W32.Funner

Risk Level 2: Low

Printer Friendly Page

Discovered: October 11, 2004
Updated: February 13, 2007 12:28:17 PM
Also Known As: WORM_FUNNER.A [Trend Micro], W32/Funner.worm [McAfee], Win32.Funner.A [Computer Assoc, MSN-Worm.Funner [Kaspersky], W32/Funner-A [Sophos]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP


When W32.Funner is executed, it performs the following actions:
  1. Copies itself as:
    • %System%\IEXPLORE.EXE
    • %System%\EXPLORE.EXE or %System%\EXPLORER.EXE
    • %Windir%\rundll32.exe
    • %System%\userinit32.exe
    • c:\funny.exe

      and executes the first three files listed.

      Notes:
    • The three files make sure that the other two are running and will restart them if any are stopped.
    • These files require the MSVBVM60.DLL file, which is a component of the Microsoft Visual Basic run-time environment.
    • %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
    • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.

  2. Creates a log file named %System%\bsfirst2.log.

  3. Adds the value:

    "Userinit"="userinit32.exe,"

    to the registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

    so that the userinit32.exe runs when you start Windows.

  4. Adds the value:

    "MMSystem"="%Windir%\rundll32.exe "%System%\mmsystem.dll"", RunDll32"

    to some of the following registry keys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

    so that the rundll32.exe runs when you start Windows.

  5. May add the line:

    Shell = %System%\explore.exe

    to the [boot] section of the system.ini file.

  6. Attempts to send c:\funny.exe to contacts in the Microsoft MSN Messenger instant message program.

  7. May contact the www.78p.com domain and download various components.

  8. Adds the following entries to the Hosts file to point to an external IP address:
    222.89.98.219 www.wo365.com
    222.89.98.219 cmfu.com
    222.89.98.219 www.cmfu.com
    222.89.98.219 9i0.com
    222.89.98.219 www.9flash.com
    222.89.98.219 9flash.com
    222.89.98.219 www.nowok.net
    222.89.98.219 nowok.net
    222.89.98.219 wisa.com.cn
    222.89.98.219 www.sia.com.cn
    222.89.98.219 www.wisa.cn
    222.89.98.219 wisa.cn
    222.89.98.219 www.zhao99.com
    222.89.98.219 zhao99.com
    222.89.98.219 www.wo123.com
    222.89.98.219 wo123.com
    222.89.98.219 wo99.com
    222.89.98.219 www.wo99.com
    222.89.98.219 www.page.com.cn
    222.89.98.219 page.com.cn
    222.89.98.219 www.432.cn
    222.89.98.219 432.cn
    222.89.98.219 wysw.com
    222.89.98.219 14.com.cn
    222.89.98.219 www.14.com.cn
    222.89.98.219 cnww.net
    222.89.98.219 www.mv99.com
    222.89.98.219 mv99.com
    222.89.98.219 www.youav.com
    222.89.98.219 www.mtvav.com
    222.89.98.219 www.98983.com
    222.89.98.219 98983.com
    222.89.98.219 www.114.com.cn
    222.89.98.219 114.com.cn
    222.89.98.219 www.net114.com
    222.89.98.219 www.skywz.com
    222.89.98.219 skywz.com
    222.89.98.219 www.hao6.com
    222.89.98.219 hao6.com
    222.89.98.219 www.678a.com
    222.89.98.219 678a.com
    222.89.98.219 www.7510.com
    222.89.98.219 7510.com
    222.89.98.219 www.zzkan.com
    222.89.98.219 zzkan.com
    222.89.98.219 www.ca183.com
    222.89.98.219 ca183.com
    222.89.98.219 3tom.com
    222.89.98.219 www.yhjm.com
    222.89.98.219 yhjm.com
    222.89.98.219 www.k369.com
    222.89.98.219 www.xxwww.com
    222.89.98.219 xxwww.com
    222.89.98.219 www.fm1000.net
    222.89.98.219 fm1000.net
    222.89.98.219 www.ok135.com
    222.89.98.219 ok135.com
    222.89.98.219 www.link999.com
    222.89.98.219 link999.com
    222.89.98.219 www.001wz.com
    222.89.98.219 001wz.com
    222.89.98.219 www.7t7t.com
    222.89.98.219 7t7t.com
    222.89.98.219 www.7k7k.com
    222.89.98.219 7k7k.com
    222.89.98.219 www.webcool.net
    222.89.98.219 webcool.net
    222.89.98.219 www.51sobu.com
    222.89.98.219 51sobu.com
    222.89.98.219 cy.51sobu.com
    222.89.98.219 www.fj3721.com
    222.89.98.219 fj3721.com
    222.89.98.219 www.msncn.com
    222.89.98.219 msncn.com
    222.89.98.219 www.6235.com
    222.89.98.219 6235.com
    222.89.98.219 www.8goo.com
    222.89.98.219 8goo.com
    222.89.98.219 www.baimin.com
    222.89.98.219 baimin.com
    222.89.98.219 www.bwwz.com
    222.89.98.219 bwwz.com
    222.89.98.219 www.howow.net
    222.89.98.219 howow.net
    222.89.98.219 www.tongchi.com
    222.89.98.219 tongchi.com
    222.89.98.219 www.65658.com
    222.89.98.219 65658.com
    222.89.98.219 www.7o7o.com
    222.89.98.219 7o7o.com
    222.89.98.219 5126.net
    222.89.98.219 www.5126.net
    222.89.98.219 www.wangzhiku.com
    222.89.98.219 wangzhiku.com
    222.89.98.219 www.soyeah.com
    222.89.98.219 soyeah.com
    222.89.98.219 www.sowang.cn
    222.89.98.219 sowang.cn
    222.89.98.219 www.77177.com
    222.89.98.219 77177.com
    222.89.98.219 www.look8.net
    222.89.98.219 look8.net
    222.89.98.219 v222.com
    222.89.98.219 www.v222.com
    222.89.98.219 www.wblink.com
    222.89.98.219 wblink.com
    222.89.98.219 www.daguilin.com
    222.89.98.219 daguilin.com
    222.89.98.219 www.soulang.com
    222.89.98.219 soulang.com
    222.89.98.219 www.369e.com
    222.89.98.219 369e.com
    222.89.98.219 www.kuwz.com
    222.89.98.219 kuwz.com
    222.89.98.219 www.07007.com
    222.89.98.219 07007.com
    222.89.98.219 www.6cn.com
    222.89.98.219 6cn.com
    222.89.98.219 www.wyly.cn.gs
    222.89.98.219 wyly.cn.gs
    222.89.98.219 www.xhoo.net
    222.89.98.219 xhoo.net
    222.89.98.219 www.365.com
    222.89.98.219 www.qoomo.com
    222.89.98.219 www.4sohu.com
    222.89.98.219 www.top777.com
    222.89.98.219 top777.com
    222.89.98.219 www.suoyou.com
    222.89.98.219 suoyou.com
    222.89.98.219 www.dlren.com
    222.89.98.219 dlren.com
    222.89.98.219 www.cityshe.com
    222.89.98.219 www.hao100.com
    222.89.98.219 hao100.com
    222.89.98.219 www.11wz.com
    222.89.98.219 11wz.com
    222.89.98.219 www.bszcx.com
    222.89.98.219 bszcx.com
    222.89.98.219 www.12so.com
    222.89.98.219 12so.com
    222.89.98.219 www.wguo.com
    222.89.98.219 wguo.com
    222.89.98.219 www.ku8.com
    222.89.98.219 ku8.com
    222.89.98.219 www.5i55.com
    222.89.98.219 5i55.com
    222.89.98.219 www.dlwz.net
    222.89.98.219 dlwz.net
    222.89.98.219 www.etidc.net
    222.89.98.219 etidc.net
    222.89.98.219 www.eaol.net
    222.89.98.219 eaol.net
    222.89.98.219 wz.dabaoku.com
    222.89.98.219 dabaoku.com
    222.89.98.219 www.dabaoku.com
    222.89.98.219 info.west263.com
    222.89.98.219 west263.com
    222.89.98.219 www.west263.com
    222.89.98.219 www.urlall.com
    222.89.98.219 urlall.com
    222.89.98.219 www.wacn.cn
    222.89.98.219 wacn.cn
    222.89.98.219 www.uhot.net
    222.89.98.219 uhot.net
    222.89.98.219 www.lywww.com
    222.89.98.219 lywww.com
    222.89.98.219 tj8.aofa.cn
    222.89.98.219 www.ddvv.cn
    222.89.98.219 www.194.cn
    222.89.98.219 www.husou.com
    222.89.98.219 www.postonline.com.cn
    222.89.98.219 www.114hi.net
    222.89.98.219 www.9617.com
    222.89.98.219 www.168169.com
    222.89.98.219 www.huiche.com
    222.89.98.219 www.cnhttp.net
    222.89.98.219 www.wang100.com
    222.89.98.219 www.xntt.com
    222.89.98.219 www.wuhanlink.com
    222.89.98.219 www.xzcn.com
    222.89.98.219 www.1360.cn
    222.89.98.219 www.chi9.net
    222.89.98.219 url.114.com.cn
    222.89.98.219 www.zhao114.com
    222.89.98.219 www.zpartner.com
    222.89.98.219 www.cckey.cn
    222.89.98.219 www.gege.com.cn
    222.89.98.219 www.86wz.com
    222.89.98.219 www.91wz.com
    222.89.98.219 www.888wz.com
    222.89.98.219 web.365ye.com
    222.89.98.219 www.kps.cn
    222.89.98.219 www.6621.com
    222.89.98.219 www.6621.cn
    222.89.98.219 www.5862.com
    222.89.98.219 www.gouhot.com
    222.89.98.219 www.123k.com
    222.89.98.219 www.jywin.com
    222.89.98.219 www.zbwz.com
    222.89.98.219 www.soko.cn
    222.89.98.219 94wo.com
    222.89.98.219 www.qeoo.com
    222.89.98.219 www.myweb.cn
    222.89.98.219 www.hflash.com
    222.89.98.219 www.x63.com
    222.89.98.219 www.hky5.com
    222.89.98.219 www.812345.com
    222.89.98.219 www.qyj.cn
    222.89.98.219 www.hao321.cn
    222.89.98.219 www.17353.com
    222.89.98.219 es.xmew.com
    222.89.98.219 www.sohu123.com
    222.89.98.219 cxhuu.nease.net
    222.89.98.219 www.5e5e.net
    222.89.98.219 www.hao868.com
    222.89.98.219 www.kunmei.com
    222.89.98.219 www.hao55.com
    222.89.98.219 www.1251.net
    222.89.98.219 www.qqkkaa.com
    222.89.98.219 www.mpsoft.net
    222.89.98.219 www.51rm.com
    222.89.98.219 www.emode.cn
    222.89.98.219 www.83883.com
    222.89.98.219 www.xowz.com
    222.89.98.219 www.v23.com
    222.89.98.219 www.xiaoyouxi.com
    222.89.98.219 www.zhao58.com
    222.89.98.219 www.sqw.cn
    222.89.98.219 www.293.net
    222.89.98.219 www.wo20.com
    222.89.98.219 www.l66.net
    222.89.98.219 link.coolala.net
    222.89.98.219 www.v339.com
    222.89.98.219 www.3355.net
    222.89.98.219 www.260.cn
    222.89.98.219 www.zdzh.com
    222.89.98.219 www.222cn.com
    222.89.98.219 www.sowang.com
    222.89.98.219 www.mypcera.com
    222.89.98.219 www.hkball.net
    222.89.98.219 www.ocn.cn
    222.89.98.219 www.qqxxx.net
    222.89.98.219 www.hao789.com
    222.89.98.219 www.haohu.net
    222.89.98.219 www.v234.com
    222.89.98.219 www.lelew.com
    222.89.98.219 www.bx169.com
    222.89.98.219 www.k958.com
    222.89.98.219 www.qianmail.com
    222.89.98.219 www.google114.com
    222.89.98.219 www.456.net
    222.89.98.219 www.kkklll.com
    222.89.98.219 www.cnurl.cn.st
    222.89.98.219 www.008.it
    222.89.98.219 wz.shcoo.com
    222.89.98.219 www.seekchina.com
    222.89.98.219 www.qqboy.net
    222.89.98.219 www.ok1500.com
    222.89.98.219 www.zhao163.net
    222.89.98.219 www.9098.com
    222.89.98.219 9098.com
    222.89.98.219 www.liveinby.com
    222.89.98.219 wz.sundx.com
    222.89.98.219 soe.amoyren.com
    222.89.98.219 www.5661.net
    222.89.98.219 www.9sou.com
    222.89.98.219 www.linan.net
    222.89.98.219 www.dabaisha.com
    222.89.98.219 www.ezhongren.com
    222.89.98.219 8u8.com
    222.89.98.219 www.niyou.com
    222.89.98.219 www.5230.cn
    222.89.98.219 www.cpzx.cn
    222.89.98.219 www.bbpig.com
    222.89.98.219 www.web222.com
    222.89.98.219 www.hao126.com
    222.89.98.219 www.yofoo.com
    222.89.98.219 www.dodo100.com
    222.89.98.219 www.369w.net
    222.89.98.219 www.1163.cn
    222.89.98.219 wz.m118.com
    222.89.98.219 www.joyo.net.tf
    222.89.98.219 netzj.cnbv.net
    222.89.98.219 guide.tzinfo.net
    222.89.98.219 www.ec365.net
    222.89.98.219 www.yingcheng.net
    222.89.98.219 www.92l.com
    222.89.98.219 www.hao128.com
    222.89.98.219 www.gdfxzx.com
    222.89.98.219 www.hulian.com
    222.89.98.219 xmt.agreatserver.com
    222.89.98.219 www.5916.net
    222.89.98.219 www.172.cn
    222.89.98.219 www.xc123.com
    222.89.98.219 www.cz66.com
    222.89.98.219 go.sunff.com
    222.89.98.219 www.chinac2c.cn
    222.89.98.219 www.023web.com
    222.89.98.219 www.lwtwjh.com
    222.89.98.219 www.jibest.com
    222.89.98.219 www.0018.cn
    222.89.98.219 www.wopiao.com
    222.89.98.219 www.ie123.com
    222.89.98.219 twys.x168.net
    222.89.98.219 url.fengqiu.cn
    222.89.98.219 wangzhi.dkwx.com
    222.89.98.219 www.cnje.net
    222.89.98.219 www.cnpick.com
    222.89.98.219 www.zpjh.com
    222.89.98.219 www.mhyf.com
    222.89.98.219 www.8264.com
    222.89.98.219 www.haoso.com
    222.89.98.219 www.wz160.com
    222.89.98.219 www.98w.net
    222.89.98.219 www.80dh.com
    222.89.98.219 www.sj166.com
    222.89.98.219 www.9222.net
    222.89.98.219 www.52so.com
    222.89.98.219 www.haozi.net
    222.89.98.219 www.39cn.com
    222.89.98.219 www.jv168.com
    222.89.98.219 www.dog3721.com
    222.89.98.219 www.3000ok.com
    222.89.98.219 www.k3k4.com
    222.89.98.219 www.028www.com
    222.89.98.219 www.bjav.com
    222.89.98.219 www.7360.com
    222.89.98.219 www.abkk.com
    222.89.98.219 www.c888.com
    222.89.98.219 web.jpwy.net
    222.89.98.219 www.zszk.net
    222.89.98.219 www.5583.com
    222.89.98.219 www.9china.cn.st
    222.89.98.219 www.renma.net
    222.89.98.219 www.fs0757.com
    222.89.98.219 www.ku123.com
    222.89.98.219 www.quhu.com
    222.89.98.219 www.iq123.com
    222.89.98.219 www.szci.com
    222.89.98.219 www.cd200.com
    222.89.98.219 www.5cha.com
    222.89.98.219 www.qq83.com
    222.89.98.219 www.qiye1.com
    222.89.98.219 www.ganyu-window.com
    222.89.98.219 www.senovo.com
    222.89.98.219 www.my818.net
    222.89.98.219 www.jcwz.com
    222.89.98.219 www.130130.com
    222.89.98.219 www.13123.com
    222.89.98.219 www.140.cn
    222.89.98.219 www.haisanya.com
    222.89.98.219 www.kk369.com
    222.89.98.219 www.dtxj.com
    222.89.98.219 www.kelove.com
    222.89.98.219 www.51820.com
    222.89.98.219 www.k383.com
    222.89.98.219 www.2645.com
    222.89.98.219 www.goo123.com
    222.89.98.219 www.258.com
    222.89.98.219 www.actoz.net
    222.89.98.219 www.hao263.com
    222.89.98.219 www.365url.com
    222.89.98.219 www.shei.com
    222.89.98.219 www.3230.com
    222.89.98.219 www.0858178.com
    222.89.98.219 www.wqsj.com
    222.89.98.219 www.newbe.net
    222.89.98.219 www.qqq9.com
    222.89.98.219 www.01wz.com
    222.89.98.219 www.51com.net
    222.89.98.219 www.chinaxajh.net
    222.89.98.219 www.baidu.org
    222.89.98.219 www.4321.cn
    222.89.98.219 www.913w.com
    222.89.98.219 www.wz100.net
    222.89.98.219 www.9720.com
    222.89.98.219 www.hcwz.net
    222.89.98.219 www.52gp.net
    222.89.98.219 www.yepian.com
    222.89.98.219 www.shuxi.com
    222.89.98.219 hi.52l.com
    222.89.98.219 www.huoe.com
    222.89.98.219 www.ngwave.com
    222.89.98.219 www.com886.com
    222.89.98.219 www.2633.net
    222.89.98.219 www.35hao.com
    222.89.98.219 www.9g8.com
    222.89.98.219 www.158ok.com
    222.89.98.219 www.mfsky.com
    222.89.98.219 www.chnow.net
    222.89.98.219 www.mxzc.com
    222.89.98.219 www.bao123.net
    222.89.98.219 www.4286.com
    222.89.98.219 www.9430.com
    222.89.98.219 www.bizcn.com
    222.89.98.219 www.8007.com.cn
    222.89.98.219 www.wenxue123.com
    222.89.98.219 www.connexone.com
    222.89.98.219 www.7can.com
    222.89.98.219 www.cc7.cn
    222.89.98.219 dh.ovoe.com
    222.89.98.219 www.058.cn
    222.89.98.219 www.3lian.net
    222.89.98.219 www.s222.com
    222.89.98.219 www.cccweb.cn
    222.89.98.219 www.yi76.com
    222.89.98.219 www.qu123.com
    222.89.98.219 www.my8888.com
    222.89.98.219 www.74190.com
    222.89.98.219 www.zdao.net
    222.89.98.219 www.china320.com
    222.89.98.219 www.3w3w.net
    222.89.98.219 www.gigi.cn
    222.89.98.219 www.91so.com
    222.89.98.219 www.789.com.cn
    222.89.98.219 www.wwvww.com
    222.89.98.219 www.yukz.com
    222.89.98.219 www.52css.com
    222.89.98.219 www.wwwz.net
    222.89.98.219 www.hslz.com
    222.89.98.219 www.xingduo.com
    222.89.98.219 www.xinren.com.cn
    222.89.98.219 website.bigwww.com
    222.89.98.219 www.bigwww.com
    222.89.98.219 www.qingdaonews.com
    222.89.98.219 www.luosoft.com
    222.89.98.219 www.tt111.com
    222.89.98.219 www.cq6.com
    222.89.98.219 www.0791www.com
    222.89.98.219 www.111163.com
    222.89.98.219 www.zhfm.com
    222.89.98.219 www.ni123.com
    222.89.98.219 www.4431.com
    222.89.98.219 www.cool3721.com
    222.89.98.219 www.34560.com
    222.89.98.219 www.6560.com
    222.89.98.219 www.yt188.com
    222.89.98.219 www.kuzhan.net
    222.89.98.219 www.88521.com
    222.89.98.219 www.fj.cn
    222.89.98.219 www.qi123.com
    222.89.98.219 www.8zhi.com
    222.89.98.219 www.73333.com
    222.89.98.219 www.lydjp.com
    222.89.98.219 www.cnwzk.net
    222.89.98.219 www.168webs.com
    222.89.98.219 www.huan8.com
    222.89.98.219 www.xgmm.com
    222.89.98.219 www.fjsw.net
    222.89.98.219 www.ievv.com
    222.89.98.219 www.tt588.com
    222.89.98.219 www.26-3.com
    222.89.98.219 www.21red.net
    222.89.98.219 21red.net
    222.89.98.219 woo365.woocn.com
    222.89.98.219 www.woocn.com
    222.89.98.219 www.110112.com
    222.89.98.219 www.4f.cc
    222.89.98.219 www.chinacts.com
    222.89.98.219 www.517sc.com
    222.89.98.219 www.gameslife.net
    222.89.98.219 www.139cn.com
    222.89.98.219 www.5135.net
    222.89.98.219 search.114.com.cn
    222.89.98.219 www.1180.net
    222.89.98.219 www.jsurl.com
    222.89.98.219 www.163.sh
    222.89.98.219 www.verysearch.com
    222.89.98.219 www.fm520.com
    222.89.98.219 www.haowz.com
    222.89.98.219 www.hzs.cn
    222.89.98.219 www.gjj.cc
    222.89.98.219 www.zw88.com
    222.89.98.219 hao12.net
    222.89.98.219 www.hao12.net
    222.89.98.219 ya12.com
    222.89.98.219 www.ya12.com
    222.89.98.219 ha12.com
    222.89.98.219 www.ha12.com
    222.89.98.219 cn.wu123.com
    222.89.98.219 www.7720.com
    222.89.98.219 www.qqwz.com
    222.89.98.219 www.yetcn.com
    222.89.98.219 www.889889.com
    222.89.98.219 www.99000.net
    222.89.98.219 www.wzdq.net
    222.89.98.219 www.001.com.cn
    222.89.98.219 www.bbs.net
    222.89.98.219 www.21eee.com
    222.89.98.219 www.chinasee.com
    222.89.98.219 www.chinasee.net
    222.89.98.219 www.779.cn
    222.89.98.219 www.ai88.net
    222.89.98.219 www.haoabc.com
    222.89.98.219 www.baidu3.com
    222.89.98.219 www.20200.com
    222.89.98.219 www.shareshow.com
    222.89.98.219 www.anli.net
    222.89.98.219 www.9good.com
    222.89.98.219 www.c201.com
    222.89.98.219 www.5507.com
    222.89.98.219 www.baidu2.com
    222.89.98.219 www.kk99.com
    222.89.98.219 www.k666.com
    222.89.98.219 www.cidu.net
    222.89.98.219 www.xmok.com
    222.89.98.219 www.900du.com
    222.89.98.219 www.happy8.cn
    222.89.98.219 www.w3ww.net
    222.89.98.219 www.520day.com
    222.89.98.219 www.88qq.com
    222.89.98.219 www.qqtt.com
    222.89.98.219 www.sl520.com
    222.89.98.219 www.32e.com
    222.89.98.219 www.gjjc.com
    222.89.98.219 www.265cn.com
    222.89.98.219 www.15123.com
    222.89.98.219 www.ec35.com
    222.89.98.219 www.51115.com
    222.89.98.219 www.55wz.com
    222.89.98.219 www.ggxx.net
    222.89.98.219 www.51link.com
    222.89.98.219 www.xicu.com
    222.89.98.219 www.uu163.com
    222.89.98.219 www.zhss.com
    222.89.98.219 www.kv100.com
    222.89.98.219 www.1000www.com
    222.89.98.219 www.3ku.cn
    222.89.98.219 www.wu5.com
    222.89.98.219 www.qq125.com
    222.89.98.219 www.come114.com
    222.89.98.219 www.ziyue.com
    222.89.98.219 www.junwang-china.com
    222.89.98.219 www.dzdy.com
    222.89.98.219 www.film21cn.com
    222.89.98.219 movies.v111.com
    222.89.98.219 www.movie001.com
    222.89.98.219 vod.hengshui.com
    222.89.98.219 www.cnfilm.com
    222.89.98.219 cinema.tyfo.com
    222.89.98.219 www.xkqq.com
    222.89.98.219 www.seemovie.net
    222.89.98.219 www.efsms.com
    222.89.98.219 www.kanvcd.com
    222.89.98.219 www.52movie.com
    222.89.98.219 www.dianying.com
    222.89.98.219 www.xk88.com
    222.89.98.219 www.filmcn.com
    222.89.98.219 www.aizb.com
    222.89.98.219 www.look163.com
    222.89.98.219 www.ohfilm.com
    222.89.98.219 www.51seeing.com
    222.89.98.219 www.kkdu.com
    222.89.98.219 www.vod588.com
    222.89.98.219 www.mfdy.net
    222.89.98.219 www.16mp3.com
    222.89.98.219 www.hao8.cn
    222.89.98.219 www.juedui.com
    222.89.98.219 www.freefilm.cn
    222.89.98.219 www.v110.com
    222.89.98.219 www.tvvcd.com
    222.89.98.219 www.21play.com
    222.89.98.219 www.kooya.net
    222.89.98.219 vod.chinabzl.com
    222.89.98.219 www.x520x.com
    222.89.98.219 www.netbooksir.com
    222.89.98.219 wenxue.myrice.com
    222.89.98.219 wenxue.xilu.com
    222.89.98.219 www.rongshuxia.com
    222.89.98.219 wind.yinsha.com
    222.89.98.219 www.chinamp3.com
    222.89.98.219 www.sogua.com
    222.89.98.219 www.yy138.com
    222.89.98.219 www.loveproxy.com
    222.89.98.219 www.ucanlove.com
    222.89.98.219 www.zzlady.com
    222.89.98.219 www.wemarried.com
    222.89.98.219 www.yeeyoo.com
    222.89.98.219 www.uume.com
    222.89.98.219 www.you2you.com
    222.89.98.219 www.gycity.com
    222.89.98.219 www.cococ.com
    222.89.98.219 www.7xi.net
    222.89.98.219 www.cnmusic.com
    222.89.98.219 www.yyfc.com
    222.89.98.219 www.xkmm.com
    222.89.98.219 www.iq888.com
    222.89.98.219 www.mtvyy.com
    222.89.98.219 www.mp88.com
    222.89.98.219 www.zhao5.com
    222.89.98.219 www.qq500.com
    222.89.98.219 www.tn27.com
    222.89.98.219 www.vod99.com
    222.89.98.219 v.ilovex.net
    222.89.98.219 www.vovoo.com
    222.89.98.219 29.29bb.com
    222.89.98.219 www.pic163.com
    222.89.98.219 www.911mm.cn
    222.89.98.219 www.haha668.com
    222.89.98.219 www.bt001.com
    222.89.98.219 www.tu520.com
    222.89.98.219 www.pic21.net
    222.89.98.219 www.bbtav.com
    222.89.98.219 www.517tg.net
    222.89.98.219 www.newsw.net
    222.89.98.219 www.100dy.com
    222.89.98.219 www.bt001.com
    222.89.98.219 www.fm830.net
    222.89.98.219 www.163101.net
    222.89.98.219 www.oicqie.com
    222.89.98.219 www.tn27.com
    222.89.98.219 www.fm930.net
    222.89.98.219 www.tn16.com
    222.89.98.219 www.mayshop.com
    222.89.98.219 www.916918.com
    222.89.98.219 www.kk1688.com
    222.89.98.219 v.eband.com.cn
    222.89.98.219 www.so8a.com
    222.89.98.219 www.newsw.net
    222.89.98.219 www.5iav.com
    222.89.98.219 www.dodofilm.com
    222.89.98.219 www.vod99.com
    222.89.98.219 www.tkfilm.com
    222.89.98.219 www.wg818.com
    222.89.98.219 www.longdvd.com
    222.89.98.219 www.eailv.com
    222.89.98.219 www.18up.com.cn
    222.89.98.219 www.51happy.com.cn
    222.89.98.219 www.aimaiti.com
    222.89.98.219 www.7cv.com
    222.89.98.219 www.sex-sky.net
    222.89.98.219 www.51sex.com.cn
    222.89.98.219 www.sh-yem.com
    222.89.98.219 www.kx8163.com
    222.89.98.219 www.lybaile.com
    222.89.98.219 www.xingfuquan.com
    222.89.98.219 www.mmbee.net
    222.89.98.219 www.5910.com.cn
    222.89.98.219 www.88ty.com
    222.89.98.219 www.to68.com
    222.89.98.219 www.sbeijing.com
    222.89.98.219 www.sex-xf.com
    222.89.98.219 www.18up.com.cn
    222.89.98.219 www.aichaohong.com
    222.89.98.219 www.xm18.com
    222.89.98.219 www.cydchina.com
    222.89.98.219 www.ld28.com
    222.89.98.219 www.18it.com
    222.89.98.219 www.52romeo.com
    222.89.98.219 www.7caihong.com
    222.89.98.219 www.bjxinglv.com
    222.89.98.219 www.xingfuquan.com
    222.89.98.219 www.shile.net
    222.89.98.219 www.gxcr.com
    222.89.98.219 www.wl51.com
    222.89.98.219 www.58183.com
    222.89.98.219 www.lnydy.com
    222.89.98.219 www.2hao.net
    222.89.98.219 www.totola.com
    222.89.98.219 5201413.com
    222.89.98.219 www.5201413.com
    222.89.98.219 www.tvliao.com
    222.89.98.219 www.sjliao.com
    222.89.98.219 www.ginhoo.com
    222.89.98.219 www.loveinhere.com
    222.89.98.219 www.loveliao.com
    222.89.98.219 www.meuu.com
    222.89.98.219 www.qq6000.com
    222.89.98.219 www.fx120.net
    222.89.98.219 www.5878.com
    222.89.98.219 www.9see.com
    222.89.98.219 www.98rm.com
    222.89.98.219 www.suiyuan.name
    222.89.98.219 www.3399.com
    222.89.98.219 www.hao513.com
    222.89.98.219 www.hxjh.net
    222.89.98.219 www.ylpj.com
    222.89.98.219 www.5i2.com
    222.89.98.219 www.heliao.com
    222.89.98.219 www.t987.net
    222.89.98.219 wo365.com
    222.89.98.219 www.xk99.com
    222.89.98.219 xk99.com
    222.89.98.219 yymp3.com
    222.89.98.219 520music.com
    222.89.98.219 da123.com
    222.89.98.219 www.v111.com
    222.89.98.219 v111.com
    222.89.98.219 5566.net
    222.89.98.219 www.5566.org
    222.89.98.219 www.zhao123.com
    222.89.98.219 www.z163.com
    222.89.98.219 www.bihao.com
    222.89.98.219 www.haoyy.com
    222.89.98.219 www.qq32.com
    222.89.98.219 www.wenxuecity.com
    222.89.98.219 www.shangdu.net
    222.89.98.219 www.haohz.com
    222.89.98.219 www.5755.com
    222.89.98.219 www.shopping7.org
    222.89.98.219 www.881903.com
    222.89.98.219 www.99bb.com
    222.89.98.219 www.sexushost.com
    222.89.98.219 www.ting88.com
    222.89.98.219 www.88uu.com
    222.89.98.219 www.yiwubag.com
    222.89.98.219 www.sexhu.com
    222.89.98.219 www.mtv99.com
    222.89.98.219 www.hao138.com
    222.89.98.219 www.37021.com
    222.89.98.219 37021.com
    222.89.98.219 www.jjwxc.net
    222.89.98.219 www.pmsky.com
    222.89.98.219 www.1ting.com
    222.89.98.219 www.qq12.com
    222.89.98.219 5898.com
    222.89.98.219 www.5898.com
    222.89.98.219 99bbs.com
    222.89.98.219 www.99bbs.com
    222.89.98.219 bbs.99bbs.com
    222.89.98.219 www.666d.com
    222.89.98.219 www.zpzz.com
    222.89.98.219 www.xdao.com
    222.89.98.219 webspacecn.com
    222.89.98.219 www.v61.net
    222.89.98.219 book.haodx.com
    222.89.98.219 www.xdao.com
    222.89.98.219 www.214g.com
    222.89.98.219 www.a263.com
    222.89.98.219 9617.com
    222.89.98.219 hung-ya.com
    222.89.98.219 21pk.com
    222.89.98.219 wo123.com
    222.89.98.219 518sex.net
    222.89.98.219 666ccc.com
    222.89.98.219 aisex.com
    222.89.98.219 91look.com
    222.89.98.219 h2004.com
    222.89.98.219 wg999.com
    222.89.98.219 qq163.com
    222.89.98.219 7j.cn
    222.89.98.219 55025.net
    222.89.98.219 dydy.iskydown.com
    222.89.98.219 www.zyew.com
    222.89.98.219 www.33uu.com
    222.89.98.219 www.showqq.com
    222.89.98.219 www.204.cn
    222.89.98.219 www.g3g4.com
    222.89.98.219 www.178ya.com
    222.89.98.219 www.88tv.net
    222.89.98.219 www.58q.com
    222.89.98.219 www.fjwz.com
    222.89.98.219 www.ok520.com
    222.89.98.219 bbs.morok.net
    222.89.98.219 www.morok.net
    222.89.98.219 www.11511.com
    222.89.98.219 www.coke163.com
    222.89.98.219 www.mtv68.com
    222.89.98.219 www.66660.com
    222.89.98.219 www.yy138.com
    222.89.98.219 www.4399.com
    222.89.98.219 www.hao222.net
    222.89.98.219 www.hao222.com
    222.89.98.219 www.8825.com
    222.89.98.219 www.zhss.com
    222.89.98.219 www.rmbchina.com
    222.89.98.219 www.qq6.cn
    222.89.98.219 www.94look.com
    222.89.98.219 www.h2006.com
    222.89.98.219 www.1717kan.com
    222.89.98.219 www.88tv.net
    222.89.98.219 www.178ya.com
    222.89.98.219 www.g3g4.com
    222.89.98.219 www.204.cn
    222.89.98.219 www.showqq.com
    222.89.98.219 www.crwx.net
    222.89.98.219 www.21pk.com
    222.89.98.219 www.33uu.com
    222.89.98.219 www.gameswg.com
    222.89.98.219 www.qq230.net
    222.89.98.219 www.zyew.com
    222.89.98.219 www.15kan.com
    222.89.98.219 www.qq36.com
    222.89.98.219 www.djfilm.com
    222.89.98.219 www.hao168.com
    222.89.98.219 www.17bao.com
    222.89.98.219 www.225.com.cn
    222.89.98.219 www.025ma.com
    222.89.98.219 www.qq500.com
    222.89.98.219 www.kanfilm.com
    222.89.98.219 www.mm8.cn
    222.89.98.219 www.japansky.net
    222.89.98.219 vod.chinasee.net
    222.89.98.219 www.ftpok.com
    222.89.98.219 www.mtv888.com
    222.89.98.219 www.mtvccc.com
    222.89.98.219 www.51k6.com
    222.89.98.219 www.juedui.com
    222.89.98.219 www.mm80.com
    222.89.98.219 www.huole.com
    222.89.98.219 www.avgod.com
    222.89.98.219 www.wethk.com
    222.89.98.219 www.999rave.com
    222.89.98.219 www.999bobo.com
    222.89.98.219 www.999cartoon.com
    222.89.98.219 www.999hotgirl.com
    222.89.98.219 www.999real.com
    222.89.98.219 www.51dd.com
    222.89.98.219 www.xxbooks.com
    222.89.98.219 www.518sex.net
    222.89.98.219 www.33uu.com
    222.89.98.219 www.sohu123.net
    222.89.98.219 www.wg999.com
    222.89.98.219 www.17ez.com
    222.89.98.219 www.92game.com
    222.89.98.219 www.cnoicq.net
    222.89.98.219 www.wu123.com
    222.89.98.219 www.88gg.com
    222.89.98.219 www.00vv.com
    222.89.98.219 www.sexshu.com
    222.89.98.219 www.xxbooks.com
    222.89.98.219 v.chiqing.com
    222.89.98.219 www.oicq88.com
    222.89.98.219 www.2791.com
    222.89.98.219 www.5lover.com
    222.89.98.219 www.wgyy.com
    222.89.98.219 www.jpwx.com
    222.89.98.219 www.7j.cn
    222.89.98.219 www.xxxpanda.com
    222.89.98.219 www.postadult.com
    222.89.98.219 www.avvcd.com
    222.89.98.219 www.Hung-ya.com
    222.89.98.219 www.onlypost.com
    222.89.98.219 www.Hell-angel.com
    222.89.98.219 www.380.cn
    222.89.98.219 www.xxgirls.net
    222.89.98.219 www.3xbbs.com
    222.89.98.219 www.sexy-books.com
    222.89.98.219 www.xxbooks.com
    222.89.98.219 www.xxstory.net
    222.89.98.219 www.qqwz.com
    222.89.98.219 www.h2004.com
    222.89.98.219 www.no1vod.com
    222.89.98.219 www.ccfilm.com
    222.89.98.219 www.xgfilm.com
    222.89.98.219 www.lhfilm.com
    222.89.98.219 www.qq163.net
    222.89.98.219 www.goodwww.com
    222.89.98.219 bbs.cnxp.com
    222.89.98.219 bt.cnxp.com
    222.89.98.219 www.139mm.com
    222.89.98.219 www.qq78.com
    222.89.98.219 www.gaoshou.net
    222.89.98.219 www.yingku.com
    222.89.98.219 www.flash51.com
    222.89.98.219 www.woogood.com
    222.89.98.219 www.cnxp.com
    222.89.98.219 www.musicfbi.com
    222.89.98.219 www.9i0.com
    222.89.98.219 www.btchina.net
    222.89.98.219 www.x365x.net
    222.89.98.219 www.x365x.com
    222.89.98.219 www.17777.com
    222.89.98.219 www.51115.com
    222.89.98.219 www.v23.com
    222.89.98.219 www.5isex.com
    222.89.98.219 www.yes-movies.com
    222.89.98.219 www.link8.com
    222.89.98.219 www.da123.com
    222.89.98.219 www.best161.com
    222.89.98.219 www.99music.net
    222.89.98.219 www.8812345.com
    222.89.98.219 www.130130.com
    222.89.98.219 www.btbbt.com
    222.89.98.219 www.520music.com
    222.89.98.219 www.91look.net
    222.89.98.219 www.91look.com
    222.89.98.219 www.mypcera.com
    222.89.98.219 www.aisex.com
    222.89.98.219 www.qq163.com
    222.89.98.219 www.025ma.com
    222.89.98.219 www.wenxuecity.com
    222.89.98.219 www.33mp3.com
    222.89.98.219 www.20jack.com
    222.89.98.219 www.18jack.com
    222.89.98.219 www.w12345.com
    222.89.98.219 www.cnxxx.com
    222.89.98.219 www.18-girl.net
    222.89.98.219 www.sexy-books.com
    222.89.98.219 www.cococ.com
    222.89.98.219 www.cococn.com
    222.89.98.219 www.postadult.com
    222.89.98.219 www.365ww.com
    222.89.98.219 www.klyy.net
    222.89.98.219 www.sunmovie.net
    222.89.98.219 www.topdy.com
    222.89.98.219 www.qq001.com
    222.89.98.219 www.free-movie.org
    222.89.98.219 www.tk4479.com
    222.89.98.219 www.88860.com
    222.89.98.219 www.cct5.com
    222.89.98.219 www.kan5.com
    222.89.98.219 www.freefilm.cn
    222.89.98.219 www.55025.net
    222.89.98.219 www.kan51.com
    222.89.98.219 www.chinasee.net
    222.89.98.219 www.kanvcd.com
    222.89.98.219 www.movie4.com
    222.89.98.219 www.vodfans.com
    222.89.98.219 www.fhvcd.com
    222.89.98.219 www.wysw.com
    222.89.98.219 www.t3j4.com
    222.89.98.219 www.kan123.com
    222.89.98.219 www.chinavbar.com
    222.89.98.219 www.5566.net
    222.89.98.219 www.88321.com
    222.89.98.219 www.ttjj.com
    222.89.98.219 www.wo123.com
    222.89.98.219 www.cnww.net
    222.89.98.219 www.9617.com
    222.89.98.219 www.haodx.com
    222.89.98.219 www.66vv.net
    222.89.98.219 www.3tom.com
    222.89.98.219 www.vv66.net
    222.89.98.219 www.dj99.com
    222.89.98.219 www.tt78.com
    222.89.98.219 www.6y.cn
    222.89.98.219 www.yymp3.com
    222.89.98.219 www.99music.com
    222.89.98.219 www.5music.org
    222.89.98.219 www.7xi.net
    222.89.98.219 www.qq230.com
    222.89.98.219 www.666ccc.com
    222.89.98.219 www.666e.com
    222.89.98.219 www.qq530.com
    222.89.98.219 www.vv66.com
    222.89.98.219 www.dj99.net


Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Use a firewall to block all incoming connections from the Internet to services that should not be publicly available. By default, you should deny all incoming connections and only allow services you explicitly want to offer to the outside world.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Ensure that programs and users of the computer use the lowest level of privileges necessary to complete a task. When prompted for a root or UAC password, ensure that the program asking for administration-level access is a legitimate application.
  • Disable AutoPlay to prevent the automatic launching of executable files on network and removable drives, and disconnect the drives when not required. If write access is not required, enable read-only mode if the option is available.
  • Turn off file sharing if not needed. If file sharing is required, use ACLs and password protection to limit access. Disable anonymous access to shared folders. Grant access only to user accounts with strong passwords to folders that must be shared.
  • Turn off and remove unnecessary services. By default, many operating systems install auxiliary services that are not critical. These services are avenues of attack. If they are removed, threats have less avenues of attack.
  • If a threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread threats, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate compromised computers quickly to prevent threats from spreading further. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.
  • If Bluetooth is not required for mobile devices, it should be turned off. If you require its use, ensure that the device's visibility is set to "Hidden" so that it cannot be scanned by other Bluetooth devices. If device pairing must be used, ensure that all devices are set to "Unauthorized", requiring authorization for each connection request. Do not accept applications that are unsigned or sent from unknown sources.
  • For further information on the terms used in this document, please refer to the Security Response glossary.

Writeup By: Hiroshi Shinotsuka
Search by name
Example: W32.Beagle.AG@mm
Limited Time Offers! Save up to 50%
Windows Vista Security