病毒名称(中文):
病毒别名:
威胁级别:
★☆☆☆☆
病毒类型:
木马程序
病毒长度:
29696
影响系统:
Win9xWinNTWin2000WinXPWin2003
病毒行为:
编写工具:
传染条件:
发作条件:
系统修改:
A、在系统安装目录下生成如下文件:
%SystemRoot%e.exe
%SystemRoot%dpe.dll
B、
1、在注册表主键:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionRun
下添加如下键值:
"addClass"="%SystemRoot%e.exe"
使用每次运行都自动注册dep.dll
2、HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionRun
下添加如下键值:
"Host"=""
3、在注册表主键:
HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearch
HKEY_LOCAL_MACHINESoftwareMicrosoftInternetExplorerSearch
下添加如下键值:
"默认"="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
"CustomizeSearch"="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
"SearchAssistant"="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
4、在注册表主键:
HKEY_CURRENT_USERSOFTWAREMicrosoftInternetExplorerMain
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMain
下添加如下键值:
"SearchPage"="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
"Default_Search_URL"="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
"SearchBar"="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
"StartPage="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
5、在注册表主键:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchUrl
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchUrl
下添加如下键值:
"默认"="http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%73%65%61%72%63%68/"
使得用户搜索时,链接到指定网站
6、在注册表主键:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionURLDefaultPrefix
下添加如下键值:
"默认"="http://%65%68%74%74%70%2E%63%63/?"
7、在注册表主键:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionURLPrefixes
下添加如下键值:
"www"="http://%65%68%74%74%70%2E%63%63/?"
8、在注册表主键:
HKEY_CLASSES_ROOTCLSID
下添加如下创建子键
{834261E1-DD97-4177-853B-C907E5D5BD6E}
并这个子建立多个键值
发作现象:
浏览器默认首页被修改,并且很难改成其它的主页。
非凡说明: