[quoted text, click to view] "Fred Yarbrough" <postmaster@127.0.0.1> wrote in message
news:ujk7uTxYGHA.4936@TK2MSFTNGP05.phx.gbl...
> Update.
>
> There is another IP address the infected machines are trying to contact
> 211.235.253.131.
>
> The file names also appear to somewhat random but have always been located
> in our c:\winnt\system32 directory. They always start with z and appear
> as
> 6 files on Windows 2000 Servers. Our Windows 2003 server only shows the
> single dll file.
> Here is what one of our W2K servers has for these files
>
> Zzgdqzow.dll
> Zzgdqzow.drv
> Zzgdqzow.ime
> Zzgdqzow.log
> Zzgdqzow.sys
> Zzgdqzow.tmp
>
>
> Fred
>
>
inetnum: 211.232.0.0 - 211.255.255.255
netname: KRNIC-KR
descr: KRNIC
descr: Korea Network Information Center
country: KR
admin-c: HM127-AP
tech-c: HM127-AP
remarks: ******************************************
remarks: KRNIC is the National Internet Registry
remarks: in Korea under APNIC. If you would like to
remarks: find assignment information in detail
remarks: please refer to the KRNIC Whois DB
remarks:
http://whois.nic.or.kr/english/index.html
remarks: ******************************************
mnt-by: APNIC-HM
mnt-lower: MNT-KRNIC-AP
changed: 20000908
changed: 20010627
status: ALLOCATED PORTABLE
source: APNIC
person: Host Master
address: 11F, KTF B/D, 1321-11, Seocho2-Dong, Seocho-Gu,
address: Seoul, Korea, 137-857
country: KR
phone: +82-2-2186-4500
fax-no: +82-2-2186-4496
e-mail:
nic-hdl: HM127-AP
mnt-by: MNT-KRNIC-AP
changed: 20020507
source: APNIC
inetnum: 211.235.253.128 - 211.235.253.255
netname: KRLINE-LLINE-ORAM-KR
descr: ORAM
country: KR
admin-c: HC081-KR
tech-c: HC081-KR
remarks: This IP address space has been allocated to KRNIC.
remarks: For more information, using KRNIC Whois Database
remarks: whois -h whois.nic.or.kr
mnt-by: MNT-KRNIC-AP
remarks: This information has been partially mirrored by APNIC from
remarks: KRNIC. To obtain more specific information, please use the
remarks: KRNIC whois server at whois.krnic.net.
changed:
source: KRNIC
begin 666 email.pgif?md5=b18767ae9a5497feae665542ba82612e
MB5!.1PT*&@H````-24A$4@```)4````3! ,```!K95*Y````&%!,5$7___\`
M``"?GY\_/S]?7U]_?W_?W]^_O[_]6702```!64E$051XG.U2RVK#,! <5#U^
M0YC4N1J2#S")TK,I2<_"-/)5Y&#]?D>V4\<-[2E0"AV$=K6S.UYI#?SC%V%G
MMUL08O:*PMXRBT.&\:.MYE"Q2'CZ].3I5-\RS5<M%4=[DW7Y3LOKA=8=KEI;
MU^!X@'"U<OMJU51XWP";%[UW.VQWJ(Z-;,N:/%9[K!SY*O-#\<99N .<<U-?
M9\G];>QK+27O_G;.W>1EK/)G*2S[DOQZO<YAED#$L?@BH1OEKY=O%7?#YTU
M4@+MJ007H^JUL!R!,@7Y9^'1I!QF">9B#D9,6A9"Y#UTG&-,0N@^E#QY@2!"
MH.%$@^]#RVG9'D-R.XW.HAMRO)FTC DA:FK1!&K1T/6,FN#1>N3T0*W,4TN7
M8([7VT&+4>3BC B#E* 3'R A& -#=SAYI#XODU+4*=$@(//(?-:*O L3T,4?
AYWR/ZQ_Y"#Q2ZX_B`SMX3GI&V3UR`````$E%3D2N0F""
`
end
begin 666 email.pgif?md5=28fb0dcfdfb657e893691610f5a2d6db
MB5!.1PT*&@H````-24A$4@```)8````1! ,```#-FDBQ````&%!,5$7___\`
M``"?GY\_/S]?7U]_?W_?W]^_O[_]6702```!2$E$051XG.U2L6[",!!],H[]
M&U:$PAH5V",([6HA8+8B<-:H0_S[?;8C`E)1IT[MZ>1[=_?R<O$%^!-F9M@_
M-<2,RC*QU/"#0#W#\HFSN"-Y/C=)R^ ;>Q!H9OCY2LNI!B_MH;5I+4X'B+8I
MVGV]M#6N:V#]KO;M#IL=ZI.57=6T;8.EA6[S&(N-N\J/::ZK[ Z3[$WRO.2Y
M5E(ZX'*+TT37IG W*0S[$LIB%<O(J-'IFV.XY.DLNH*GYO4&(!0"W;D"G=7B
M6!JNH-"EC;E*E.GF1CZ9[%@!588&0L33]]SC$(10HZ^8.0$OO&?@1KTC+2OH
MN]:TB<H[)I.6UMX/BEH,GEH,A(Y535KG$"6'J#6RWD-LP>@5AU&\6J.\&EW2
M&OBF$* "?YX`KS4T8<H<PAA=AS!$6I]IX@TL1>>.DH .[O6>_^WW[0M5146.
0Q#IP"P````!)14Y$KD)@@@``
`
end