|
Trojan.Tooso.3 Tooso.3 木馬程式會刪除電腦的檔案和移除登錄檔 Tooso.3 木馬程式可能會透過郵件的方式散播,此木馬程式會執行"小畫家應用程式",刪除電腦的檔案和移除登錄檔,而且會終止安全性相關的程序和停止系統服務。 基本介紹
風險評估
Trojan.Tooso.3 行為描述: 註:在Win95/98/me %System% 預設值為 C:\windows\System
在WinNT/2000/XP/2003 %System% 系統預設值為 C:\WinNT\System32
AVExch32Service AVPCC AVUPDService Ahnlab task Scheduler AlertManger ........... AUPD1ATE.EXE AUPDATE.EXE Av1synmgr.exe Avc1onsol.exe Avconsol.exe .............. SharedAccess wscsvc ATUPDATER.EXE AUPDATE.EXE AUTODOWN.EXE AUTOTRACE.EXE AUTOUPDATE.EXE ............. [http://]www.21ebuild.com/[REMOVED]/osa4.gif [http://]www.51.net/[REMOVED]/osa4.gif [http://]www.acsohio.com/[REMOVED]/osa4.gif [http://]www.agria.hu/[REMOVED]/osa4.gif [http://]www.andi.com.vn/[REMOVED]/osa4.gif ................. winshost.exe wiwshost.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
"winshost.exe" = "%System%\winshost.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
"winshost.exe" = "%System%\winshost.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Symantec NetDriver Monitor" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"ccApp" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"NAV CfgWiz" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"SSC_UserPrompt" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"McAfee Guardian" ........... HKEY_LOCAL_MACHINE\SOFTWARE\Symantec HKEY_LOCAL_MACHINE\SOFTWARE\McAfee HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab HKEY_LOCAL_MACHINE\SOFTWARE\Agnitum HKEY_LOCAL_MACHINE\SOFTWARE\Panda Software HKEY_LOCAL_MACHINE\SOFTWARE\Zone Labs |