瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » TO:TIEMAO (sysWord.tam)
艾玛 - 2005-11-4 15:16:00
Troj/VB-IW is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
When first run Troj/VB-IW copies itself to:
<System>\word.exe
<Windows>\system\regedit.exe
The following registry entries are created to run Troj/VB-IW on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
KV2005
<System>\word.EXE
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
KV2005
<System>\word.EXE
The Trojan creates a copy of MSWINSCK.OCX with the following filename:
<System>\~sysWord.tam
This file may be deleted.
天天网 - 2005-11-4 16:02:00
收到
永远的小柴犬 - 2006-6-14 11:04:00
搂住  这是啥啊?

我的中啦


我哭了
cc1111 - 2007-1-7 22:18:00
到底怎么杀呀?
1
查看完整版本: TO:TIEMAO (sysWord.tam)