Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!
Credits 2,165 Posts 730 Joined 2004-04-21 00:00 22-year member UID 22966 Gender Male
Status Offline
I found that: as long as (when Active Scripting is not disabled in IE) opening the union homepage dos.e-stone.cn, it will automatically chain to http://833200.com/index/ to execute an HTML application of lhxyhta.hta, which will further generate the win.hta file under the root directory of the C drive, and finally generate a program of intrenat.exe under the WINDOWS system directory, and run (resident) and modify the registry to start with WINDOWS. This program is shelled, and it seems to be stealing passwords or something.
Credits 27,736 Posts 10,521 Joined 2002-10-09 12:00 23-year member UID 9
Status Offline
Oh, I really don't know who did it. Just now I checked the homepage and have deleted that code segment inside (I remember there didn't seem to be this extra code before). Thanks for reporting!
Credits 2,165 Posts 730 Joined 2004-04-21 00:00 22-year member UID 22966 Gender Male
Status Offline
Two more points were omitted:
This Trojan horse will also generate two files in the system directory: WinSocks.dll and SYSTEMwin.exe (at first glance, it seems like system files).
Please friends who visited the DOS Union homepage a while ago carefully check your own computers.
c. Be more careful in the future