Very good blocked network Trojan virus ten Trick 1th/2 page _ Virus killing

Source: Internet
Author: User
Trojan Horse is a remote control of the virus program, the program has a strong concealment and harm, it can be unnoticed in the state of control you or monitor you. Some people say, since the Trojan is so powerful, then I can not be far away from it!

However, this trojan is really "naughty", it can be no matter whether you welcome, as long as it is happy, it will try to get into your "home"! Ah, that also got, hurry to see their own computer there is no Trojan, perhaps in the "Home" in trouble! Then how do I know where the Trojan is? I believe that the rookie who are not familiar with the Trojan must want to know such a problem. The following is the trick of the Trojan lurking, after watching do not forget to take the trick to deal with these losses yo!

1, integrated into the program

In fact Trojan is also a server-client program, in order not to allow users to easily delete it, it is often integrated into the program, once the user activates the Trojan, then the Trojan file and an application bundled together, and then uploaded to the server to cover the original file, so even if the trojan was deleted, As long as the application bundled with the Trojan, the Trojan will be installed up. Bound to an application, such as binding to a system file, every time Windows startup starts a Trojan.

2, hidden in the configuration file

Trojan is too cunning, know the rookie is usually using the graphical interface of the operating system, for those who have not very important configuration files are mostly indifferent, which just give a trojan to provide a hiding place. And the use of the special role of configuration files, Trojans can easily in everyone's computer run, attack, and thus peeping or watching everyone. However, now this way is not very covert, easy to find, so in Autoexec.bat and Config.sys loaded Trojan horse program is not seen, but also can not be taken lightly oh.

3, lurking in the Win.ini

Trojan Horse to achieve control or monitor the purpose of the computer, must run, however, no one will be silly to their own computer to run the damn Trojan. Of course, the Trojan is also early psychological preparation, know that human is a high IQ of animals, will not help it to work, so it must find a safe and can be in the system start automatically run the place, so lurking in the Win.ini is a Trojan feel more comfortable place. You may wish to open Win.ini to see, in its [Windows] field has the start command "load=" and "run=", in general, "=" after the blank, if there is followed by the program, for example: run=c:\windows\ File.exeload=c:\windows\file.exe at this time you must be careful, this file.exe is probably a Trojan oh.

4, camouflage in the ordinary document

This method appears late, but it is now very popular, for unskilled windows operators, it is easy to be fooled. The method is to disguise the executable file as a picture or text--in the program, change the icon to Windows Default Picture icon, and then change the file name to *.jpg.exe, because the Win98 default setting is "Do not show known file suffix name", the file will appear as *.jpg, People who don't pay attention to this icon is a Trojan horse (if you embed a picture in the program is more perfect).

5, built into the registry

The above method makes the Trojan really comfortable for a while, no one can find it, and can automatically run, it is fast! However, the long time, the human quickly took it out of the hand, and it was severely punished! But it is also unwilling, summed up the failure of the lesson, that the above hiding place is easy to find, Now you have to hide in a place that is not easy to find, so it thought of the registration form! Indeed, because of the complexity of the registry, Trojans often like to hide in here merry, quickly check, what program under its, open eyes carefully, do not let go of the Trojan: HKEY_LOCAL_MACHINE\Software \microsoft\windows\currentversion all the key values that begin with "run"; HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion all the key values that begin with "run"; Hkey-users\. Default\software\microsoft\windows\currentversion all the key values that begin with "run".
Current 1/2 page 12 Next read the full text

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.