瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:埃斯垂变种C(Worm.Xgtray.c)

1   1  /  1  页   跳转

求助:埃斯垂变种C(Worm.Xgtray.c)

求助:埃斯垂变种C(Worm.Xgtray.c)

“埃斯垂变种C(Worm.Xgtray.c)”病毒。该病毒是由VB编写的蠕虫病毒,通过邮件传播。中招后,会在磁盘上生成nethood.htm,windows.exe,ghost.bat三个文件,并且每打开一个文件夹就会在该文件夹下生成一个同名文件夹(其实为可执行的.exe文件)。病毒运行后将生成一个名为“folder.htt”的文件,当打开包含此文件的文件夹时就会执行病毒。
那位能够帮我一下。
下面上传的是那三个文件。

附件附件:

下载次数:6
文件类型:application/octet-stream
文件大小:
上传时间:2005-8-11 8:20:42
描述:

最后编辑2005-08-12 08:16:09
分享到:
gototop
 

安全模式下杀毒看看
gototop
 

诺顿发现并杀掉,病毒名是W32.Traxg@mm
gototop
 

你所发的nethood.htm,感染了非W32.Traxg@mm的病毒.病毒名是JS.Exception.Exploit
我们定义此病毒为Adware
下面是此病毒的分析报告,请您详尽阅读

JS.Exception.Exploit is a detection for an exploit that allows Java applets to perform various actions on your system if you are using an older or unpatched version of Microsoft Internet Explorer.

In many cases, JS.Exception.Exploit may perform simple actions such as changing your Internet Explorer home page. (This is one of the most common uses of this exploit.) It has been reported, but not confirmed, that some adware programs use JS.Exception.Exploit to do this. As a result, your Symantec antivirus program may detect JS.Exception.Exploit when the adware program displays a pop-up ad that uses the exploit.

IMPORTANT:
If your Symantec antivirus program alerts you to JS.Exception.Exploit, this means that it has stopped the exploit and prevented it from running. It does not mean that your computer is "infected" with this threat. Rather, it means that the antivirus program has stopped it. Because the exploit is usually not on your computer, in most cases you will not be able to "delete" it, since there is nothing to delete.

To be sure that your computer is free of currently-known threats, we suggest that you run LiveUpdate and then run a full system scan.

If you continue to receive alerts when pop-up ads are displayed, you need to determine what adware you have installed on your computer, then disable or remove it. You may need to contact your computer vendor for assistance in identifying and disabling advertising software. You can also obtain and run programs that are designed to detect and remove adware.


 
 
Type:  Trojan Horse
 
 
 
 
Systems Affected:  Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected:  Windows 3.x, Macintosh, OS/2, UNIX, Linux
CVE References:  CVE-2000-1061




gototop
 

多谢各位。我试试看。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT