Trojan/PSW.QQKdw.45
Trojan/PSW.QQKdw.45
病毒类型:木马
危害等级:*
影响平台:Win9X/2000/XP/NT/Me/2003
Trojan/PSW.QQKdw.45是盗取qq密码的木马程序。
传播过程及特征:
1.病毒运行后,将创建下列文件:
%System%winsocks.dll, 36864字节
%WinDir%system.dat, 2719776字节
%WinDir%win.ini, 8294字节
%WinDir%desktopwdwej.exe, 16384字节
%WinDir%desktop
.exe, 12288字节
%WinDir%desktopl.exe, 77824字节
%WinDir%ytsgfvz.exe, 434176字节
%WinDir%intren0t.exe, 36864字节
2.修改WIN.INI文件:
在WIN.INI中添加 run=c:windowskir.exe
3.修改注册表:
在注册表中添加下列启动项:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"ytsgfvz" = %WinDir%ytsgfvz.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"golci" = %program files%golci.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"bbh" = %WinDir%bh.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"INDEX" = %WinDir%desktopindex.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Intren0t" = %WinDir%intren0t.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices]
"ytsgfvz" = %WinDir%ytsgfvz.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices]
"golci" = %program files%golci.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices]
"bbh" = %WinDir%bh.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices]
"INDEX" = %WinDir%desktopindex.exe
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices]
"Intren0t" = %WinDir%intren0t.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"ytsgfvz" = %WinDir%ytsgfvz.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"golci" = %program files%golci.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"bbh" = %WinDir%bh.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"INDEX" = %WinDir%desktopindex.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunservices]
"ytsgfvz" = %WinDir%ytsgfvz.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunservices]
"golci" = %program files%golci.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunservices]
"bbh" = %WinDir%bh.exe
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunservices]
"INDEX" = %WinDir%desktopindex.exe
这样,在Windows启动时,病毒就可以自动执行。