知道问题在哪~
不过...还是不懂除虫..........
Worm@W32.Alcra.2 行为描述:
注:在Win95/98/me %System% 预设值为 C:\windows\System
在WinNT/2000/XP/2003 %System% 系统预设值为 C:\WinNT\System32
骇虫会使下列的档案失效,并且将这些档案属性设定成隐藏:
%System%\cmd.com
%System%\netstat.com
%System%\ping.com
%System%\regedit.com
%System%\taskkill.com
%System%\tasklist.com
%System%\tracert.com
%System%\taskmgr.exe
骇虫会显示一个讯息视窗:
Title: Setup
Body: Welcome to the Setup Wizard
It is recommended that you close all other applications before continuing.
点选"Next"按钮将继续下一步或者点选"cancel"按钮取消安装。
当使用者点选"Next"按钮,则显示一个错误讯息:
Title: Setup
Body: Version has expired please download software update.
骇虫将试图从下列网站下载档案并且执行:
[http://]members.chello.nl/[REMOVED]/a.exe
[http://]members.chello.nl/[REMOVED]/a.exe
[http://]members.chello.nl/[REMOVED]/a.exe
[http://]members.chello.nl/[REMOVED]/b.exe
[http://]members.chello.nl/[REMOVED]/b.exe
[http://]members.chello.be/[REMOVED]/a.exe
[http://]members.chello.be/[REMOVED]/b.exe
骇虫会连结下列网页:
[http://]katz.ws/[REMOVED]
[http://]www.phazeddl.com/[REMOVED]
[http://]ddldirect.com/[REMOVED]/ddl.php
[http://]gotddl.com/[REMOVED]
[http://]fullddl.net/[REMOVED]
................
骇虫会在下列P2P软体的共享目录中产生病毒档案:
Ares\My Shared Folder
eMule\Incoming
Kazaa\My Shared Folder
My Shared Folder
gnucleus\downloads
..........
病毒执行后,在%System%产生
bszip.dll
病毒执行后,在%ProgramFiles%\winupdates\ 目录产生
winupdates.exe
a.tmp
a.zip
修改登录档,如此开机即会启动骇虫。
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
"winupdates" = "%ProgramFiles%\winupdates\winupdates.exe /auto"