病毒名称(中文):
病毒别名:
威胁级别:
★★☆☆☆
病毒类型:
木马程序
病毒长度:
61440
影响系统:
Win9xWinNT
病毒行为:
这是一个木马病毒,该病毒会盗取用户计算机上的传奇帐户密码,病毒还对抗安全软件.
1.生成文件:
C:\WINNT\HHBB.exe
%system%\HHBB.dll
%system%\WINDNS.exe
2.添加注册表项,使病毒开机运行:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
WINDNS.exe键值
WINDNS.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DDK键值
C:\WINNT\HHBB.exe
3.修改hosts文件,延长病毒生命周期:
127.0.0.1avp.com
127.0.0.1ca.com
127.0.0.1customer.symantec.com
127.0.0.1dispatch.mcafee.com
127.0.0.1download.mcafee.com
127.0.0.1f-secure.com
127.0.0.1kaspersky.com
127.0.0.1www.kasperksy-labs.com
127.0.0.1liveupdate.symantec.com
127.0.0.1liveupdate.symantecliveupdate.com
127.0.0.1mast.mcafee.com
127.0.0.1mcafee.com
127.0.0.1my-etrust.com
127.0.0.1nai.com
127.0.0.1networkassociates.com
127.0.0.1rads.mcafee.com
127.0.0.1secure.nai.com
127.0.0.1securityresponse.symantec.com
127.0.0.1sophos.com
127.0.0.1symantec.com
127.0.0.1trendmicro.com
127.0.0.1update.symantec.com
127.0.0.1updates.symantec.com
127.0.0.1us.mcafee.com
127.0.0.1viruslist.com
127.0.0.1www.avp.com
127.0.0.1www.ca.com
127.0.0.1www.f-secure.com
127.0.0.1www.kaspersky.com
127.0.0.1www.mcafee.com
127.0.0.1www.my-etrust.com
127.0.0.1www.symantec.com
127.0.0.1www.viruslist.com
127.0.0.1kaspersky-labs.com
127.0.0.1downloads-eu1.kaspersky-labs.com
127.0.0.1downloads-us1.kaspersky-labs.com
127.0.0.1downloads1.kaspersky-labs.com
127.0.0.1downloads2.kaspersky-labs.com
127.0.0.1downloads3.kaspersky-labs.com
127.0.0.1downloads4.kaspersky-labs.com
127.0.0.1windowsupdate.microsoft.com
127.0.0.1downloads5.kaspersky-labs.com
127.0.0.1ftp.avp.ru
127.0.0.1updates3.kaspersky-labs.com
127.0.0.1updates2.kaspersky-labs.com
127.0.0.1updates1.kaspersky-labs.com
127.0.0.1ftp.kaspersky.com
127.0.0.1downloads-us22.kaspersky-labs.com
127.0.0.1downloads-us1.kaspersky-labs.com
127.0.0.1downloads-us2l.kaspersky-labs.com
127.0.0.1downloads-eu2l.kaspersky-labs.com
127.0.0.1v4.windowsupdate.microsoft.com
127.0.0.1v5.windowsupdate.microsoft.com
127.0.0.1windowsupdate.microsoft.com
4.修改防火墙的规则,逃避防火墙的监视.
5.结束以下程序:
KV2004.exe
RavMon.exe
TfLockDownMain
ZoneAlarm
ZAFrameWnd
天网防火墙个人版
天网防火墙企业版
噬菌体
MAILMON.EXE
KAVPFW.EXE
IPARMOR.EXE
EGHOST.EXE