Qqshow virus uses special technologies to steal QQ accounts and run them automatically

Source: Internet
Author: User

July October 27: QQ Show virus uses special technologies to steal QQ accounts and run them automatically

Jiang min reminds you today that Virus. Autorun. fy "USB flash drive parasite" variants fy and Trojan/PSW. QQShou. vj "qq" variants vj are worth noting.

Virus name: Virus. Autorun. fy

Chinese name: "USB flash drive parasite" variant fy

Virus length: 26668 bytes

Virus Type: Worm

Hazard level:★

Affected Platforms: Win 9X/ME/NT/2000/XP/2003

Virus. Autorun. fy The "U disk parasite" variant fy is one of the newest members of the "U disk parasite" worm family, which is written in Delphi 6.0-7.0 and shelled. After running fy, the "USB flash drive parasite" variant copies itself to the specified directory and sets the file attribute to read-only and hidden. By adding a scheduled task to the batch processing and adding a startup entry to the registry, the worm runs automatically upon startup. Create a disk image hijacking file (autorun. inf) and Virus File, set the file attribute to read-only and hidden, so that the user double-click the drive letter will activate the "U disk parasite" variant fy automatically run. The process image hijacking technology is used to modify the registry so that some security software cannot be started in infected computers. Modifying the Registry invalidates the function of displaying hidden files in [Folder Options. Monitor the Windows names of programs running on infected computers in the background. Once security-related programs are found, they are immediately closed. Connect to the specified site and automatically download and execute malicious programs on the infected computer. In addition, the fy variant of the "U disk parasite" not only can be transmitted through the U disk, mobile hard disk, etc., but also can be upgraded on its own.

Virus name: Trojan/PSW. QQShou. vj

Chinese name: "qqxiu" variant vj

Virus length: 33399 bytes

Virus Type: Trojan

Hazard level:★★

Affected Platforms: Win 9X/ME/NT/2000/XP/2003

Trojan/PSW. QQShou. vj "qq" variant vj is one of the newest members of the "qq" Trojan family. It is written in Delphi 6.0-7.0 and shelled. After the "qqxiu" variant vj runs, it copies itself to the specified directory and releases the trojan DLL component file under the directory. The file attributes are set to hidden and archived. Modify the Registry to enable automatic startup of Trojans. Inject the trojan DLL component file into the process with all user-level permissions of the infected computer system and load and run it to hide itself and prevent it from being scanned and killed. Special technologies are used to prevent trojan DLL component files from being stored in the hard disk during running. Connect to the specified site, obtain the IP address and city of the infected computer, use the HOOK Technology to steal information such as the user's QQ account and QQ password, and send it to the specified email address of the hacker in the background. If an e disk exists on the infected computer, the "qqxiu" vj will also generate the disk image hijacking file "AutoRun. inf and Virus File AUTORUN. "EXE". As a result, the user can double-click the "qq" vj on the e-drive to automatically run.

For the above viruses, Jiangmin anti-virus Center recommends that the majority of computer users:

1. Please immediately upgrade Jiangmin anti-virus software to enable a new generation of intelligent classification high-speed Anti-Virus engine and various monitoring functions to prevent the current prevalence of viruses, Trojans, harmful programs or code from attacking users' computers.

2. Users of jiangminkv network version should upgrade the control center in a timely manner, and suggest relevant management personnel to scan and kill viruses throughout the network as appropriate to ensure the security of enterprise information.

3. Jiangmin anti-virus software uses the Virtual Machine shelling technology to perform virtual shelling for mainstream shell viruses, effectively eliminating the "shell virus ".

4. "Jiangmin mi Bao" can effectively protect the passwords of accounts such as online banking, payment platforms, online securities transactions, and online games, and fully protect users' private information.

5. Jiangmin anti-virus software uses window protection and process protection technologies to prevent viruses from shutting down the anti-virus software process, ensure the security of anti-virus software, and better protect the security of users' computers.

6. Jiangmin anti-virus software "Mobile storage access anti-virus" can prevent viruses from using mobile devices (such as USB flash drives and mobile hard drives) to intrude into users' computers and completely protect computer system security.

7. fully enable the BOOTSCAN function to eliminate viruses that are self-protected and anti-virus software before the system starts.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.