爱毒霸社区
拒绝当“肉鸡” 保安获大奖!
顽固病毒解决方案大全
一点一滴学电脑应用技巧
毒霸2008教程——清理专家
欺骗是攻击者最热衷的手法
爱毒霸社区推荐安全工具下载
如何使用命令行查毒
远程清除机器狗病毒实战
清理专家在手,菜鸟杀毒不愁
如何判断进程或程序是否安全
windows安全漏洞的解释索引
史上最强磁碟机病毒清除思路
金山ARP防火墙1.2版功能简介
这是一个通过邮件传播的蠕虫病毒,该病毒会在感染机器上搜索邮件地址,把自己发送到这个地址,还会修改大量IE设置。
1.生成文件:
%Windows%\ShellNew\ElnorB.exe
%Documents and Settings%\%User%\Local Settings\Application Data\csrss.exe
%Documents and Settings%\%User%\Local Settings\Application Data\inetinfo.exe
%Documents and Settings%\%User%\Local Settings\Application Data\lsass.exe
%Documents and Settings%\%User%\Local Settings\Application Data\services.exe
%Documents and Settings%\%User%\Local Settings\Application Data\smss.exe
%Documents and Settings%\%User%\Local Settings\Application Data\winlogon.exe
%Documents and Settings%\%User%\Templates\bararontok.com
%Documents and Settings%\%User%\「开始」菜单\程序\启动\Empty.pif
%System%\%user name%"s Setting.scr
%windows%\Tasks\At1.job
2.添加注册表起始项,使病毒开机运行:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Bron-Spizaetus
%Systemroot%\ShellNew\ElnorB.exe
3.计划任务At1.job
内容为每天17:08启动病毒%Documents and Settings%\%User%\Templates\bararontok.com
注释为: 由NetScheduleJobAdd 创建
4.修改以下键值:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableCMD
0
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
0
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
5,从感染机器中搜索以下后缀的文件,来寻找邮件地址
asp
cfm
csv
doc
eml
html
php
txt
wab
6,过滤包含下列字符串的邮件地址
ADMIN
AHNLAB
ALADDIN
ALERT
ALWIL
ANTIGEN
ASSOCIATE
AVAST
AVIRA
BILLING@
BUILDER
CILLIN
CONTOH
CRACK
DATABASE
DEVELOP
ESAFE
ESAVE
ESCAN
EXAMPLE
GRISOFT
HAURI
INFO@
LINUX
MASTER
MICROSOFT
NETWORK
NOD32
NORMAN
NORTON
PANDA
PROGRAM
PROLAND
PROTECT
ROBOT
SECURITY
SOURCE
SYBARI
SYMANTEC
TRUST
UPDATE
VAKSIN
VAKSIN
VIRUS