病毒介绍:
VBS.Lava病毒是通过Visual Basic语言编写的,其能够删除反病毒程序,感染长度为4505字节。此病毒感染安装有Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me, Microsoft IIS操作系统的计算机,而不会感染安装有Windows 3.x, Macintosh, OS/2, Unix, Linux操作系统的计算机。
1.此病毒能够更改Autoexec.bat批处理文件。
2.此病毒必须通过用户下载并运行后才能够发作,与其它蠕虫病毒的属性是不同的。
3.此病毒一旦被激活并开始运行后,其首先会将自身复制到C:\Windows\Sooolazo.vbs和C:\WinNT\Sooolazo.vbs中,这个路径在病毒体内是固定的,不会因计算机操作系统的不同而发生变化。
4.如果计算机系统中含有下列的文件夹,此病毒将试图删除这些文件夹中的所有文件:
C:\AntiViral Toolkit Pro
C:\Program Files\Command Software\F-PROT95
C:\Program Files\McAfee\VirusScan
C:\Program Files\Norton AntiVirus
C:\Toolkit\FindVirus
C:\Program Files\Panda Software\Panda Antivirus Titanium。
5.接下来,此病毒将本身复制到下列文件中:
C:\Program Files\Morpheus\My Shared Folder\CristinaAguilera.Jpg.vbs
C:\Program Files\Morpheus\My Shared Folder\AVP-Spanish Patch.Zip.VBS
C:\Program Files\Morpheus\My Shared Folder\Norton Antivirus 2002 Crack.Zip.vbs
C:\Program Files\Morpheus\My Shared Folder\SilviaSaintDoubleAnalAction.jpg.vbs
C:\Program Files\Morpheus\My Shared Folder\Panda Titanium Crack.zip.vbs
C:\Program Files\Morpheus\My Shared Folder\LasKetChupXXX.jpg.vbs
C:\Archiv~1\Morpheus\My Shared Folder\CristinaAguilera.Jpg.vbs
C:\Archiv~1\Morpheus\My Shared Folder\AVP-Spanish Patch.Zip.VBS
C:\Archiv~1\Morpheus\My Shared Folder\Norton Antivirus 2002 Crack.Zip.vbs
C:\Archiv~1\Morpheus\My Shared Folder\SilviaSaintDoubleAnalAction.jpg.vbs
C:\Archiv~1\Morpheus\My Shared Folder\Panda Titanium Crack.zip.vbs
C:\Archiv~1\Morpheus\My Shared Folder\LasKetChupXXX.jpg.vbs
C:\Program Files\KaZaA\My Shared Folder\CristinaAguilera.Jpg.vbs
C:\Program Files\KaZaA\My Shared Folder\AVP-Spanish Patch.Zip.VBS
C:\Program Files\KaZaA\My Shared Folder\Norton Antivirus 2002 Crack.Zip.vbs
C:\Program Files\KaZaA\My Shared Folder\SilviaSaintDoubleAnalAction.jpg.vbs
C:\Program Files\KaZaA\My Shared Folder\Panda Titanium Crack.zip.vbs
C:\Program Files\KaZaA\My Shared Folder\LasKetChupXXX.jpg.vbs
C:\Archiv~1\KaZaA\My Shared Folder\CristinaAguilera.Jpg.vbs
C:\Archiv~1\KaZaA\My Shared Folder\AVP-Spanish Patch.Zip.VBS
C:\Archiv~1\KaZaA\My Shared Folder\Norton Antivirus 2002 Crack.Zip.vbs
C:\Archiv~1\KaZaA\My Shared Folder\SilviaSaintDoubleAnalAction.jpg.vbs
C:\Archiv~1\KaZaA\My Shared Folder\Panda Titanium Crack.zip.vbs
C:\Archiv~1\KaZaA\My Shared Folder\LasKetChupXXX.jpg.vbs。
6.此病毒会添加键值:
LARVA C:\Windows\sooolazo.vbs
x C:\WinNT\sooolazo.vbs
到注册表编辑器:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run中,使得机器启动时病毒就会自动运行。
7.此病毒同时也将下列命令加入到Autoexec.bat文件中:
@Start C:\windows\sooolazo.vbs>nul
@Start C:\winnt\sooolazo.vbs>nul
cls。
8.此病毒一旦运行后会显示出标题为"LVG"及文本内容为"Error 421 Kernel32.dll"的信息框。
|
|