| 導購 | 订阅 | 在线投稿
分享
 
 
 

Win32.Troj.PSWLineage.bw

來源:互聯網  2008-08-14 22:19:36  評論

病毒名稱(中文):

病毒別名:

威脅級別:

★★☆☆☆

病毒類型:

木馬程序

病毒長度:

61440

影響系統:

Win9xWinNT

病毒行爲:

這是一個木馬病毒,該病毒會盜取用戶計算機上的傳奇帳戶密碼,病毒還對抗安全軟件.

1.生成文件:

C:\WINNT\HHBB.exe

%system%\HHBB.dll

%system%\WINDNS.exe

2.添加注冊表項,使病毒開機運行:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

WINDNS.exe鍵值

WINDNS.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DDK鍵值

C:\WINNT\HHBB.exe

3.修改hosts文件,延長病毒生命周期:

127.0.0.1avp.com

127.0.0.1ca.com

127.0.0.1customer.symantec.com

127.0.0.1dispatch.mcafee.com

127.0.0.1download.mcafee.com

127.0.0.1f-secure.com

127.0.0.1kaspersky.com

127.0.0.1www.kasperksy-labs.com

127.0.0.1liveupdate.symantec.com

127.0.0.1liveupdate.symantecliveupdate.com

127.0.0.1mast.mcafee.com

127.0.0.1mcafee.com

127.0.0.1my-etrust.com

127.0.0.1nai.com

127.0.0.1networkassociates.com

127.0.0.1rads.mcafee.com

127.0.0.1secure.nai.com

127.0.0.1securityresponse.symantec.com

127.0.0.1sophos.com

127.0.0.1symantec.com

127.0.0.1trendmicro.com

127.0.0.1update.symantec.com

127.0.0.1updates.symantec.com

127.0.0.1us.mcafee.com

127.0.0.1viruslist.com

127.0.0.1www.avp.com

127.0.0.1www.ca.com

127.0.0.1www.f-secure.com

127.0.0.1www.kaspersky.com

127.0.0.1www.mcafee.com

127.0.0.1www.my-etrust.com

127.0.0.1www.symantec.com

127.0.0.1www.viruslist.com

127.0.0.1kaspersky-labs.com

127.0.0.1downloads-eu1.kaspersky-labs.com

127.0.0.1downloads-us1.kaspersky-labs.com

127.0.0.1downloads1.kaspersky-labs.com

127.0.0.1downloads2.kaspersky-labs.com

127.0.0.1downloads3.kaspersky-labs.com

127.0.0.1downloads4.kaspersky-labs.com

127.0.0.1windowsupdate.microsoft.com

127.0.0.1downloads5.kaspersky-labs.com

127.0.0.1ftp.avp.ru

127.0.0.1updates3.kaspersky-labs.com

127.0.0.1updates2.kaspersky-labs.com

127.0.0.1updates1.kaspersky-labs.com

127.0.0.1ftp.kaspersky.com

127.0.0.1downloads-us22.kaspersky-labs.com

127.0.0.1downloads-us1.kaspersky-labs.com

127.0.0.1downloads-us2l.kaspersky-labs.com

127.0.0.1downloads-eu2l.kaspersky-labs.com

127.0.0.1v4.windowsupdate.microsoft.com

127.0.0.1v5.windowsupdate.microsoft.com

127.0.0.1windowsupdate.microsoft.com

4.修改防火牆的規則,逃避防火牆的監視.

5.結束以下程序:

KV2004.exe

RavMon.exe

TfLockDownMain

ZoneAlarm

ZAFrameWnd

天網防火牆個人版

天網防火牆企業版

噬菌體

MAILMON.EXE

KAVPFW.EXE

IPARMOR.EXE

EGHOST.EXE

病毒名稱(中文): 病毒別名: 威脅級別: ★★☆☆☆ 病毒類型: 木馬程序 病毒長度: 61440 影響系統: Win9xWinNT 病毒行爲: 這是一個木馬病毒,該病毒會盜取用戶計算機上的傳奇帳戶密碼,病毒還對抗安全軟件. 1.生成文件: C:\WINNT\HHBB.exe %system%\HHBB.dll %system%\WINDNS.exe 2.添加注冊表項,使病毒開機運行: HKCU\Software\Microsoft\Windows\CurrentVersion\Run WINDNS.exe鍵值 WINDNS.exe HKLM\Software\Microsoft\Windows\CurrentVersion\Run DDK鍵值 C:\WINNT\HHBB.exe 3.修改hosts文件,延長病毒生命周期: 127.0.0.1avp.com 127.0.0.1ca.com 127.0.0.1customer.symantec.com 127.0.0.1dispatch.mcafee.com 127.0.0.1download.mcafee.com 127.0.0.1f-secure.com 127.0.0.1kaspersky.com 127.0.0.1www.kasperksy-labs.com 127.0.0.1liveupdate.symantec.com 127.0.0.1liveupdate.symantecliveupdate.com 127.0.0.1mast.mcafee.com 127.0.0.1mcafee.com 127.0.0.1my-etrust.com 127.0.0.1nai.com 127.0.0.1networkassociates.com 127.0.0.1rads.mcafee.com 127.0.0.1secure.nai.com 127.0.0.1securityresponse.symantec.com 127.0.0.1sophos.com 127.0.0.1symantec.com 127.0.0.1trendmicro.com 127.0.0.1update.symantec.com 127.0.0.1updates.symantec.com 127.0.0.1us.mcafee.com 127.0.0.1viruslist.com 127.0.0.1www.avp.com 127.0.0.1www.ca.com 127.0.0.1www.f-secure.com 127.0.0.1www.kaspersky.com 127.0.0.1www.mcafee.com 127.0.0.1www.my-etrust.com 127.0.0.1www.symantec.com 127.0.0.1www.viruslist.com 127.0.0.1kaspersky-labs.com 127.0.0.1downloads-eu1.kaspersky-labs.com 127.0.0.1downloads-us1.kaspersky-labs.com 127.0.0.1downloads1.kaspersky-labs.com 127.0.0.1downloads2.kaspersky-labs.com 127.0.0.1downloads3.kaspersky-labs.com 127.0.0.1downloads4.kaspersky-labs.com 127.0.0.1windowsupdate.microsoft.com 127.0.0.1downloads5.kaspersky-labs.com 127.0.0.1ftp.avp.ru 127.0.0.1updates3.kaspersky-labs.com 127.0.0.1updates2.kaspersky-labs.com 127.0.0.1updates1.kaspersky-labs.com 127.0.0.1ftp.kaspersky.com 127.0.0.1downloads-us22.kaspersky-labs.com 127.0.0.1downloads-us1.kaspersky-labs.com 127.0.0.1downloads-us2l.kaspersky-labs.com 127.0.0.1downloads-eu2l.kaspersky-labs.com 127.0.0.1v4.windowsupdate.microsoft.com 127.0.0.1v5.windowsupdate.microsoft.com 127.0.0.1windowsupdate.microsoft.com 4.修改防火牆的規則,逃避防火牆的監視. 5.結束以下程序: KV2004.exe RavMon.exe TfLockDownMain ZoneAlarm ZAFrameWnd 天網防火牆個人版 天網防火牆企業版 噬菌體 MAILMON.EXE KAVPFW.EXE IPARMOR.EXE EGHOST.EXE
󰈣󰈤
王朝萬家燈火計劃
期待原創作者加盟
 
 
 
>>返回首頁<<
 
 
 
 
 熱帖排行
 
 
 
靜靜地坐在廢墟上,四周的荒凉一望無際,忽然覺得,淒涼也很美
© 2005- 王朝網路 版權所有