Virus alias:
Processing time:
Threat Level: ★
Chinese name:
Virus type: Trojan Horse
Impact System: WIN9X/WINNT/WIN2K/WINXP/WIN2003
Virus behavior:
Writing tools: VB, Aspack compression
Infection conditions: User accidentally run, or through a floppy disk
Seizure conditions: Users are not careful to run
System Modifications:
The MagicCall.exe that the virus releases to the floppy disk destroys the boot area of the floppy disk:
1. When the virus runs, it is blocked in memory and copies itself to%systemroot%system32internet.exe
2. To the registry
Hkey_current_usersoftwaremicrosoftwindowscurrentversionrunservices
Add the following key value: "Internet.exe" = "%systemroot%system32internet.exe"
3. If there is a floppy disk in the floppy drive, the virus will write to the floppy disk MagicCall.exe file
Seizure phenomenon: After poisoning, the virus will automatically connect http://www.zymf.com,
http://www.csdn.net/soft/openfile.asp?kind=1&id=6398 site.