Watch out for all types of Trojan horses during the virus broadcast on April 9, October 02

Source: Internet
Author: User

Jiang Min's October 2 virus broadcast: Be careful when the Warcraft Trojan steals confidential information of the online game World of Warcraft

Jiang min reminds you today that TrojanDownloader. Small. udy and Tro variants in today's viruses

Jan/PSW. Moshou. Obtain the "Warcraft" variant of the bucket, which is worth noting.

Virus name: TrojanDownloader. Small. udy

Chinese name: udy

Virus length: 37376 bytes

Virus Type: Trojan download

Hazard level:★★

Affected Platforms: Win 9X/ME/NT/2000/XP/2003

TrojanDownloader. Small. udy the udy variant udy is one of the latest members of the Trojan downloader family, which is written in Delphi 6.0-7.0. After the udy variant runs, it copies itself to the specified directory on the system disk. Register as a system service to enable automatic startup of the Trojan installer. The "tiny dot" variant udy has the USB flash drive and mobile hard drive transmission function. It uses the disk image hijacking technology to create the disk image hijacking file "autorun. inf and virus program files. In the background of the infected computer, call the system process svchost.exe or i0000e. EXE, inject malicious code into it, and call and execute it. When the udy variant is running, there are neither processes nor wireless processes, which are concealed and difficult to find. Secretly connect to the specified site of the hacker in the background, download malicious programs and run them automatically. In addition, the udy variant of "small dot" has the function of avoiding some anti-virus software and firewall monitoring, reducing the security level on infected computers.

Virus name: Trojan/PSW. Moshou. b7-

Chinese name: "World of Warcraft" variant of the Buch

Virus length: 25173 bytes

Virus Type: Trojan

Hazard level:★

Affected Platforms: Win 9X/ME/NT/2000/XP/2003

Trojan/PSW. Moshou. Obtain the "Warcraft" variant. As one of the latest members of the "Warcraft" Trojan family, it is written in Delphi 6.0-7.0 and shelled. After the "Warcraft" variant has run, it copies itself to the specified directory of the infected computer. Modify the Registry to enable automatic startup of Trojans. Self-injection is carried to user-level permission processes, such as the infected computer's zookeeper er.exekeeper notepad.exe, to hide itself and prevent being scanned and killed. Secretly monitors the title of the window opened by the user in the background, and steals the game account, password, role level, equipment information, amount of money, and other information of the online game World of Warcraft players, the stolen player information is sent to the remote server specified by the hacker in the background, causing loss of the player's game account, equipment, items, and money, causing great losses to the game players.

According to rising global anti-virus monitoring network, a virus is worth noting today: "automatically run variant IPG (Worm. Win32.Autorun. ipg. The virus is spread through a USB flash drive and will lock the IE browser homepage of the user's computer to "hao123". At the same time, the virus will automatically download viruses, Trojans, and Backdoor programs from the website specified by the hacker, give your computer security a threat.

Popular Viruses today:

"Automatic Running of variant IPG (Worm. Win32.Autorun. ipg)" virus: degree of vigilance★★★Trojans are transmitted over the network, depending on the system: WIN9X/NT/2000/XP.

After the virus runs, it will copy itself to the system file directory, with the file name being javascrsss.exe ". Modify the Registry to run automatically as the system starts. The virus locks the IE browser homepage of the user's computer to "HAO123", and modifies the system settings so that the user cannot modify the IE homepage on his own. The virus automatically downloads viruses, Trojans, and other operations from the website specified by the hacker, threatening users' computer security. The virus will also copy itself to a mobile storage device, such as the USB flash drive, with the file name "“niu.exe", trying to spread through these devices. At the same time, the virus also comes with the automatic "Trojan" function, it will automatically find all the webpage format files on the local machine, and add virus code to it. If the computer or website server edited by the website is infected with the virus, the user may be infected with the virus when accessing these websites.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.