
1 file(s) copied.
C:\Users\saferun_user\AppData\Local\Temp>.\notepad.exe
Access is denied.
åèšïŒWindowsãã©ã«ããŒã®Notepad.exeãæ©èœããTEMPãã©ã«ããŒã«ã³ããŒããŠå®è¡ãããšãã¢ã¯ã»ã¹ãæåŠãããŸãã ãã¹ãŠãOKã§ãã ç¶ããŸãããã
3.䜿ãããã
䜿ããããããããã«ãæ°ãããŠãŒã¶ãŒã®äžã§æ倧æ°ã®ç°ãªããã©ãŠã¶ãŒã«å¯ŸããŠééçãªèµ·åããµããŒãããå¿ èŠããããŸãã ãã®ããã«ããããšããå§ãããŸãïŒ
1.çŸåšã®ãŠãŒã¶ãŒã®ãã©ãŠã¶ãŒãããã¡ã€ã«ãæ°ãããŠãŒã¶ãŒã«ã³ããŒããŸãã ããšãã°ãFirefoxã®å Žåã次ã®ããã«ãªããŸãã
xcopy /E /I /C /Y /Q /H /R %APPDATA%\Mozilla\* C:\Users\saferun_user\AppData\Roaming\Mozilla\
2.ãã©ãŠã¶ãŒã®Runasèµ·åãç»é²ããVBSãã©ãŠã¶ãŒãå«ããã©ã«ããŒã«ãã¡ã€ã«ãäœæããŸãã Runasã®STDINã§ãã¹ã¯ãŒããåä¿¡ããéã®å¶éãåé¿ããã«ã¯ãVBSãä»ããŠãããè¡ãå¿ èŠããããŸãã Fine Microsoftã¯ãOSã®ã»ãã¥ãªãã£ã匷åããããã«ãããè¡ããŸãã ã ãã€ãã®ããã«ãã»ãã¥ãªãã£ã¯äŸç¶ãšããŠçããããhemoã¯å¢å ããŸããã VBSãã¡ã€ã«ã¯ãããšãã°æ¬¡ã®ããã«ãªããŸãã
Option explicit
Dim oShell
set oShell= Wscript.CreateObject("WScript.Shell")
oShell.Run "RunAs /noprofile /user:saferun_user Firefox.exe"
WScript.Sleep 1000
oShell.Sendkeys "Passw0rd"
oShell.Sendkeys "{ENTER}"
Wscript.Quit
å°ãã³ã¡ã³ãã ã€ã³ã¿ãŒãããäžã§ã¯ãSendkeysãäžéšã®ããŒãžã§ã³ã§èŠã€ãããªããçŠæ¢ãããŠãããšæžããŠããŸãããWindows 7 ProfessionalãUltimateãHomeã§ã¯ãã¹ãŠãæ©èœããŸãã ç¶ããŸãã
3.ãã©ãŠã¶ãŒã¢ã€ã³ã³ã䜿çšããŠãæ°ããäœæããVBSãã¡ã€ã«ãžã®ã·ã§ãŒãã«ãããäœæããŸãã
Set oWS = WScript.CreateObject("WScript.Shell")
sLinkFile = "C:\firefox_saferun.LNK"
Set oLink = oWS.CreateShortcut(sLinkFile)
oLink.TargetPath = "C:\Program Files (x86)\Mozilla Firefox\firefox.vbs"
oLink.IconLocation = "C:\Program Files (x86)\Mozilla Firefox\firefox.exe,0"
oLink.WorkingDirectory = "C:\Program Files (x86)\Mozilla Firefox\"
oLink.Save
4.ãŠãŒã¶ãŒããã©ãŠã¶äžã«ãã§ã«æã£ãŠãããã¹ãŠã®ã·ã§ãŒãã«ãããæ°ããã·ã§ãŒãã«ããã«çœ®ãæããŸãã åè«ã ãã¹ã¯ãããäžã®å¥ã®ãã©ã«ããŒã«ã·ã§ãŒãã«ãããé 眮ããããã§ãŠãŒã¶ãŒèªèº«ã決å®ããŸãã
ããããã¡ã€ã«ãªã¹ã
å šäœãšããŠããã¹ãŠãåé¡ãªãããã«èŠããŸãã
::Writed by: Sergey.Golovanov at kaspersky.com for habrahabr.ru @echo on @Echo This batch file will create a new user for browsers with no rights to run downloaded from Internet files. Pause ::Setup new user:: set safeusername=saferun_user_%random% set safepassword=%random%Ai%random% echo Login: %safeusername% echo Password: %safepassword% net user %safeusername% /delete del Browserlist4saferun.txt net user %safeusername% %safepassword% /add ::init new user profile:: echo Option explicit > init_new_user_profile.vbs echo Dim oShell >> init_new_user_profile.vbs echo set oShell= Wscript.CreateObject("WScript.Shell") >> init_new_user_profile.vbs echo oShell.Run "RunAs /profile /user:%safeusername% ping" >> init_new_user_profile.vbs echo WScript.Sleep 1000 >> init_new_user_profile.vbs echo oShell.Sendkeys "%safepassword%" >> init_new_user_profile.vbs echo oShell.Sendkeys "{ENTER}" >> init_new_user_profile.vbs echo Wscript.Quit >> init_new_user_profile.vbs call cscript init_new_user_profile.vbs ping -n 10 localhost >> nul del init_new_user_profile.vbs ::Setup privileges for new user:: net localgroup users %safeusername% /delete icacls c:\users\%safeusername%\ /deny %safeusername%:(OI)(IO)(WDAC,WO,X) ::Setup browsers:: :FindOpera if exist %APPDATA%\Opera\ xcopy /E /I /C /Y /Q /H /R %APPDATA%\Opera\* C:\Users\%safeusername%\AppData\Roaming\Opera\ if exist "%Programfiles%\Opera\Opera.exe" goto run4opera if exist "%Programfiles(x86)%\Opera\Opera.exe" goto run4operax86 Goto FindFireFox :run4opera echo Opera^|%Programfiles%\Opera>> Browserlist4saferun.txt Goto FindFireFox :run4operax86 Set Browsername=Opera echo Opera^|%Programfiles(x86)%\Opera>> Browserlist4saferun.txt Goto FindFireFox :FindFireFox if exist %APPDATA%\Mozilla\ xcopy /E /I /C /Y /Q /H /R %APPDATA%\Mozilla\* C:\Users\%safeusername%\AppData\Roaming\Mozilla\ if exist "%Programfiles%\Mozilla Firefox\Firefox.exe" goto run4Firefox if exist "%Programfiles(x86)%\Mozilla Firefox\Firefox.exe" goto run4Firefoxx86 Goto FindChrome :run4Firefox echo Firefox^|%Programfiles%\Mozilla Firefox>> Browserlist4saferun.txt Goto FindChrome :run4Firefoxx86 echo Firefox^|%Programfiles(x86)%\Mozilla Firefox>> Browserlist4saferun.txt Goto FindChrome :FindChrome If exist %LOCALAPPDATA%\Google\Chrome\Application\chrome.exe goto run4chrome Goto FindIE :run4chrome ::// Can work for some versions of Chrome by not stable. Dissabled for performance. ::xcopy /E /I /C /Y /Q /H /R %LOCALAPPDATA%\Google\Chrome\* C:\Users\%safeusername%\AppData\Local\Google\Chrome\ ::for /r C:\Users\%safeusername%\AppData\Local\Google\Chrome\ %%C in (*.exe) do icacls %%C /grant %safeusername%:(X) ::for /r C:\Users\%safeusername%\AppData\Local\Google\Chrome\ %%C in (*.dll) do icacls %%C /grant %safeusername%:(X) ::echo Chrome^|C:\Users\%safeusername%\AppData\Local\Google\Chrome\Application\>> Browserlist4saferun.txt Goto FindIE :FindIE ::// TODO A lot of XCOPYs if exist "%LOCALAPPDATA%\Microsoft\Internet Explorer" ( xcopy /E /I /C /Y /Q /H /R "%USERPROFILE%\Favorites\*" "C:\Users\%safeusername%\Favorites\" xcopy /E /I /C /Y /Q /H /R "%LOCALAPPDATA%\Microsoft\Internet Explorer\*" "C:\Users\%safeusername%\AppData\Local\Microsoft\Internet Explorer\" xcopy /E /I /C /Y /Q /H /R "%LOCALAPPDATA%\Microsoft\Windows\History\*" "C:\Users\%safeusername%\AppData\Local\Windows\History\" xcopy /E /I /C /Y /Q /H /R "%APPDATA%\Roaming\Microsoft\Windows\Cookies\*" "C:\Users\%safeusername%\AppData\Roaming\Microsoft\Windows\Cookies\" ) if exist "%Programfiles(x86)%\Internet Explorer\iexplore.exe" goto run4iex86 if exist "%Programfiles%\Internet Explorer\iexplore.exe" goto run4ie :run4iex86 echo IExplore^|%Programfiles(x86)%\Internet Explorer>> Browserlist4saferun.txt goto MakeLinks :run4ie echo IExplore^|%Programfiles%\Internet Explorer>> Browserlist4saferun.txt ::Make links:: :MakeLinks rd /s /q %USERPROFILE%\Downloads\Browser rd /s /q %USERPROFILE%\Desktop\SafeLinks mklink /d %USERPROFILE%\Downloads\Browser C:\Users\%safeusername%\Downloads mkdir %USERPROFILE%\Desktop\SafeLinks echo on For /f "tokens=1,2 delims=|" %%A in (Browserlist4saferun.txt) do ( echo Option explicit > "%%B\%%A.vbs" echo Dim oShell >> "%%B\%%A.vbs" echo set oShell= Wscript.CreateObject^("WScript.Shell"^) >> "%%B\%%A.vbs" echo oShell.Run "RunAs /user:%safeusername% %%A.exe" >> "%%B\%%A.vbs" echo WScript.Sleep 1000 >> "%%B\%%A.vbs" echo oShell.Sendkeys "%safepassword%" >> "%%B\%%A.vbs" echo oShell.Sendkeys "{ENTER}" >> "%%B\%%A.vbs" echo Wscript.Quit >> "%%B\%%A.vbs" echo Set oWS = WScript.CreateObject^("WScript.Shell"^) > "%USERPROFILE%\Desktop\SafeLinks\%%A.lnk.vbs" echo sLinkFile = "%USERPROFILE%\Desktop\SafeLinks\%%A_saferun.LNK" >> "%USERPROFILE%\Desktop\SafeLinks\%%A.lnk.vbs" echo Set oLink = oWS.CreateShortcut^(sLinkFile^) >> "%USERPROFILE%\Desktop\SafeLinks\%%A.lnk.vbs" echo oLink.TargetPath = "%%B\%%A.vbs" >> "%USERPROFILE%\Desktop\SafeLinks\%%A.lnk.vbs" echo oLink.IconLocation = "%%B\%%A.exe,0" >> "%USERPROFILE%\Desktop\SafeLinks\%%A.lnk.vbs" echo oLink.WorkingDirectory = "%%B\" >> "%USERPROFILE%\Desktop\SafeLinks\%%A.lnk.vbs" echo oLink.Save >> "%USERPROFILE%\Desktop\SafeLinks\%%A.lnk.vbs" ) for /r %USERPROFILE%\Desktop\SafeLinks\ %%p in (*.vbs) do cscript %%p for /r %USERPROFILE%\Desktop\SafeLinks\ %%v in (*.vbs) do del %%v :: Open Explorer with links:: explorer %USERPROFILE%\Desktop\SafeLinks\ :: Create Uninstall:: echo @echo off > uninstall_%~n0.bat echo net user %safeusername% /del >> uninstall_%~n0.bat echo rd /s /q %USERPROFILE%\Downloads\Browser >> uninstall_%~n0.bat echo rd /s /q %USERPROFILE%\Desktop\SafeLinks >> uninstall_%~n0.bat echo rd /s /q C:\Users\%safeusername%\ >> uninstall_%~n0.bat echo For /f "tokens=1,2 delims=|" %%%%A in (Browserlist4saferun.txt) do del "%%%%B\%%%%A.vbs" >> uninstall_%~n0.bat echo del Browserlist4saferun.txt >> uninstall_%~n0.bat echo del %%0 >> uninstall_%~n0.bat :Exit
ãã¹ãäž
ããŠãä»åºŠã¯ããããã¹ãŠéçã§ã©ã®ããã«æ©èœãããè©ŠããŠã¿ãŸãããïŒ
1.ã¢ã³ããŠã€ã«ã¹ããªãã«ããŠãJAVAãªã©ã®ããŠã³ã°ã¬ãŒãããŸãïŒã«ããã«ã¯ããã«äžå®ãæããŸããïŒã
2.ãªã¹ãããããããã¡ã€ã«ãã³ããŒããŠè²Œãä»ããŸãã
3. saferun.batãšããŠä¿åããæ·±åŒåžããŠããã«ã¯ãªãã¯ããŸãã
4.ã³ã³ãœãŒã«ãç¹æ» ãããšã¯ã¹ãããŒã©ãŒãŠã£ã³ããŠãéããŸãã ãŠã£ã³ããŠãã·ã§ãŒãã«ããã§èŠãŠãããèããŸãã
5.ä»»æã®ãã©ãŠã¶ãŒãéžæããŸãã YouTubeã«ã¢ã¯ã»ã¹ãããã¹ãŠãæ©èœããããšãã¯ãªãã¯ããããšãªã©ã確èªããŸãã
6.次ã«ãGoogleã«ã¢ã¯ã»ã¹ããŠãæã人æ°ã®ããRunetãã©ãŠã¶ããæ¢ããŸãïŒããã¯ããã«ããããã«ãŒãç¡æã§ããŠã³ããŒãããæ¹æ³ã瀺ãã効ã§ãïŒã ããã€ãã®ãªã³ã¯ãã¯ãªãã¯ãããšãã³ã³ãã¥ãŒã¿ãŒãçãããããããå§ããŸãã ã¡ãã£ãšåŸ ã£ãŠãŸãã æªãããšã¯äœãèµ·ãããªãã£ãããã§ãã Process ExplorerãèŠããšããã©ãŠã¶ãJAVA.exeãèµ·åããæ°ãããŠãŒã¶ãŒãæ£åžžã«ç¶æ¿ããŠããããšãããããŸãã
7.ããã§ãæ°ãããŠãŒã¶ãŒã®äžæãã£ã¬ã¯ããªã«ç§»åããŠã次ã®å 容ã確èªããŸã...
8.ãã¡ã€ã«ã____ 991.exeãã«å¯Ÿããæš©éã確èªããŸã
9.äœæããããŠãŒã¶ãŒã®äžã§cmd.exeãåãé¢ããŸãã ãã¹ã¯ãŒãã¯ãããšãã°ããã©ãŠã¶ã®EXEã®æšªã«ããVBSã¹ã¯ãªããã§ç¢ºèªã§ããŸã
10.æ°ããã³ã³ãœãŒã«ã§cdïŒ tempïŒ ãäœæãããã\ ____ 991.exeããšæžã蟌ã¿ãŸãã EnterãæŒããŠãã ããïŒ
11. URA-URA !!! ããã¯åå©ã§ãã
12.詳现ãæ°ã«ãã人
C:\Users\saferun_user_31714\AppData\Local\Temp>d:\md5.exe ____991.ex ____991.ex : 04DA16B5447D8F2B4BD23AFD469FB153
ãã®ãã¡ã€ã«ãéå§ãããå Žåãé¢çœãåçãšæ¯æã端æ«ã§ã®äœæ¥èŠæ±ã衚瀺ãããŸãã
çµè«ã®ä»£ããã«
ããããã¡ã€ã«ã¯ã管çè ãšåçŽãªãŠãŒã¶ãŒã®äž¡æ¹ããWindows 7ãæäœããéã«ããã©ã€ããã€æ»æããšã¯ã¹ããã€ãããã®ä¿è·ã«éåžžã«åœ¹ç«ã¡ãŸãã ã¯ãã圌ã¯ç¹æš©ã®å¢å ã«äŒŽããã€ããŒãã®çè«çãªå¶éãæã£ãŠããŸããããã®ãããªå©ç¹ã¯ãã£ãã«èŠãããŸããã ããããã¡ã€ã«ã䜿çšããå Žåã®é·æ-éåžžã«è¿ éã«ç·šéããé»åã¡ãŒã«ã¯ã©ã€ã¢ã³ãããªãã£ã¹ããã°ã©ã ãªã©ã®æ°ããããã°ã©ã ã®ãµããŒããè¿œå ã§ããŸãã ãã¥ãŒãã³ã°ãæè»æ§ãã¯ãŒã«ãã¹ãã¯ãŒã«ãã¹ã¯éåžžã«éèŠã§ãããLCã§ã¯ãããéåžžã«ããç解ããŠããŸãã
èè ã®ãã®æèã®æµããæåŸãŸã§èªãã§ãããŠããããšãããããŠãã€ãã¹ãã¯ãªãã¯ããããšã¯ãããŸããã 8ïŒããã°ã£ãŠïŒ
PSã ãã®ããããã¡ã€ã«ã¯ãLC補åã®äžéšã§ããSafeBrowserãšã¯é¢ä¿ãããŸããã
PPPã ããããã¡ã€ã«ã¯éåžžã«äŸ¿å©ãªã¢ã³ã€ã³ã¹ããŒã«ãäœæããŸã-äœããçªç¶ééã£ãå Žåã«åããŠã
PPPã ãã€ãã®ããã«ããã¬ã³ããªãŒãªãŠãŒã¶ãŒk1kãã³ã¡ã³ãã«ãããããŠãèšäºã®èè ãè£ ããŸãã ããã§ãã ãããããé¡ãããŸãïŒ