病毒名称(中文):
安哥
病毒别名:
W32.HLLW.Polybot,Phatbot,W32/Polybot.l!irc[McAf
威胁级别:
★★★☆☆
病毒类型:
黑客程序
病毒长度:
103
影响系统:
Win9xWinNTWin2000WinXPWin2003
病毒行为:
编写工具:
传染条件:
发作条件:
系统修改:
A、在系统目录拷贝其自身为以下文件之一:
%System%soundman.exe
%System%confgldr.exe
%System%spoolsvc.exe
%System%winwork.exe
%System%winhelp.exe
%System%csrs.exe
B、在注册表主键:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices
下添加如下键值之一:
"^`d}qZxu"="~`d}qzxu3zYF"
"ConfigurationLoader"="confgldr.exe"
"VideoProcess"="sysconf.exe"
"ServiceHostProcess"="spoolsvc.exe"
"Winmsg"="winwork.exe"
"svchost"="winhelp.exe"
"csrs"="csrs.exe"
C、以以下名称之一建立一个服务:
ConfigurationLoader
SoundMan
ServiceHostProcess
D、隐藏包含字符"soun."的所有文件;
E、在%System%driversetchosts文件中添加以下行:
127.0.0.1www.symantec.com
127.0.0.1securityresponse.symantec.com
127.0.0.1symantec.com
127.0.0.1www.sophos.com
127.0.0.1sophos.com
127.0.0.1sophos.com
127.0.0.1www.mcafee.com
127.0.0.1mcafee.com
127.0.0.1liveupdate.symantecliveupdate.com
127.0.0.1www.viruslist.com
127.0.0.1viruslist.com
127.0.0.1viruslist.com
127.0.0.1f-secure.com
127.0.0.1www.f-secure.com
127.0.0.1kaspersky.com
127.0.0.1www.avp.com
127.0.0.1www.kaspersky.com
127.0.0.1avp.com
127.0.0.1www.networkassociates.com
127.0.0.1networkassociates.com
127.0.0.1www.ca.com
127.0.0.1ca.com
127.0.0.1mast.mcafee.com
127.0.0.1my-etrust.com
127.0.0.1www.my-etrust.com
127.0.0.1download.mcafee.com
127.0.0.1dispatch.mcafee.com
127.0.0.1secure.nai.com
127.0.0.1nai.com
127.0.0.1www.nai.com
127.0.0.1update.symantec.com
127.0.0.1updates.symantec.com
127.0.0.1us.mcafee.com
127.0.0.1liveupdate.symantec.com
127.0.0.1customer.symantec.com
127.0.0.1rads.mcafee.com
127.0.0.1trendmicro.com
127.0.0.1www.trendmicro.com
发作现象:
非凡说明: