Home >> Advisories & Alerts <<  Security Bulletins || àÍ¡ÊÒÃà¼Âá¾Ãè || à¤Ã×èͧÁ×Í || ºÃÔ¡Òà || FAQ. || à¡ÕèÂǡѺ ThaiCERT

Advisories & Alerts
CERT Advisory
Alert
 

ª×èÍ : W32.Bropia
ª¹Ô´ : ˹͹ÍÔ¹à·ÍÃìà¹çµ (worm)
ª×èÍÍ×è¹·ÕèÃÙé¨Ñ¡ : W32.Bropia
ÃдѺ¤ÇÒÁÃØ¹áç : »Ò¹¡ÅÒ§
Ãкº»¯ÔºÑµÔ¡Ò÷ÕèÁռšÃзº
: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Ãкº»¯ÔºÑµÔ¡Ò÷ÕèäÁèÁռšÃзº
: Linux, Macintosh, OS/2, UNIX


¢éÍÁÙÅ·ÑèÇä» || ÇÔ¸Õ¡ÒÃá¾Ãè¡ÃШÒ || ¼Å¡Ãзº·Õèà¡Ô´¢Öé¹ ||ÃÒÂÅÐàÍÕ´·Ò§à·¤¹Ô¤ || ÇÔ¸Õ¡ÒáӨѴ˹͹ª¹Ô´¹Õé || ÇÔ¸Õ»éͧ¡Ñ¹µÑÇàͧ¨Ò¡Ë¹Í¹ª¹Ô´¹Õé || ¢éÍÁÙÅÍéÒ§ÍÔ§


¢éÍÁÙÅ·ÑèÇä»

µÑÇ˹͹¹Õé¨Ðá¾Ãè¡ÃШÒ¼èÒ¹â¾ÃⵤÍÅ(¾ÍÃìµ 1863/tcp) ·ÕèãËéºÃÔ¡Òèҡâ»Ãá¡ÃÁ MSN Messenger â´Â¨ÐÍÒÈÑÂà¤Ã×èͧ·Õè¶Ù¡Ë¹Í¹ª¹Ô´¹Õ館¡¤ÒÁà»ç¹¾ÒËÐÊÓËÃѺ¡ÒÃÊè§ä¿Åìä»Âѧ ¼Ùé·ÕèÁÕÃÒª×èÍÍÂÙèã¹ contact list ¢Í§¼ÙéÃѺáÅÐËÒ¡¼ÙéÃѺ ÃѺä¿ÅìáÅÐà»Ô´ãªé§Ò¹¨Ð·ÓãËéµÔ´µÑÇ˹͹ª¹Ô´¹Õéä´é ¡ÒÃá¾Ãè¡ÃШÒ¢ͧ˹͹ª¹Ô´¹Õé¼èÒ¹ä¿Åì㹪×èÍ·ÕèᵡµèÒ§¡Ñ¹ àªè¹

ä¿Åìª×èÍ

love_me.pif
sexy_bedroom.pif
drunk_lol.pif
naked_party.pif
web_cam.pif
drunk_lol.pif
webcam_004.pif

µÑÇÍÂèҧ˹éҨͧ͢ MSN ¢Í§µÑÇ˹͹

ÇÔ¸Õ¡ÒÃá¾Ãè¡ÃШÒÂ

˹͹ª¹Ô´¹ÕéÊÒÁÒöá¾Ãè¡ÃШÒ¼èÒ¹â»Ãá¡ÃÁ MSN à»ç¹ËÅÑ¡

¼Å¡Ãзº·Õèà¡Ô´¢Öé¹

  • Êè§ä¿ÅìṺãËé¡Ñº¼Ùé·ÕèÁÕÃÒª×èÍÍÂÙèã¹ contact list ¢Í§¼ÙéÃѺ : ˹͹¨ÐÊè§ä¿Åì ¼èÒ¹â»Ãá¡ÃÁ MSN â´ÂÍѵâ¹ÁѵÔ
  • à¤Ã×èͧÍÒ¨·Ó§Ò¹¼Ô´¾ÅÒ´ : à¹×èͧ¨Ò¡Ë¹Í¹¨Ðá¡éä¢ä¿ÅìáÅÐÃÕ¨ÔÊ·ÃÕ ·ÓãËéà¤Ã×èͧ·Ó§Ò¹¼Ô´¾ÅÒ´ä´é
  • ËÂØ´¡Ò÷ӧҹâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ : Ê觼ŷÓãËéà¤Ã×èͧ¤ÍÁ¾ÔÇàµÍÃì·Õè¶Ù¡Ë¹Í¹ª¹Ô´¹Õéá¾Ãè¡ÃШÒ ÍÒ¨¶Ù¡Ë¹Í¹ª¹Ô´Í×è¹á¾Ãè¡ÃШÒÂà¢éÒÁÒä´é

ÃÒÂÅÐàÍÕ´·Ò§à·¤¹Ô¤

ÅѡɳзÕèÍÒ¨¨Ðºè§ãËéàËç¹ÇèÒµÔ´µÑÇ˹͹

  1. äÁèÊÒÁÒö·Ó¡Òà click ¢ÇÒä´é
  2. äÁèÊÒÁÒöãªé§Ò¹ task manager ä´é â´Â¡Òá´ Ctrl-Alt-Del
  3. µÑÇ˹͹ÊÃéÒ§ä¿Åìã¹à¤Ã×èͧ¼ÙéàÊÕÂËÒ´ѧ¹Õé
    C:\<ª×èÍä¿Åì¢Í§Ë¹Í¹>.pif
    C:\omc.com
    C:\windows\system32\lexplore.exe
  4. à¤Ã×èͧ¨Ð¾ÂÒÂÒÁµÔ´µèÍ MSN
  5. µÑÇ˹͹¨ÐµÔ´µÑé§â»Ãá¡ÃÁâ·Ã¨Ñ¹ã¹à¤Ã×èͧâ´Âà»Ô´¾ÍÃ쵪¹Ô´ udp ·ÕèÁÕËÁÒÂàÅ¢·ÕèÊÙ§¡ÇèÒ 1024 àªè¹
    44802/udp
    9943/udp
    2268/udp
    à»ç¹µé¹
  6. à¤Ã×èͧ·Ó§Ò¹ªéÒŧ

àÁ×èÍ˹͹ W32.Bropia ¶Ù¡àÍç¡«Ô¤Ôǵì ˹͹¨ÐÁÕ¡Ãкǹ¡Òôѧ¹Õé

ÇԸաӨѴ˹͹ª¹Ô´¹Õé

  • ¡ÒáӨѴ˹͹ẺÍѵâ¹ÁÑµÔ ÇÔ¸Õ·Õè 1
  1. ´ÒǹìâËÅ´â»Ãá¡ÃÁ Sysclean.com ¨Ò¡àÇçºä«µì http://www.trendmicro.com/ftp/products/tsc/sysclean.com
  2. ´ÒǹìâËÅ´ä¿Åì pattern ª×èÍ lptxxx.zip ¨Ò¡ http://www.trendmicro.com/download/pattern.asp

    ËÁÒÂà赯 xxx á·¹µÑÇàÅ¢àÇÍÃìªÑ¹ÅèÒÊØ´¢Í§ä¿Åì pattern

  3. ᵡä¿Åì lptxxx.zip ¹Óä¿Åìª×èÍ lpt$vpn.xxx à¡çºäÇéã¹â¿Åà´ÍÃìà´ÕÂǡѺä¿Åì Sysclean.com ·Õèä´é¨Ò¡¢éÍ 1
  4. µÑ´¡ÒÃàª×èÍÁµèÍà¤Ã×Í¢èÒÂ
  5. ËÂØ´¡Ò÷ӧҹ·Ø¡â»Ãá¡ÃÁ ÃÇÁ·Ñé§â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ´éÇÂ
  6. ¨Ò¡¹Ñé¹Ãѹä¿Åì Sysclean.com ¨Ð»ÃÒ¡¯ä´ÍÐÅçÍ¡ãËé·Ó¡ÒÃÊ᡹â´Â¡´»ØèÁ Scan
  7. àÃÔèÁµé¹¡ÒÃãªé§Ò¹â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊÍÕ¡¤ÃÑé§
  8. ·Ó¡ÒûÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑÊ·ÕèãªéÍÂÙèáÅéÇ·Ó¡ÒÃÊ᡹ÍÕ¡¤ÃÑé§à¾×èÍãËéá¹èã¨ÇèÒà¤Ã×èͧ·Õèãªé§Ò¹ÍÂÙèäÁèÁÕäÇÃÑÊ
  • ÊÓËÃѺ¼ÙéµÔ´µÑé§â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ
  1. ¶éÒãªé§Ò¹Ãкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì ME ËÃ×Í XP ãËé·Ó¡Òà disable System Restore ¡è͹ (ÍèÒ¹ÃÒÂÅÐàÍÕ´à¾ÔèÁàµÔÁ·ÕèÊèǹ¢Í§ ¢éÍÁÙÅà¾ÔèÁàµÔÁÊÓËÃѺ Windows XP áÅÐ ME)
  2. »ÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑÊãËÁèÅèÒÊØ´¨Ò¡àÇçºà¾¨¢Í§ºÃÔÉÑ·à¨éҢͧâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ·Õè·èÒ¹ãªé ËÃ×Í µÔ´µèͺÃÔÉÑ··Õè·èÒ¹µÔ´µèÍ«×éÍâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ
  3. ÃÕʵÒÃì·à¤Ã×èͧãËéà¢éÒã¹Ãкºáºº Safe Mode â´Âã¹Ãкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì 95/2000/XP ãËé¡´ F8 ÃÐËÇèÒ§¡Òúٵà¤Ã×èͧ
  4. Ê᡹äÇÃÑÊ´éÇÂâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ·Õèä´éÃѺ¡ÒúÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑʨҡ¢éÍ·Õè 2 ËÅѧ¨Ò¡¡ÒÃÊ᡹â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑʨзӡÒÃźä¿ÅìµÑÇ˹͹ÍÍ¡¨Ò¡Ãкº·Ñé§ËÁ´ ·Õè¡ÅèÒÇÁÒáÅéÇã¹¢éÒ§µé¹

¢éÍÁÙÅà¾ÔèÁàµÔÁÊÓËÃѺÇÔ¹â´ÇÊì ME:

ËÁÒÂà˵Ø: Ãкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì ME ãªé backup utility ÊÓËÃѺ backup ä¿Åìâ´ÂÍѵâ¹ÁѵÔäÇé·Õèâ¿Åà´ÍÃì C:\_Restore ´Ñ§¹Ñé¹ä¿Åì·ÕèµÔ´àª×éÍÊÒÁÒö¶Ù¡à¡çºäÇéà»ç¹ä¿Åì backup ä´é áÅÐ â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑʨÐäÁèÊÒÁÒöźä¿ÅìàËÅèÒ¹Õéä´é ¨Ö§µéͧ·Ó¡ÒáàÅÔ¡¡ÒÃãªé§Ò¹ Restore Utility µÒÁ¢Ñ鹵͹´Ñ§¹Õé

  1. ¤ÅÔê¡¢ÇÒ·Õèäͤ͹ My Computer º¹ Desktop áÅÐ àÅ×Í¡ Properties
  2. àÅ×͡ᶺ Performance
  3. ¡´»ØèÁ File System
  4. àÅ×͡ᶺ Troubleshooting
  5. ãÊèà¤Ã×èͧËÁÒÂàÅ×Í¡ "Disable System Restore"
  6. ¡´»ØèÁ Apply
  7. ¡´»ØèÁ Close
  8. ¡´»ØèÁ Close ÍÕ¡·Õ
  9. àÁ×èÍÁÕ˹éÒµèÒ§¢Öé¹ÁÒ¶ÒÁÇèÒ¨ÐÃÕʵÒÃì·à¤Ã×èͧËÃ×ÍäÁè ãËé¡´ Yes
    ËÁÒÂà˵Ø: µÍ¹¹Õé Restore Utility ¶Ù¡Â¡àÅÔ¡áÅéÇ
  10. ËÅѧ¨Ò¡àÃÕ¡ãªé§Ò¹ Fix tools àÃÕºÃéÍÂáÅéÇ à»Ô´ËÒµÓá˹觢ͧä¿ÅìàËÅèÒ¹Ñé¹ä´é¨Ò¡â¿Åà´ÍÃì C:\_Restore áÅСӨѴÍÍ¡
    ËÅѧ¨Ò¡¡Ó¨Ñ´àÃÕºÃéÍÂáÅéÇ¡çÃÕʵÒÃì·à¤Ã×èͧãËéãªé§Ò¹ä´éµÒÁ»¡µÔ
    ËÁÒÂà˵Ø: ¡ÒÃà»Ô´ãªé Restore Utility ÍÕ¡¤ÃÑé§ ãËé·ÓµÒÁ¢Ñ鹵͹·Õè 1-9 áÅÐã¹¢Ñ鹵͹·Õè 5 ãËé¡àÅÔ¡à¤Ã×èͧËÁÒ·ÕèàÅ×Í¡ "Disable System Restore" ÍÍ¡

¢éÍÁÙÅà¾ÔèÁàµÔÁÊÓËÃѺÇÔ¹â´ÇÊì XP

ËÁÒÂà˵Ø: Ãкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì XP ãªé backup utility ÊÓËÃѺ backup ä¿Åìâ´ÂÍѵâ¹ÁѵÔäÇé·Õèâ¿Åà´ÍÃì C:\_Restore ´Ñ§¹Ñé¹ä¿Åì·ÕèµÔ´àª×éÍÊÒÁÒö¶Ù¡à¡çºäÇéà»ç¹ä¿Åì backup ä´é áÅÐ â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑʨÐäÁèÊÒÁÒöźä¿ÅìàËÅèÒ¹Õéä´é ¨Ö§µéͧ·Ó¡ÒáàÅÔ¡¡ÒÃãªé§Ò¹ Restore Utility µÒÁ¢Ñ鹵͹´Ñ§¹Õé

  1. ¤ÅÔê¡¢ÇÒ·Õèäͤ͹ My Computer º¹ Desktop áÅÐ àÅ×Í¡ Properties
  2. àÅ×͡ᶺ System Restore
  3. ãÊèà¤Ã×èͧËÁÒÂàÅ×Í¡ "Turn off System Restore" ËÃ×Í "Turn off System Restore on all drives"
  4. ¡´»ØèÁ Apply
  5. ¡´»ØèÁ Yes
    ËÁÒÂà˵Ø: µÍ¹¹Õé Restore Utility ¶Ù¡Â¡àÅÔ¡áÅéÇ
  6. ËÅѧ¨Ò¡àÃÕ¡ãªé§Ò¹ Fix tools àÃÕºÃéÍÂáÅéÇ à»Ô´ËÒµÓá˹觢ͧä¿ÅìàËÅèÒ¹Ñé¹ä´é¨Ò¡â¿Åà´ÍÃì C:\_Restore áÅСӨѴÍÍ¡ ËÅѧ¨Ò¡¡Ó¨Ñ´àÃÕºÃéÍÂáÅéÇ¡çÃÕʵÒÃì·à¤Ã×èͧãËéãªé§Ò¹ä´éµÒÁ»¡µÔ
    ËÁÒÂà˵Ø: ¡ÒÃà»Ô´ãªé Restore Utility ÍÕ¡¤ÃÑé§ ãËé·ÓµÒÁ¢Ñ鹵͹·Õè 1-5 áÅÐã¹¢Ñ鹵͹·Õè 5 ãËé¡àÅÔ¡à¤Ã×èͧËÁÒ·ÕèàÅ×Í¡ "Turn off System Restore" ÍÍ¡

ÇÔ¸Õ»éͧ¡Ñ¹µÑÇàͧ¨Ò¡Ë¹Í¹ª¹Ô´¹Õé

    1. ËéÒÁÃѺä¿Åì ËÃ×Íà»Ô´ãªé§Ò¹ä¿Åì·Õèä´éÃѺ¨Ò¡â»Ãá¡ÃÁ MSN
    2. ÊÓËÃѺ¼Ùé´ÙáÅÃкº·èÒ¹¤ÇûԴ¡ÒÃãªé§Ò¹¢Í§¾ÍÃìµ 1863/tcp à¾×èÍÃЧѺ¡ÒÃá¾Ãè¡ÃШÒ¢ͧµÑÇ˹͹ª¹Ô´¹Õé
    3. µÔ´µÑé§â»Ãá¡ÃÁµè͵éÒ¹äÇÃÑÊ áÅеéͧ·Ó¡ÒûÃѺ»Ãا°Ò¹¢éÍÁÙÅäÇÃÑÊà»ç¹µÑÇÅèÒÊØ´ÍÂÙèàÊÁÍ
    4. ÊÃéÒ§á¼è¹¡ÙéÃкº©Ø¡à©Ô¹ (Emergency disk) ¢Í§â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ áÅлÃѺ»Ãا°Ò¹¢éÍÁÙÅã¹á¼è¹ÍÂÙèàÊÁÍ
    5. ·Ó¡ÒÃÊÓÃͧ¢éÍÁÙÅã¹à¤Ã×èͧÍÂÙèàÊÁÍ áÅÐàµÃÕÂÁËÒÇÔ¸Õ¡ÒÃá¡éä¢àÁ×èÍà¡Ô´à˵آѴ¢éͧ¢Öé¹
    6. µÔ´µÒÁ¢èÒÇÊÒÃá¨é§àµ×͹à¡ÕèÂǡѺäÇÃÑʵèÒ§æ «Öè§ÊÒÁÒö¢ÍãªéºÃÔ¡ÒÃÊè§¢èÒÇÊÒüèÒ¹·Ò§ÍÕ-àÁÅì¢Í§·ÕÁ§Ò¹ ThaiCERT ä´é·Õè http://thaicert.nectec.or.th/mailinglist/register.php
    7. ÊÒÁÒöÍèÒ¹ÃÒÂÅÐàÍÕ´à¾ÔèÁàµÔÁà¡ÕèÂǡѺÇÔ¸Õ»éͧ¡Ñ¹µÑÇàͧ¨Ò¡äÇÃÑÊ·ÑèÇä»ä´éã¹ËÑÇ¢éÍ ÇÔ¸Õ»éͧ¡Ñ¹µÑÇàͧãËé»ÅÍ´ÀѨҡäÇÃÑʤÍÁ¾ÔÇàµÍÃì

ªéÍÁÙÅÍéÒ§ÍÔ§

*** ThaiCERT ¢ÍʧǹÊÔ·¸Ôì㹡ÒÃàʹÍá¹Ç·Ò§»éͧ¡Ñ¹àº×éͧµé¹ áÅÐÇÔ¸Õ¡Òôѧ¡ÅèÒÇäÁè¨Óà»ç¹µéͧä´é¼Å 100% ¢Öé¹ÍÂÙè¡ÑºÃкº»®ÔºÑµÔ¡Òà â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊã´ áÅÐâ»Ãá¡ÃÁÍ×è¹æ ·ÕèµÔ´µÑé§àͧã¹à¤Ã×èͧ¤ÍÁ¾ÔÇàµÍÃì¢Í§·èÒ¹àͧ***

à¼Âá¾Ãèâ´Â ThaiCERT àÁ×èÍ 20 Á¡ÃÒ¤Á 2548 11.31 ¹.
»ÃѺ»ÃاÅèÒÊØ´â´Â
ThaiCERT àÁ×èÍ 20 Á¡ÃÒ¤Á 2548 16:00 ¹.


ËÒ¡·èÒ¹¾ºàËç¹¢éͼԴ¾ÅÒ´ËÃ×ÍÁÕ¤Óá¹Ð¹Ó â»Ã´Êè§¢éͤÇÒÁ¢Í§·èÒ¹ÁÒ·Õè thaicert@nectec.or.th ·èÒ¹ÊÒÁÒö´ÒǹìâËÅ´ PGP Public Key ¢Í§ ThaiCERT ä´é 㹡óշÕèµéͧ¡ÒÃà¢éÒÃËÑÊÍÕ-àÁÅì



Home >> Advisories & Alerts <<  Security Bulletins || àÍ¡ÊÒÃà¼Âá¾Ãè || à¤Ã×èͧÁ×Í || ºÃÔ¡Òà || FAQ. || à¡ÕèÂǡѺ ThaiCERT

ThaiCERT Disclaimer | Copyright © 2001 ThaiCERT(NECTEC). All rights reserved.