Win32.Hack.Ppdoor.at

王朝system·作者佚名  2008-08-14
窄屏简体版  字體: |||超大  

病毒名称(中文):

病毒别名:

威胁级别:

★★☆☆☆

病毒类型:

黑客程序

病毒长度:

74752

影响系统:

Win9xWinNT

病毒行为:

这是一个通过p2p传播的后门程序,能关闭大量安全软件,下载后门程序,开放特定的端口,并把自身作为服务,端,留下安全隐患。

1,释放下列文件

%system%\ipxrbase.exe

%root%\programfiles\internetexplorer\iexplore.exe

%system%\kasgfka.dll

%system%\jobdrkmj.dll

2,修改注册表:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

添加:"AccessWebControl=%system%\ipxrbase.exe"

达到自启动的目的

3关闭以下安全软件:

"mcshield"

"vsstat"

"avconsol"

"mcagent"

"mcvsescn"

"myagtt"

"shstat"

"avpcc"

"avp32"

"avpm"

"avpupd"

"kavi"

"pavsrv"

"apvxdw"

"drweb"

"spider"

"dwwin"

"drwtsn32"

"ccapp"

"vptray"

"navw32"

"navapw"

"pccgu"

"pccl"

"aveage"

"tmlist"

"pccnt"

"ash"

"asv"

"asw"

"avg"

"kwatch"

"kav32."

"*kav6"

"giantanti"

"gcasserv"

"gcasdts"

"spysweeper"

"kpf"

"vsmon"

"zlclient"

"outpost"

"persfw"

"smc.exe"

"smcserv"

"sysgut"

"sygate"

"cpd.exe"

"firewall"

"ca.exe"

"avguard.exe"

"procexp",

"autoruns"

"pskill"

"rootkit"

"wuauclt"

"wuauserv"

"*mcafee"

"*norton"

"*panda"

"*avast"

"*avg",0

"*kerio",0

等等

4从以下网址下载后门程序:

http://www.amazing******.com/counter.php?i=130913&c=393052******

5,通过p2p传播,并开放相应的端口,留下安全隐患。

 
 
 
免责声明:本文为网络用户发布,其观点仅代表作者个人观点,与本站无关,本站仅提供信息存储服务。文中陈述内容未经本站证实,其真实性、完整性、及时性本站不作任何保证或承诺,请读者仅作参考,并请自行核实相关内容。
 
 
© 2005- 王朝網路 版權所有 導航