关于此病毒的一些资料: “ Trojan.DownLoader.24290”,通过可移动存储设备进行传播,传染力极强。 “ Trojan.DownLoader.24290”威胁级别:高 病毒特征: A.该病毒会在可移动磁盘中创建Autorun.inf文件. B.该病毒会尝试连接一些网络站点来下载其他的病毒或木马. 发作症状: 1.当该病毒被执行后,它会复制其本身到以下路径: - %system%\serveter.exe (20,480 Bytes) - %system%\Deleteme.bat – batch file(delete itself) * Windows system folder(%system%) - Windows 9X/ME/XP: C:\Windows\system32 - Windows NT/2000: C:\Winnt\system32 2.如果可移动磁盘插入被感染系统,该病毒会创建以下文件到磁盘根目录下: - Autorun.inf - serveter.exe: Execution file of Trojan.DownLoader.24290 3.该病毒会尝试连接以下站点,并下载另外的病毒. - address: xz.888<…>.info(74.<…>.11) - port: TCP 80, 137 4.下载下来的病毒会盗取被感染系统信息. http://xz.888<...>.info/1.exe - detected as Trojan.PWS.Wsgame http://xz.888<...>.info/2.exe - detected as Trojan.Havedo http://xz.888<...>.info/3.exe - detected as Trojan.PWS.Gamania http://xz.888<...>.info/4.exe - detected as Trojan.PWS.Wsgame http://xz.888<...>.info/5.exe - detected as Trojan.Havedo http://xz.888<...>.info/6.exe - detected as Trojan.PWS.Gamania http://xz.888<...>.info/7.exe - detected as Trojan.PWS.Gamania http://xz.888<...>.info/8.exe - detected as Trojan.Havedo http://xz.888<...>.info/9.exe - detected as Trojan.Havedo http://xz.888<...>.info/10.exe - detected as Trojan.Havedo 5.该病毒会增加以下注册表项,以便系统启动时自动执行. -[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ Removable Storage] “Description = Windows InstallService” “DisplayName = Windows InstallService” “ImagePath = %system%\serveter.exe” “Start = 2”
受感染的系统包括: -Windows 9X/ME: C:\Windows\SYSTEM -Windows NT/2000 : C:\Winnt\System32 -Windows XP : C:\Windows\System32 |