Jiang Min reminds you to pay attention today: TrojanDownloader.Losabel.ay “dew Sa” variety ay and Trojan/Monder.ams “the modern king” variety ams is worth in today's virus paying attention.
Viral name: TrojanDownloader.Losabel.ay
Chinese name: “dew Sa” variety ay
Viral length: 50688 bytes
Viral type: Wooden horse downloading
Dangerous rank: ¡ï¡ï
Affects the platform: Win 9X/ME/NT/2000/XP/2003
TrojanDownloader.Losabel.ay “dew Sa” variety ay is “dew Sa” one of wooden horse family's most young bloods, uses the Delphi compilation, and after adds shell processing. after “dew Sa” variety ay movement, duplicates is infected the computer system “%SystemRoot% \ system32 \” under the table of contents, names again as “lsasss.exe”. Duplicates in the system initiation menu, names again as “winpapt.exe”. The revision registry, realizes the wooden horse starting automatic movement. In is infected computer system's backstage to connect the hacker to assign the stand, the gain evil intention procedure downloading address tabulation, and downloads all malicious procedure. And, downloads the malicious procedure possibly is steals the network game account household the wooden horse, the advertisement procedure, the back door and so on, for is infected the computer user to bring the varying degree the loss. The distortion registry, realizes the advancement reflection to kidnap forcefully, causes the user to move time certain safety procedures what in fact moves is “dew Sa” variety ay, even the system bringing duty supervisor is also unable the normal operation. In is infected computer system's backstage discreet surveillance advancement which moves and already the window title which opens, once discovered that certain security software routine is moving, closes forcefully immediately it. The destruction registry item, the cause is unable to demonstrate the hideaway document. Traversal user computer's C to the Z driver, the foundation “autorun.inf” the document as well as the viral transcription, using the U plate, moves mobile equipments and so on hard disk to carry on the dissemination. after “dew Sa” the variety ay execution the installation procedure finished, meets the deletion. Moreover, “dew Sa” variety ay may also from the promotion.
Viral name: Trojan/Monder.ams
Chinese name: “modern king” variety ams
Viral length: 101440 bytes
Viral type: Wooden horse
Dangerous rank: ¡ï¡ï
Affects the platform: Win 9X/ME/NT/2000/XP/2003
Trojan/Monder.ams “the modern king” variety ams is “the modern king” one of wooden horse family's most young bloods, uses the higher order language compilation, releases the DLL wooden horse module by some wooden horse procedure, generally realizes the wooden horse starting automatic movement through the revision registry. “modern king” variety ams usual movement in “iexplore.exe” in advancement, by this hideaway, avoidance security software's Zha Sha. after “modern king” variety ams load movement, can spring the advertisement window occasionally, serious influence user's normal operation. Through promotes own jurisdiction, to tamper with method searches forcefully and so on registry key value and closes the massive popular security software, the browser auxiliary security plug-in unit forcefully and so on, and will possibly unload certain security software, reduced enormously was infected computer system's security. Is infected in the backstage secret collection computer's system message to give concurrently the hacker. Connects the server which in the backstage the hacker assigns, the downloading evil intention procedure and, in is infected on the computer the automatic transfer movement. And, downloads the malicious procedure possibly is the net tours the wooden horse, the advertisement procedure (hoodlum software), the back door and so on, for is infected the computer user to bring the varying degree the loss.
Other pages: : 1 * 2 * Next>>
|