EndurerOriginal
2006-03-181Version
Just now to help a friend get printer, hand to http://endurer.ys168.com download hijackthis scan, in addition to the discovery of Yahoo Assistant, a search tool bar, Sina point through, Sina download assistant, 3721 Chinese mail, Dudu and other annoying stuff, another item:
O4-HKLM/../run: [Office] C:/Windows/system/order.exe
After finding the file, I found that not only the icons used in the file are the same as those in word, but the descriptions in the file attributes are also similar to those in word. Not a good stuff.
Download "Rising Antivirus assistant" to http://endurer.ys168.com, using rising online free scan, found three exposure files:
File Name virus name
C:/Windows/system/winlog0n. EXE> veunpackfile Trojan. Clicker. audix. B
C:/Windows/system/order.exe Trojan. dockiller. B
C:/Windows/temp/unpacked. EXE> veunpackfile Trojan. Clicker. audix. B
We used the "Rising Antivirus assistant" to solve the problem.
Empty the temporary ie folder.
Let's take a look at the information aboutTrojan. dockiller. BInformation:
Http://it.rising.com.cn/antivirus/virusdataasp/viruslist.asp? Id = 71673
Virus Classification |
PE virus in Windows |
Virus name |
Trojan. dockiller. B |
Other names |
|
Virus Length |
|
Dependent System |
|
Communication channels |
|
Behavior Type |
Trojan programs in Windows |
Sensory Dyeing |
|
Virus attack |
|
Star version No. |
16.53.30 |
The trojan virus written in VB is compiled using pcode. It looks like a Word document. 1. copy itself to % WINDIR %/system/regedit.exe and % WINDIR %/system32/order.exe. Ii. Add auto-start items HKLM/software/Microsoft/Windows/CurrentVersion/policies/Explorer/run Office: % WINDIR %/system32/order.exe 3. Search for "Windows Task Manager" and stop yourself immediately after detection. Prevent user discovery. 4. Search for "User Account" and try to get the user password. Every time the 5th percentile is run, it will overwrite a .doc file under the current directory, and the covered .doc file cannot be recovered. 6. When you double-click a virus file, the message "cannot open the Word file of a later version" is displayed, which creates an illusion and puzzles the user. |
|