杀毒联盟帮你提供最完美的电脑病毒资讯网站Rss 2.0

今天是:

 杀毒联盟提供病毒资讯致力做中国最专业的网络学院! [设为首页]  [加入收藏]  [联系我们]
| 网站首页 | 病毒预警 | 最新病毒 | 业界新闻 | 系统进程 | 安全防御 | 解决方案 | 你问我答 |
您现在的位置: 杀毒联盟 >> 最新病毒 >> 正文 知识在于积累,成功在于努力。---杀毒联盟
SkypeClient.exe,sys_32.ini,映像劫持 冒牌Skype131212,Worm.Delf.cc.131212
杀毒联盟 www.shaduu.com 杀毒很难,防毒很简单,shaduu帮您成为防病毒高手为您提供技术信息   

          ★★★   作者:佚名    文章来源:互联网整理    点击数:    更新时间:2008-7-16 6:42:12 添加到百度搜藏 添加到百度搜藏 【字体:

SkypeClient.exe,sys_32.ini,映像劫持 冒牌Skype131212,Worm.Delf.cc.131212这个盗号木马会伪装成SkypeClient通讯软件,骗取用户下载,进入系统后建立监视,记录用户输入的信息。并连接指定的远程地址。它还会映像劫持大量的安全软件。

在磁盘中释放出以下文件:
C:\sys_32.ini
C:\WINDOWS\TEMP\SkypeClient.exe

在注册表中创建了以下信息:
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\I mage File Execution Options\avp.com"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\I mage File Execution Options\avp.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe"

在注册表中设置了以下信息:
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe" "Debugger" "ntsd -d"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe" "Debugger" "ntsd -d"

病毒会连接作者指定的网址:
域名:"****" 端口:80 (TCP)

在系统中创建了以下进程:
"SkypeClient.exe"

病毒会连接网络进行数据与指令的传播

免责声明:本网转载内容均注明出处,转载是出于传递更多信息之目的,并不代表我们立场。

  • 上一篇病毒:

  • 下一篇病毒:
  • 赞 助 商
     
    频 道 最 新
    · Hacker.com.cn.exe jiejie下载器4096 Win32
    · HBKernel32.sys HBYY.dll SelfDel.bat  HB网
    · Worm.Brontok.a.98816
    · Win32.Troj.VB.286792
    · 大话西游盗号木马73728 Win32.PSWTroj.Maga
    · %a.exe smssb.exe奸商修改器 Win32.troj.pr
    · 破坏TesSafe.sys  地下城盗贼102400 Win32.
    · 6AECFF9B.cfg 6AECFF9B.dll aecff9.sys 大话
    · dp1.fne Exmlrpc.fne Prstgressep11.exe 黑
    · 6AECFF9B.cfg 6AECFF9B.dll aecff9.sys 大话
    · Prstgressep11.exe 黑客远程控制器765465 W
    · 今日预警“灰鸽子变种FB(Backdoor.Win32.G
    · ED.exe Pierce.exe变形虫下载器143360 Win3
     
    相关文章
    sgdewg.dll,sgdewg.dll.LoG,QQ三国盗号者11
    ctfmon.exe,dat3.reg,Logo1_.exe,rundl132.
    oohxebyt.dll,qba0999.tmp泽尼特变种119296