病毒名称:
I-Worm.Hiton.dll.enc
类别: 蠕虫
病毒资料:
破坏方法:
一个蠕虫病毒
病毒行为:
病毒一运行,首先检测当前系统日期,月份大于3时病毒将从当前系统中删除自己。否则将自己复制到%WINDOWS%目录下文件名为:svchost.exe并从体内释放一个文件到%SYSTEM%目录下,文件名为:mssvc.dll并在修改以下注册表键:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Service Host Driver
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\EXPlorer\Data
HKEY_CURRENT_USER\Software\\Microsoft\\Command Processor\AutoRun
并把系统原来的CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32改成指向病毒释放的dll文件。
当病毒为第一次运行是:
将从HKEY_CLASSES_ROOT\mpegfile\shell\open\command读出文件名,并生成一个随机数据的temp文件用以下读出的文件名打开。(一般为Media Player)如果该注册表项不存在病毒将尝试用Notepad打开。
病毒不为第一次运行:
将搜索email地址,将检测是否为运行一天以后。如果是病毒将修改host文件并释放一个Mirc.ini 文件。
病毒从icq文件中读去共享目录并将建立一个目录并将自己复制过去:
(文件名为以下随机选择)
Wakeboard Unleashed,Veritas Backup Exec V91,ScanSoft OmniPage v14 Office,
PowerDVD 5 Deluxe,Pinnacle Studio v9 Multilanguage,Symantec Norton Anti Spam 2004
Enterprise
Symantec Norton Anti Virus 2004 Enterprise,Symantec Norton Systemworks 2004
Enterprise
School Tycoon,Point of Attack 2,Onimusha,Nero_Burning_Rom_6_0_0_1_9,Microsoft
Windows XP Media Center Edition 2004
Microsoft Windows XP SP2 No Activation,Microsoft Windows Server 2003,Microsoft
Technet 2004
Microsoft Systems Management Server 2003,Microsoft Office NET,McAfee Internet
Security 6
L'Entraineur 4 Saison 2003-2004 Multilangue.Legacy of Kain - Defiance,Leadtools
Multimedia Imaging Suite
Jack The Ripper.InstallShield DevStudio 9 SP1,Counter Strike - Condition Zero
Online
Geomagic Studio V6,FIFA Football 2004,Easy CD Creator 7,Deep Sea Tycoon.Dead to
Rights
Cyberlink PowerProdUCer 2 Gold,Borland C++ Builder X Enterprise,Borland JBuilder
X Enterprise
Borland Delphi 8 Enterprise,AutoCAD Mechanical 2004 DX,Adobe Illustrator CS,
Adobe InCopy CS
Adobe Atmosphere 1.0,3D Studio Max 6.
扩展名为:exe名src
病毒从以下扩展名文件中读取邮件地址并尝试向这些地址发送邮件。
.eml,.txt,.dbx,.hlp,.mht,.wab,.tbb,.htm
当病毒在尝试发邮件时发生错误将显示一个假的消息欺骗用户:(因为病毒利用dll进行发送邮件,所以具有很强的伪装性) Connection Error 66473:
Please check your Internet Connection
or Firewall. If the Error occurs again you
should Contact your ISP.
邮件含有的特征串:
i found this amazing file in my Recycled , i know u love this kind of things ;)
ONCRcyaaa........Hummm , i hope u accept this show as an apology.ONCRsave it for
hard times..i will be waiting for u emaill to remind me of your self....i'm fine ,
thanx for aSKINg :) ONCRand thanx for the nice attachements.ONCRbut unfortunately,
i don't remember you......you seem to be mad @ me coz i didn't send u anything for
along time,ONCRi didn't forget u , but i was kinda busy , i've got all of ur
emailsONCRthanx :) and i hope u accept this one as an apology.....i've got this
surprise from a friend :)ONCRit really deserves a few minutes of your
time.ONCRNever
mind !.......i thing the subject is enough to describe the attached file !ONCRcheck
it out and replay your opinion...heyyyy i tried many times to send u this email but
ur account was out of storage as i thinkONCRa
病毒的清除法:
使用光华反病毒软件,彻底删除。
病毒演示:
病毒FAQ:
Windows下的PE病毒。
发现日期:
2004-3-3