Win32.Troj.Lmir.vj

病毒行為:
該病毒是一個《傳奇》盜號木馬。它會將盜取的帳號密碼傳送給盜號者。建議升級病毒庫查殺給病毒,以免中毒受害。
1、生成的檔案
%SystemRoot%\215366.DLL
%SystemRoot%\215366M.BMP
2、添加啟動項目
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
"AppInit_DLLs" = "215366M.BMP"
3、註冊標識
HKLM\System\CurrentControlSet\Control\Session Manager
"PendingFileRenameOperations" = "\??\%SystemRoot%\system32\cd212312dqs"
4、會結束以下程式
iceword.exe
fwmain.exe
XGuard.exe
tcpview.exe
WSockExpert.exe
rfwsrv.exe
tpfw.exe
pfw.exe
SockMon5.exe
ActiveNetworkMonitor.exe
NetAnalyzer.exe
PeepNet.exe
CaptureNet.exe
PacScope.exe
ent.exe
NetSnifferV3.exe
gcenter.exe
eye.exe
mtna.exe
wit.exe
NetConnectManager.exe
PortExplorer.exe
netcheck.exe
Ethereal.exe
NetworkView.exe
cports.exe
NetPryer.exe
ehsniffer.exe
smbfilesniffer.exe
iris.exe
sniffer.exe
kvfw.exe
cutesniffer.exe
sns.exe
5、病毒運行完後會自刪除。

相關詞條

熱門詞條

聯絡我們