Virus alias: Trojan/uhenmail [KV]
Processing time:
Threat Level: ★★★
Chinese name: Email gangster
Virus type: Trojan Horse
Impact System: WIN9X/WINME/WINNT/WIN2000/WINXP
Virus behavior:
Authoring tools: Borland Dephi
Infectious conditions:
Conditions of attack: run wrongly or deliberately
System Modifications:
To add a virus to the Registry's Startup entry: Hkey_local_machinesoftwaremicrosoftwindowscurrentversionrun
Seizure phenomenon:
If the machine is connected to the Internet, Uhemail.exe will initiate a denial-of-service attack on the previously specified Web site
If the machine is not connected to the Internet, you can see the warning message popping up like Figure Win32.Troj.UhenMail.ma_3.jpg
Special Note:
The program is an email gangster configuration program, you can fill in the domain name of a website and generate a file named Uhemail.exe
Run Uhemail.exe will initiate a denial-of-service attack on the previously specified Web site
Open and random ports