µ×¤·¤Ö¤ê¤Ë¾ã³²¥ì¥Ý¡¼¥È
°ÊÁ°¤«¤é¤è¤¯¤¢¤ë¾ã³²¤Î°ì¤Ä¤Ç¡¢¡Öspoolsv.exe¡×¤¬CPU¤òÀêµò¤·¡¢¥Ñ¥½¥³¥ó¤Îưºî¤¬ÉÔ°ÂÄê¤Ë¤Ê¤Ã¤¿¾ì¹ç¤ÎÂнèË¡¡£
spoolsv.exe¤È¤Ï¡¢¥×¥ê¥ó¥È¤¹¤ë¾ì¹ç¤Ë¡¢¥×¥ê¥ó¥¿¤Î°õºþ¾ðÊó¤ò¥¹¥×¡¼¥ë¡ÊÃߤ¨¤Æ¡Ë¤·¡¢ÃÙ±ä°õºþ¤ò¤¹¤ë¤¿¤á¤Ë¡¢¥Õ¥¡¥¤¥ë¤òÆÉ¤ß¹þ¤ó¤Ç¥á¥â¥ê¤Ë³ÊǼ¤¹¤ë¥×¥í¥°¥é¥à¤Ç¤¢¤ê¡¢°õºþ¤ò¤¹¤ë¾ì¹ç¤ËɬÍפʥե¡¥¤¥ë¤Ç¤¢¤ë¡£
¤è¤Ã¤Æ¡¢¤¿¤Àñ¤Ë¡Ö¥µ¡¼¥Ó¥¹¤ÎÄä»ß¡×¤ò¹Ô¤Ã¤Æ¡¢Ää»ß¤·¤Æ¤â½ªÎ»¤Ï¤Ç¤¤ë¤¬¡¢°õºþ¤¬¤Ç¤¤Ê¤¯¤Ê¤ë¤¿¤á¡¢°Â°×¤Ë½ªÎ»¤¹¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤¡£
°õºþ¤ò¹Ô¤¦¥Ñ¥½¥³¥ó¤Ç¤¢¤ì¤Ð¡¢Î©¤Á¾å¤¬¤Ã¤Æ¤¤¤Ê¤¤¤È¥À¥á¤À¤È¤¤¤¦¤³¤È¤Ë¤Ê¤ë¡£
¤·¤«¤·¡¢¥Ñ¥½¥³¥ó¤¬µÞ¤Ë¥Õ¥ê¡¼¥º¤¹¤ë¤³¤È¤¬Áý¤¨¡¢¥¿¥¹¥¯¥Þ¥Í¡¼¥¸¥ã¤â³«¤«¤Ê¤¤¾õÂ֤ˤʤ롣
¾ã³²¥Ñ¥½¥³¥ó¤Î¥¹¥Ú¥Ã¥¯¤Ï°Ê²¼¤ÎÄ̤ê
OS¡§WindowsXP SP1
¥á¥â¥ê¡§512MB
CPU¡§Celeron¡¡2.7MHz
¤½¤Î¾¥¹¥Ú¥Ã¥¯¤Ï¸¶°ø¤Ë¤Ê¤é¤Ê¤¤¤Î¤Ç¡¢¾Ê¤¯¡£
¤Þ¤º¹Í¤¨¤é¤ì¤ë¸¶°ø¤ò¾å¤²¤Æ¤ß¤è¤¦¡£
1¡¥¥×¥ê¥ó¥¿¤Î°õºþ¤¬¤¿¤Þ¤Ã¤Æ¤¤¤ë
2. ¸½ºß¤Î¥á¥â¥ê¾õ¶·¤«¤é¹Ô¤±¤Ð¾¯¤Ê¤¤°Ù¡¢¡¢Æ°ºî¤¬ÃÙ¤¯¤Ê¤Ã¤¿¤Î¤Ç¤Ï¤Ê¤¤¤«¡£
3¡¥¥¦¥¤¥ë¥¹¤¬¸¶°ø¤Ç¤Ï¤Ê¤¤¤À¤í¤¦¤«
4. LAN¤ò¤Ä¤Ê¤²¤Æ¤¤¤ë´Ö¤ËȯÀ¸¤¹¤ë
5. SP1¤Î¤¿¤á¡¢SP¤¬ºÇ¿·¤Ç¤Ï¤Ê¤¤
¡Ö1¡×¤«¤é¹Í¤¨¤Æ¤ß¤ë¡£
¥×¥ê¥ó¥¿¤Î°õºþ¥¸¥ç¥Ö¤¬ºï½ü¤µ¤ì¤Ê¤¤¤Þ¤Þ¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ç¤Ï¤Ê¤¤¤«¡£
¤½¤Î¾ì¹ç¡¢spoolsv.exe¤Î¥×¥í¥»¥¹¤ò¤È¤á¤¿¸å¡¢¡ÖC:¥WINDOWS¥system32¥spool¥PRINTERS¡×¤ÎÃæ¤òºï½ü¤·¡¢ºÆÅÙspoolsv.exe¤Î¥×¥í¥»¥¹¤ò³«»Ï¤¹¤ì¤Ð¡¢Àµ¾ï¤ËÌá¤ë¡£
¤·¤«¤·¡¢C:¥WINDOWS¥system32¥spool¥PRINTERS¡×¤ÎÃæ¤Ï¥«¥é¤À¡£
¤È¤¤¤¦»ö¤Ç¡¢¼¡¤Î¸¡¾Ú¤Ø
¼¡¤Ë¥á¥â¥ê¤ÎÎ̤À¤¬¡¢Ä̾ï¤Îºî¶È¤Ë¤ÏÌäÂê¤Ê¤¤¤¿¤á¡¢¥×¥é¥¹512M¤Ë¤·¤Æ£±GÀѤó¤Ç¤â¾õ¶·¤ÏÊѤï¤é¤º¡£
¥á¥â¥ê¤¬Áý¤¨¤Æ¤â¡¢CPU¤ÏÊѤï¤é¤Ê¤¤¤Î¤Ç¡¢Åö¤¿¤êÁ°¤Ç¤¹¤¬¡¦¡¦¡¦
¤è¤Ã¤Æ¼¡
¤ä¤Ï¤ê¡¢¤³¤ì¤âÍÎϸõÊä¤Î°ì¤Ä
¡Ö3¡×¤Î¥¦¥¤¥ë¥¹¤Ç¤¢¤Ã¤¿¾ì¹ç¡¢¡ÖBackdoor.Graybird.E¡×Åù¤¬¹Í¤¨¤é¤ì¤ë
http://www.sophos.co.jp/security/analyses/viruses-and-spyware/trojgraybirda.html
¤·¤«¤·¡¢¥ì¥¸¥¹¥È¥ê¤Î²þ¤¶¤ó¤Ï°ìÀڤʤ·
¤¸¤ã¤¢¡¢¤¤¤Ã¤½LAN¤ò³°¤·¤Æ¤ß¤ë¡£
¤¹¤ë¤È¡¢º£¤Þ¤Ç100%¤À¤Ã¤¿CPU¤¬0¡ó¤Ë¤Ê¤ë¤Ç¤Ï¤Ê¤¤¤«¡£
¤³¤ì¤Ç¤¤¤¤¤Ï¤º¤¬¤Ê¤¤¡£
¤À¤Ã¤Æ¡¢º£¤Ï¡¢¤¹¤Ù¤Æ¥Í¥Ã¥È¥ï¡¼¥¯¤Ç¤Ä¤Ê¤¬¤Ã¤Æ¤¤¤ë´Ä¶¤Çºî¶È¤·¤Æ¤¤¤ë¤Î¤ËLAN¤¬¤Ä¤Ê¤¬¤Ã¤Æ¤¤¤Ê¤¤¤È¡¢»Å»ö¤Ë¤Ê¤é¤Ê¤¤¡£
¤è¤Ã¤Æ¡¢²ò·è¤Ë¤Ï»ê¤Ã¤Æ¤¤¤Ê¤¤¡£
¤·¤«¤·¡¢¤Ò¤È¤Ä¤ï¤«¤Ã¤¿¤³¤È¤Ï¡¢LAN¤ò¤Ä¤Ê¤²¤ë¤Èspoolsv¤«¤é²¿¤é¤«¤Î¥Ñ¥±¥Ã¥È¤òÁ÷¿®¤·¤Æ¤¤¤ë¤³¤È¤Ë¤Ê¤ë¡£
LAN¤ò³°¤¹¤È£°¤Ë¤Ê¤ë¤¬¡¢LAN¤ò¤Ä¤Ê¤²¤ë¤È100¡ó¤ËµÕÌá¤ê¡£
¡¦¡¦¡¦¤È¤¤¤¦¤³¤È¤Ï¡¢spoolsv¤¬°Õ¿ÞŪ¤Ë²¿¤«¤òȯ¿®¤·¤Æ¤¤¤ë¤³¤È¤Ë¤Ê¤ë¡£
ºÇ¸å¤ËSP¤ÎºÇ¿·ÈǤؤΥ¢¥Ã¥×¥Ç¡¼¥È¤À¡£
WindowsXP¤òSP1¢ªSP3¤Ø¥¢¥Ã¥×¥Ç¡¼¥È¤ò¹Ô¤¦¡£
¤·¤«¤·¡¢²¿¤éÊѤï¤ê¤Ï¤Ê¤¤¡£
¤¤¤í¤¤¤íÄ´¤Ù¤¿¤¬¡¢²ò·è¤Ç¤¤º¡£
ºÇ¸å¤Ë¥×¥ê¥ó¥¿¤âºï½ü¤·¤Æ¤ß¤ë¡¢
1Âæ¤ÏUSB
2Âæ¤¬¥Í¥Ã¥È¥ï¡¼¥¯¥×¥ê¥ó¥¿
¤â¤¦°ìÂæ¤¬¶¦Í¥×¥ê¥ó¥¿¤Î4Âæ¤¬ÍøÍѲÄǽ¤Ê¥×¥ê¥ó¥¿¡£
¤¹¤Ù¤Æ¤Î¥×¥ê¥ó¥¿¤¬¾Ã¤¨¤¿»þÅÀ¤Ç¡¢spoolsv.exe¤Îưºî¤¬°ÂÄꤷ¤¿¡£
¤³¤ì¤À¤Ã¤¿¤Î¤«¡£
¤¹¤Ù¤Æ¤Î¥×¥ê¥ó¥¿¤òºï½ü¤·¤Æ¡¢°ì¤Ä¤º¤ÄÍͻҤò¤ß¤ë¡£
USB¥×¥ê¥ó¥¿¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¡¢¥Í¥Ã¥È¥ï¡¼¥¯¥×¥ê¥ó¥¿¤âÆþ¤ì¤Æ¤ß¤ë¤¬¡¢
°ÂÄꤷ¤Æ¤¤¤ë¡£
spoolsv¤â0%¤Ç¤Ï¤Ê¤¤¤«¡£
¤³¤³¤Þ¤Ç½ñ¤¤¤Æ¡¢ºÇ¸å¤Ï¥×¥ê¥ó¥¿¤Îºï½ü¤Ç¼£¤ë¤È¤Ï¡¦¡¦¡¦¡¦
ºÇ½é¤Ë¤·¤Æ¤ª¤±¤Ð¤è¤«¤Ã¤¿¡£
Íפ¹¤ë¤Ëº£²ó¤Î¸¶°ø¤Ï¥×¥ê¥ó¥¿¥É¥é¥¤¥Ð¤ÎÉÔ¶ñ¹ç¤È¤¤¤¦»ö¤Ç²ò·è¤·¤Þ¤·¤¿¡£