您现在的位置是:首页 > 电脑技术查询 > 电脑知识

win32.hack.huigezi.hx.333312

编辑:chaxungu时间:2022-09-28 09:38:07分类:电脑知识

目录·病毒名称
·威胁级别
·病毒类型
·病毒长度
·影响系统
·病毒行为


病毒名称win32.hack.huigezi.hx.333312
威胁级别★★☆☆☆
病毒类型黑客程序
病毒长度333312
影响系统win9xwin2000winxp

病毒行为该病毒属后门类,是灰鸽子的变种,病毒运行后衍生病毒文件到系统目录下,修改注册表,
创建服务,并以服务的方式达到随机启动的目的;病毒运行后开启后门,让黑客可远程控制
用户机器。
1.生成文件
c:\windows\lsuss.exe
2.生成服务
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
type=dword:00000110
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
start=dword:00000002
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
errorcontrol=dword:00000000
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
imagepath=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,6c,73,75,73,73,2e,65,78,65,00,
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
displayname="necm"
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
objectname="localsystem"
hkey_local_machine\system\currentcontrolset\services\networkconnectionsmanage
description="管理“网络和拨号连接”文件夹中对象,在其中您可以查看局域网和远程连接。"
3.创建一个隐藏的lsuss.exe进程.
4.病毒运行后会在%windir%下创建一个delete.bat文件来删除源文件.
5.病毒运行后开启后门,让黑客可远程控制用户机器.