基本介紹
- 中文名:Win32.Hack.Huigezi.jt
- 處理時間:2006-06-15
- 影響系統:Win 2000/NT,Win XP,Win 2003
- 威脅級別:一星
簡介,病毒行為,
簡介
病毒別名: 處理時間:2006-06-15 威脅級別:★
3
病毒行為
1、生成的檔案
%SystemRoot%\Hackercomcn.exe
%SystemRoot%\uninstal.bat
2、註冊表修改項
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GrayPigeon_Hackerom
"Description" = "灰鴿子服務端程式。遠程監控管理."
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GrayPigeon_Hackercom
"DisplayName" = "GrayPigeon_Hackercomcn"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GrayPigeon_Hackercomcn
"ImagePath" = "C:\WINNT\Hackercomcn.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GrayPigeon_Hackercomcn
"Description" = "灰鴿子服務端程式。遠程監控管理."
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GrayPigeon_Hackercomcn
"DisplayName" = "GrayPigeon_Hackercomcn"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GrayPigeon_Hackercomcn
"ImagePath" = "C:\WINNT\Hackercomcn.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GrayPigeon_Hackercomcn
"Start" = "0x2"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GrayPigeon_Hackercomcn
"Type" = "0x110"
3、該病毒在系統添加的服務
名稱:GrayPigeon_Hacker.comcn