"Gray pigeon variant 373760" (Win32.Hack. Huigezi.373760) is a gray pigeon variant, which belongs to the latter category. After the virus runs, the virus file is exported to the system directory and the Registry is modified,
Create a service and start it at random. After the virus runs, you can remotely control your machine.
"QQ hacker" (Win32.PSWTroj. QQPass.98400) is a QQ hacker. After the virus runs, the virus file is derived to the system directory. the startup entry is added to the Registry.
I. "grey pigeon variant 373760" (Win32.Hack. Huigezi.373760) Threat Level:★
1. After the virus runs, an iexplore.exepath will be created to route the virus file to the iexplore.exe process address.
2. The virus will generate an UNINSTL. BAT file for self-deletion.
3. After the virus runs, you can remotely control the user's machine.
Ii. "QQ hacker" (Win32.PSWTroj. QQPass.98400) Threat Level:★
1. After the virus runs, the SYSTEMYH. bak file will be injected into the process.
2. After the virus runs, the user's QQ account will be stolen by reading the memory.
3. After the virus runs, a batch file named "source file name" and "_ deleteme. bat" will be generated for self-deletion.
Suggestions from Jinshan anti-virus engineers
1. It is best to install professional anti-virus software for comprehensive monitoring. We recommend that you install anti-virus software to prevent the increasing number of viruses. After installing anti-virus software, you should upgrade the software frequently, enable some main monitoring frequently (such as email monitoring), and monitor the memory, report problems to ensure computer security.
2. users who play online games and use QQ chat will increase, so all types of Trojan horses will increase. We recommend that you develop good network usage habits and Upgrade anti-virus software in time, enable Firewall, real-time monitoring, and other functions to cut off the virus transmission path and leave the virus alone.