VIRUSUL SAPTAMANII
0Noi troieni - in circulatie Saptamana trecuta, un nou troian si-a facut aparitia in lumea virtuala. El se numeste Trojan.Xombe.A si se raspandeste sub forma de e-mail, aparent venit de la
Noi troieni - in circulatie
Saptamana trecuta, un nou troian si-a facut aparitia in lumea virtuala. El se numeste Trojan.Xombe.A si se raspandeste sub forma de e-mail, aparent venit de la Microsoft.
Formatul mesajului este urmatorul:
Subiect: Windows XP Service Pack 1 (Express) - Critical Update.
Corp mesaj:
Window Update has determined that you are running a beta version of Windows XP Service Pack 1 (SP1). To help improve the stability of your computer, Microsoft recommends that you remove the beta version of Windows XP SP1 and re-install Windows XP SP1. If you cannot remove the beta version, you should still reinstall Windows XP SP1.
Windows XP SP1 provides the latest security, reliability, and performance updates to the Windows XP family of operating systems. Windows XP SP1 is designed to ensure Windows XP platform compatibility with newly released software and hardware, and includes updates to resolve issues discovered by customers or by Microsoft's internal testing team....
The maximum download size is approximately 3 MB, however the size of the download and time required may be less for computers that have had updates previously installed. ... Windows XP SP1 includes Internet Explorer 6 SP1. Anti-virus software programs may interfere with the installation of Windows XP SP1. Please disable anti-virus software while installing the service pack. Just run the file winxp_sp1.exe in attach and make sure to restart your PC after installation will be completed.
(c) 2004 Microsoft Corporation. All rights reserved. Terms of Use Privacy Statement
Atasament: WINXP_SP1.EXE
Dupa ce se executa atasamentul, virusul descarca de pe adresa gamemaniacs.org un fisier care este, de fapt, un alt troian downloader.
O data executat, acest al doilea fisier se copiaza in sistem ca c:\windows\system\msvchost.exe si creeaza cheia de registri Software\Microsoft\Windows\
CurrentVersion\Run\ mssvc
Ce se va intampla in continuare? Ce este mai rau... troianul aduna informatii din calculatorul infectat si le trimite catre acel site.
Nota: Virusii din aceasta rubrica pot fi eliminati cu antivirusul BitDefender, produs de compania Softwin.