¡Ã±£¤·¥Õ¥¡¥¤¥ë¡¦¥Õ¥©¥ë¥À¤¬É½¼¨¤Ç¤¤Ê¤¤¡£
¤½¤ì¤¬¡¢°ìÈֺǽé¤Ëµ¤¤Å¤¤¤¿°ÛÊѤǤ·¤¿¡£
Ä̾±£¤·¥Õ¥¡¥¤¥ë¤ò¸«¤¨¤ë¾õÂÖ¤ËÀßÄꤷ¤Æ¤¢¤Ã¤¿¤Î¤Ç¡¢
¤ª¤«¤·¤¤¤Ê¤È»×¤¤¡¢¥Õ¥©¥ë¥À¥ª¥×¥·¥ç¥ó¤ò³«¤¡¢
¡Ö¤¹¤Ù¤Æ¤Î¥Õ¥¡¥¤¥ë¤È¥Õ¥©¥ë¥À¤òɽ¼¨¤¹¤ë¡×
¤òŬÍѤ·¤Þ¤·¤¿¤¬¡¢Ä¾¤ê¤Þ¤»¤ó¡£
ºÆ¤Ó¥Õ¥©¥ë¥À¥ª¥×¥·¥ç¥ó¤ò³«¤¤¤Æ³Îǧ¤·¤Æ¤ß¤ë¤È
¡Ö±£¤·¥Õ¥¡¥¤¥ë¤ª¤è¤Ó±£¤·¥Õ¥©¥ë¥À¤òɽ¼¨¤·¤Ê¤¤¡×
¤ËÀßÄ꤬Ìá¤Ã¤Æ¤·¤Þ¤Ã¤Æ¤¤¤Þ¤¹¡£
¡ÖÊݸ¤ì¤¿¥ª¥Ú¥ì¡¼¥Æ¥£¥ó¥°¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤òɽ¼¨¤·¤Ê¤¤¡Ê¿ä¾©¡Ë¡×
¤Î¥Á¥§¥Ã¥¯¤ò³°¤·¤Æ¤ß¤Æ¤âƱÍͤηë²Ì¤Ç¤·¤¿¡£
¤³¤ì¤Ï¤Þ¤º¤¤¡¢¡¢¡Ê´À¡Ë¤È»×¤¤¡¢
¡Ö±£¤·¥Õ¥¡¥¤¥ë¤¬É½¼¨¤Ç¤¤Ê¤¤¡×¡¡
¤Ç¥°¥°¤Ã¤Æ¤ß¤¿¤È¤³¤í¡¢
¥¦¥£¥ë¥¹¤Ë´¶À÷¤·¤Þ¤·¤¿´ØÏ¢¤Î¥¦¥§¥Ö¥Ú¡¼¥¸¤¬¤º¤é¤ê¡£
¡Ãmmvo.exe ´ØÏ¢¥¦¥£¥ë¥¹
¤¤¤í¤¤¤íÄ´¤Ù¤Æ¸«¤¿¤È¤³¤í¡¢
¡¦±£¤·¥Õ¥¡¥¤¥ë¡¦¥Õ¥©¥ë¥À¤¬É½¼¨¤Ç¤¤Ê¤¤¡£
¡¦¥·¥¹¥Æ¥à¹½À®¥æ¡¼¥Æ¥£¥ê¥Æ¥£(msconfig)¤Î¥¹¥¿¡¼¥È¥¢¥Ã¥×¤Ëmmvo¤¬¤¢¤ë¡£
¡¦³Æ¥É¥é¥¤¥Ö¤Î¥ë¡¼¥È¤Ëautorun.inf¤¬¤¢¤ë¡£
¡¦¥¤¥ó¥¿¡¼¥Í¥Ã¥È°ì»þ¥Õ¥¡¥¤¥ë¤Ëuu.rar¤â¤·¤¯¤Ïuu.exe¤¬¤¢¤ë¡£
¤³¤Îmmvo.exe´ØÏ¢¥¦¥£¥ë¥¹³Îǧ¤Î¤¿¤á¤Î
¾åµ£´¹àÌܤ¹¤Ù¤Æ¤¬»ä¤ÎPC¾å¤Ç³Îǧ¤µ¤ì¤Þ¤·¤¿¡£
¤³¤ä¤Ä¤Ï¡¢USB¥á¥â¥ê¤ò²ð¤·¤Æ´¶À÷¤¹¤ë¥¦¥¤¥ë¥¹¤é¤·¤¯¡£
³Î¤«¤Ë¡¢°ÛÊѤ˵¤¤Å¤¤¤¿Ä¾Á°¤Ë
USB¥á¥â¥ê¤òPC¤Ë¤Ä¤Ê¤¤¤Ç¤¤¤Þ¤·¤¿¡£
¤·¤«¤â¤½¤ÎUSB¥á¥â¥ê¤Ï½ÐÄ¥¤¹¤ëÃοͤËÂߤ·¤Æ¤¤¤¿¤â¤Î¤Ç¡¢
½ÐÄ¥Àè¤Î¥Û¥Æ¥ë¤ÎPC¤«¤é¤È¤«¡¢¤Ê¤«¤Ê¤«¤¢¤ê¤¬¤Á¤Ê´¶¤¸¤¬¤·¤Þ¤¹¡£
¡Ãmmvo.exe ¶î½ü¤Ø¤ÎÆ»Äø
¤Þ¤º¤Ï¡¢
¡¦¥¤¥ó¥¿¡¼¥Í¥Ã¥È°ì»þ¥Õ¥¡¥¤¥ë¤ÎÁ´ºï½ü¡£
¡¦¤¹¤Ù¤Æ¤Î¥É¥é¥¤¥Ö¤Ç¥·¥¹¥Æ¥à¤ÎÉü¸µ¤ò̵¸ú¤Ë¤¹¤ë¡£
¡¦¥·¥¹¥Æ¥à¹½À®¥æ¡¼¥Æ¥£¥ê¥Æ¥£(msconfig)¤Ç
¥¹¥¿¡¼¥È¥¢¥Ã¥×¤ËÅÐÏ¿¤µ¤ì¤Æ¤¤¤ëmmvo¤ò³°¤¹¡£
¤ò¼Â¹Ô¤·¤Þ¤·¤¿¡£
¤½¤·¤Æspybot¤òƳÆþ¡£¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¡¢¸¡º÷¤·¤Æ¡¢¾ïÃ󤵤»¤Þ¤·¤¿¡£
¸¡º÷¤Ç¸«¤Ä¤«¤Ã¤¿¤¤¤¯¤Ä¤«¤Î¥¦¥£¥ë¥¹¤ÏÁ´ºï½ü¡£
NOD32¡Ê£³£°Æü»îÍÑÈǡˤΥ¤¥ó¥¹¥È¡¢¸¡º÷¡¢¾ïÃó¤â¿ä¾©¤µ¤ì¤Æ¤¤¤Þ¤·¤¿¤¬¡¢
¤³¤ì¤ÏºÇ¸å¤ÎºÇ¸å¤Î¼êÃʤˤ·¤è¤¦¤È»×¤¤Æ³Æþ¤Ï¤·¤Þ¤»¤ó¤Ç¤·¤¿¡£
¤½¤·¤Æ¡¢
±£¤·¥Õ¥¡¥¤¥ë¡¢¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤ò´Þ¤à
¡ÖÁ´¤Æ¤Î¥Õ¥¡¥¤¥ë¤¬¸«¤¨¤ë¡×¾õÂ֤ˤ¹¤ë¤Ù¤¯
°Ê²¼¤Î¥ì¥¸¥¹¥È¥êÁàºî¤ò¼Â¹Ô¡£
¼«Æ°µ¯Æ°¤Î¶Ø»ß¤Î¤¿¤á¤Î¥ì¥¸¥¹¥È¥êÁàºî
[HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:000000b5
±£¤·¥Õ¥¡¥¤¥ë¡¦¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤Îɽ¼¨¤Î¤¿¤á¤Î¥ì¥¸¥¹¥È¥êÁàºî
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced\Folder\
Hidden\SHOWALL]"CheckedValue"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
"ShowSuperHidden"=dword:00000001
¤¬¡¢¥ì¥¸¥¹¥È¥ê¥¡¼¤ò¾åµ¤Î¤è¤¦¤Ëµ½Ò¤·¤Æ¤â
¤¹¤°¤Ë½ñ¤´¹¤¨¤é¤ì¤Æ¤·¤Þ¤¤¡¢²¿ÅÙ¤ä¤Ã¤Æ¤â¡¢
¸µ¤ËÌá¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¡£
¥»¡¼¥Õ¥â¡¼¥É¤Ë¤·¤Æ¼Â¹Ô¤·¤¿¤ê¡¢¤¢¤ì¤³¤ì»î¤·¤Æ¤ß¤Þ¤·¤¿¤¬
¤À¤á¤Ç¤·¤¿¡£
¼¡¤Ë
¥Õ¥¡¥¤¥ë¸¡º÷¡¡¢ª¡¡¾ÜºÙÀßÄꥪ¥×¥·¥ç¥ó
¡¦¡¡¥·¥¹¥Æ¥à¥Õ¥©¥ë¥À¤Î¸¡º÷
¡¦¡¡±£¤·¥Õ¥¡¥¤¥ë¤È¥Õ¥©¥ë¥À¤Î¸¡º÷
¡¦¡¡¥µ¥Ö¥Õ¥©¥ë¥À¤Î¸¡º÷
¤Ë¥Á¥§¥Ã¥¯¤òÆþ¤ì¡¢mmvo¤Ç¸¡º÷¤·¤Æ¤â
°ú¤Ã¤«¤«¤ê¤Þ¤»¤ó¤Ç¤·¤¿¡£
°ì±þnifty¤Î¥ª¥ó¥é¥¤¥ó¥¦¥£¥ë¥¹¥¹¥¥ã¥ó¤Ç¤â
¸¡º÷¤·¤Æ¤ß¤Þ¤·¤¿¤¬¡¢¤À¤á¤Ç¤·¤¿¡£
¤³¤³¤Ç·Ú¤¯ÅÓÊý¤ËÊë¤ì¤Þ¤¹¡£
¤½¤³¤Ë¤¢¤ë¤Ï¤º¤Îmmvo.exe¤äautorun.inf¤Ë
¤Ê¤«¤Ê¤«¼ê¤¬ÆÏ¤¤Þ¤»¤ó¡£
¤Þ¤¿¤¾¤í¤¢¤ì¤³¤ì¸¡º÷¤·¤Æ
¤¿¤É¤ê¤Ä¤¤¤¿¤Î¤Ï¥³¥Þ¥ó¥É¥×¥í¥ó¥È¤Ç¤·¤¿¡£
¡Ã¥³¥Þ¥ó¥É¥×¥í¥ó¥È¤Ë¤è¤ëºï½ü
º¤¤Ã¤¿¤È¤¤Î¥³¥Þ¥ó¥É¥×¥í¥ó¥È¡£
¥³¥Þ¥ó¥É¥×¥í¥ó¥È¤ÎÁàºî¤Ë´Ø¤·¤Æ¾Ü¤·¤¯¤Ï
¡¦
¥³¥Þ¥ó¥É¥×¥í¥ó¥×¥È¤ò»È¤Ã¤Æ¤ß¤è¤¦¡ª¤ò¤´Í÷¤¯¤À¤µ¤¤¡£
¤Þ¤ºC¥É¥é¥¤¥Ö¤Îautorun.inf¥Õ¥¡¥¤¥ë¤Îºï½ü¤ò
»î¤ß¤Æ¤ß¤Þ¤·¤¿¡£
¤Þ¤º¤Ï¡¢¥³¥Þ¥ó¥É¥×¥í¥ó¥È¤òµ¡Æ°¡¡¤Ç¡¢
cd c:\¡¡
¤ÈµÆþ¡£¤³¤ì¤Ç¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê¤¬Êѹ¹¤µ¤ì¤Þ¤¹¡£¡¡¤Ç¡¢
C:\>dir /ah
¤ÈµÆþ¡£¤³¤ì¤ÇC:\¾å¤Ë¤¢¤ë±£¤·¥Õ¥¡¥¤¥ë¡õ¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤¬É½¼¨¤µ¤ì¤Þ¤¹¡£
db.bat
fdwigka.cmd
autorun.inf
¤Ê¤É¤Î¥¦¥£¥ë¥¹´ØÏ¢¥Õ¥¡¥¤¥ë¤¬¸«»ö³Îǧ¤µ¤ì¤Þ¤·¤¿¡£
¤½¤·¤Æº£Å٤ϡ¢
C:\>attrib -r -h -s autorun.inf
¤ÈµÆþ¡£¤³¤ì¤Çautorun.inf¤Î±£¤·¥Õ¥¡¥¤¥ë°À¤¬²ò½ü¤µ¤ì¤Þ¤·¤¿¡£
C:\¾å¤Ë±£¤ì¤Æ¤¤¤¿autorun.inf¤¬¸½¤ì¤Þ¤·¤¿¡£
¤½¤ì¤ò¤¹¤«¤µ¤ººï½ü¤·¡¢´¶À÷ËɻߤΤ¿¤á¤Ë
¤¹¤«¤µ¤ºautorun.inf¤È¤¤¤¦Ì¾Á°¤Î
¥Õ¥©¥ë¥À¤òºîÀ®¤·¤Þ¤¹¡£¥Õ¥¡¥¤¥ë¤Ç¤Ê¤¯¥Õ¥©¥ë¥À¤Ç¤¹¡£
autorun.inf¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤Ï¡¢
ºï½ü¤·¤Æ¤â¿ôÉäÇÉü³è¤·¤Æ¤·¤Þ¤¦¤Î¤Ç¡¢
¤¢¤é¤«¤¸¤áautorun.inf¤È¤¤¤¦Ì¾Á°¤Î¥Õ¥©¥ë¥À¤ò
¤É¤³¤«¤ËºîÀ®¤·¤Æ¤ª¤¡¢ºï½ü¤·¤Æ¤¹¤°¥³¥Ô¥Ú
¤È¤¤¤¦´¶¤¸¤ÇºîÀ®¤·¤Þ¤·¤¿¡£
¥É¥é¥¤¥Ö¾å¤Ëautorun.inf¥Õ¥©¥ë¥À¤òºîÀ®¤Ç¤¤ì¤Ð
¤«¤Ê¤ê°ì°Â¿´¤Ç¤¹¡£
¤³¤ÎÍ×ÎΤǻĤê¤Î³Æ¥É¥é¥¤¥Öľ²¼¤Îauto.inf¤¿¤Á¤Î
ºï½ü¡¢autorun.inf¥Õ¥©¥ë¥À¤ÎºîÀ®¤ò¼Â¹Ô¤·¤Æ¤¤¤¤Þ¤¹¡£
¥É¥é¥¤¥Ö¤ÎÊѹ¹¤Ï
D¥É¥é¥¤¥Ö¤Ê¤é cd /d D:\
E¥É¥é¥¤¥Ö¤Ê¤é cd /d E:\
¡¡¡¡
¤È¤¤¤¦¤è¤¦¤ËµÆþ¤¹¤ë¤ÈÊѹ¹¤Ç¤¤Þ¤¹¡£
¤Ç¡¢¤¹¤Ù¤Æ¤Î¥É¥é¥¤¥Ö¤Îautorun.inf¤¿¤Á¤ò¶îÃà¤Ç¤¤¿¤é
¤³¤ó¤É¤Ïc:\windows\system32\ ¤Ë¸ºß¤¹¤ë¡¢
mmvo.exe
mmvo0.dll
mmvo1.dll
¤¿¤Á¤Îºï½ü¤Ç¤¹¡£
cd c:\windows\system32\ ¤ÈµÆþ¤·¡¢Â³¤±¤Æ
>dir /ah ¡¡¤ÈµÆþ¤·¤Æ¡¢
system32¥Õ¥©¥ë¥ÀÆâ¤Î±£¤·¥Õ¥¡¥¤¥ë¤È¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤òɽ¼¨¤µ¤»¤Þ¤¹¡£
¤³¤ì¤Ç¡¢
mmvo.exe
mmvo1.dll
£²¤Ä¤Î¥Õ¥¡¥¤¥ë¤¬¸«¤Ä¤«¤ê¤Þ¤·¤¿¡£
¤³¤ì¤é¤Î¥Õ¥¡¥¤¥ë¤âƱÍͤ˱£¤·Â°À¤ò²ò½ü¤·ºï½ü¤·¤Þ¤¹¡£
mmvo.exe¤Ï¤¹¤ó¤Ê¤êºï½ü¤Ç¤¤Þ¤·¤¿¤¬¡¢
mmvo1.dll¤Ï¡¡¡Ö¤³¤Î¥Õ¥¡¥¤¥ë¤Ï»ÈÍÑÃæ¤Ç¥¢¥¯¥»¥¹¤Ç¤¤Þ¤»¤ó¡£¡×
¤È¤¤¤¦¤è¤¦¤Ê¥á¥Ã¥»¡¼¥¸¤¬¤Ç¤Æ¡¢ºï½ü¤Ç¤¤Þ¤»¤ó¤Ç¤·¤¿¡£
¤·¤«¤·¤Ê¤¼¤«°Üư¤ä¥ê¥Í¡¼¥à¤Ï¤Ç¤¤¿¤Î¤Ç¡¢
¥Ç¥¹¥¯¥È¥Ã¥×¾å¤Ë°Ü¤·¤Æ¥ê¥Í¡¼¥à¤·¤ÆÃÖ¤¤¤Æ¤ª¤¤Þ¤·¤¿¡£
¥³¥Þ¥ó¥É¥×¥í¥ó¥È¤Ç¤Î½èÍý¤Ï¡¢°ì±þ¤³¤³¤Ç½ªÎ»¡£
¸å¤Ï¤â¤¦ÂçµÍ¤á¤Ç¤¹¡£
regedit¤ò³«¤¤¤Æmmvo¤Èmmva¤Ç¸¡º÷¤·¤Þ¤·¤¿¡£
¥Ò¥Ã¥È¤·¤¿¤â¤Î¤Ç¤½¤ì¤é¤·¤¤¥ì¥¸¥¹¥È¥ê¡¼¥¡¼¤òºï½ü¡£
¤½¤·¤Æ¥¤¥ó¥¿¡¼¥Í¥Ã¥È°ì»þ¥Õ¥¡¥¤¥ë¤òºÆ¤Ó³Îǧ¤·¤Æ¤ß¤¿¤é
¤Þ¤¿uu.rar¤Èuu.exe¤¬¸«¤Ä¤«¤Ã¤¿¤Î¤Ç¨ºï½ü¡£
¤â¤¦°ìÅٳƥɥ饤¥Ö¤Ë´ØÏ¢¥Õ¥¡¥¤¥ë¤¬Æþ¤Ã¤Æ¤Ê¤¤¤«¡¢
¥³¥Þ¥ó¥É¥×¥í¥ó¥È¤Ç³Îǧ¤·¤Þ¤·¤¿¤¬¡£¤³¤Á¤é¤Ï¤Ê¤·¡£
¤³¤Î»þÅÀ¤Ç¤Ï¤Þ¤À
±£¤·¥Õ¥¡¥¤¥ë¡¦¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤Îɽ¼¨¤Î¤¿¤á¤Î¥ì¥¸¥¹¥È¥êÁàºî
¤ò¤·¤Æ¤â¡¢¸µ¤ËÌá¤Ã¤Æ¤·¤Þ¤¤¤Þ¤¹¡£
¤±¤É¤â¤¦¤Û¤«¤Ë¤ä¤ë¤³¤È¤â¤Ê¤¤¤«¤Ê¤È»×¤¤¡¢
PC¤òºÆµ¯Æ°¤·¤Æ¤ß¤Þ¤¹¡£
ºÆµ¯Æ°¤·¤Æ¤¹¤°¥¦¥£¥ë¥¹¤Î´¶À÷¾õ¶·¤ò³Îǧ¡£
±£¤·¥Õ¥¡¥¤¥ë¡¦¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤Îɽ¼¨¤Î¤¿¤á¤Î¥ì¥¸¥¹¥È¥êÁàºî
¤ò¼Â¹Ô¡£¤Ç¤¤Þ¤·¤¿¡£¤¹¤Ù¤Æ¤Î¥Õ¥¡¥¤¥ë¤¬É½¼¨²Äǽ¤Ë¤Ê¤ê¤Þ¤·¤¿¡£
¥·¥¹¥Æ¥à¹½À®¥æ¡¼¥Æ¥£¥ê¥Æ¥£(msconfig)¤Î
¥¹¥¿¡¼¥È¥¢¥Ã¥×¤Ë¤¢¤Ã¤¿mmvo¤¬¤Ê¤¯¤Ê¤Ã¤Æ¤¤¤Þ¤·¤¿¡£
³Æ¥É¥é¥¤¥Ö¤Î¥ë¡¼¥È¤Ëautorun.inf¥Õ¥¡¥¤¥ë¤¬¤Ê¤¤¡£
¤½¤Î¾¤Î´ØÏ¢¥Õ¥¡¥¤¥ë¤â¤Ê¤¤¡£
¥¤¥ó¥¿¡¼¥Í¥Ã¥È°ì»þ¥Õ¥¡¥¤¥ë¤Ëuu.rar¤â¤·¤¯¤Ïuu.exe¤â¤Ê¤¤¡£
¤³¤³¤é¤Ç¤¿¤Ö¤ó£¸³ä£¹³ä¤Î¶î½ü¤Ï¤Ç¤¤Æ¤ë¤È»×¤¤¤Þ¤¹¡£
¸å¤ÏNOD£³£²¤Ê¤É¤òƳÆþ¤¹¤ë¤Ê¤ê¤·¤Æ¡¢Æþǰ¤Ë¥Á¥§¥Ã¥¯¤·
²¿¤â½Ð¤Æ¤³¤Ê¤±¤ì¤Ð¡¢Âç¾æÉפǤ·¤ç¤¦¡£
»ä¤Ïǰ¤Î¤¿¤á¡¢C¥É¥é¥¤¥Ö¤òºÆ¥»¥Ã¥È¥¢¥Ã¥×¤·¤Þ¤·¤¿¡£
¤³¤ì¤Ç¤è¤¦¤ä¤¯´°Á´¤Ë¶î½ü¤¬´°Î»¡£
¤¢¡¼Èè¤ì¤¿¡£
¡öÄɵ
¤½¤¦¤¤¤¨¤ÐUSB¥á¥â¥ê¤ÎÊý¤ò½èÍý¤¹¤ë¤Î¤ò˺¤ì¤Æ¤¤¤Þ¤·¤¿¡£
º£º¢¤â¤¦»É¤·¤¿¤¯¤Ê¤¤¤Î¤Ç¡¢¤É¤¦¤·¤è¤¦¤È¤¤¤¦´¶¤¸¤Ç¤¹¡£
USB¥á¥â¥ê¤Î½èÍý¤ÏPC¤Î¶î½ü¤ò¤¹¤ëÁ°¤Ë
¤ä¤Ã¤Æ¤ª¤¤¤¿Êý¤¬¤¤¤¤¤Ç¤·¤ç¤¦¡£
¥Ç¥¸¥«¥á¤Î¥á¥â¥ê¤Ê¤É¤âÍ×Ãí°Õ¤Ç¤¹¡£
¥Õ¥©¡¼¥Þ¥Ã¥È¡õautorun.inf¥Õ¥©¥ë¥À¤ÎºîÀ®¤Ç
OK¤À¤È»×¤ï¤ì¤Þ¤¹¡£