ログイン
ようこそ、
さん
Language:
日本語
English
Deutsch
Français
Español
Italiano
Português
Русский
日本語
简体中文
繁體中文
弊社と弊社製品に関する詳細は、
グローバルサイト
でご覧ください。
個人向け
ビジネス(企業・法人向け)
サポート
お問い合わせ
Search
PCの修理が必要ですか?
専門家に頼む
まとめ
すべての説明
統計
Virus:
W32/Polip.A
Type:
File infector
In the wild:
Yes
Reported Infections:
High
Distribution Potential:
Low
Damage Potential:
Low
Static file:
No
General
Methods of propagation:
• Infects files
• Peer to Peer
Aliases:
• Symantec: W32.Polip
• Mcafee: W32/Polip
• Kaspersky: P2P-Worm.Win32.Polip.a
• TrendMicro: PE_POLIP.A
• Sophos: W32/Polipos-A
• VirusBuster: Win32.Polipos.A
• Eset: Win32/Polip
• Bitdefender: Win32.Polip.A
Platforms / OS:
• Windows 98
• Windows 98 SE
• Windows NT
• Windows 2000
• Windows XP
• Windows 2003
Files
It deletes the following files:
• drwebase.vdb
• avg.avi
• vs.vsn
• anti-vir.dat
• avp.crc
• chklist.ms
• ivb.ntz
• ivp.ntz
• chklist.cps
• smartchk.ms
• smartchk.cps
• aguard.dat
• avgqt.dat
• lguard.vps
File infection
Infector type:
Embedded - The virus inserts its code throughout the file (in one or more places).
Self Modification:
Polymorphic - The entire virus code changes from one infection to another. The virus contains a polymorphic engine.
Ignores files that:
Contain any of the following strings in their name:
• vtf; tb; dbg; f-; nav; pav; mon; rav; nvc; fpr; dss; ibm; inoc; scn;
pack; vsaf; vswp; fsav; adinf; sqstart; mc; watch; kasp; nod; setup;
temp; norton; mcafee; anti; tmp; secure; upx; forti; scan; "zone
labs"; alarm; symantec; retina; eeye; virus; firewall; spider;
backdoor; drweb; viri; debug; panda; shield; kaspersky; doctor; "trend
micro"; sonique; cillin; barracuda; sygate; rescue; pebundle; ida;
spf; assemble; pklite; aspack; disasm; gladiator; ort; expl; process;
eliashim; tds3; starforce; sec; avx; root; burn; aladdin; esafe; olly;
grisoft; avg; armor; numega; mirc; softice; norman; neolite; tiny;
ositis; proxy; webroot; hack; spy; iss; pkware; blackice; lavasoft;
aware; pecompact; clean; hunter; common; kerio; route; trojan;
spyware; heal; alwil; qualys; tenable; avast; a2; etrust; spy;
steganos; security; principal; agnitum; outpost; avp; personal;
softwin; defender; intermute; guard; inoculate; sophos; frisk; alwil;
protect; eset; nod32; f-prot; avwin; ahead; nero; blindwrite; clonecd;
elaborate; slysoft; hijack; roxio; imapi; newtech; infosystems;
adaptec; "swift sound"; copystar; astonsoft; "gear software"; sateira;
dfrgntfs; {; }; $
Contain any of the following strings in their path:
• {
• }
• $
• \\?\
• \\.\
•
The following files are infected:
By file type:
• exe
• scr
Files in any of the following directories:
• C:\program files
• C:\windows
• C:\win98
• C:\win98se
• C:\winxp
• C:\win2000
• C:\winnt
• C:\winme
Injection
– It injects itself into a process.
Not into processes containing containing the following string:
• ggf
Rootkit Technology
Method used:
• Hook the Import Address Table (IAT)
Hooks the following API functions:
• CreateFileW
• CreateFileA
• SearchPathW
• SearchPathA
• CreateProcessW
• CreateProcessA
• LoadLibraryExW
• LoadLibraryExA
• ExitProcess
説明の挿入者 Razvan Olteanu の 2010年2月9日火曜日
説明の更新者 Andrei Ivanes の 2010年2月10日水曜日
戻る
.
.
.
.
マイアカウント
https
://
このウィンドウは暗号化されています。
ログイン
パスワードを忘れた場合
パスワードのリセット
マイプロフィール
製品
支払い履歴
通知
パスワードのリセット
お問い合わせ
ログアウト