登入
歡迎您,
Language:
繁體中文
English
Deutsch
Français
Español
Italiano
Português
Русский
日本語
简体中文
繁體中文
欲瞭解有關我們公司和產品的更多資訊,
請訪問我們的全球網站
。
家庭及個人防護
企業資訊安全
技術支援
聯絡我們
Search
需要修復電腦?
聘請專家
摘要
病毒說明
統計資料
Virus:
W32/Polip.A
Type:
File infector
In the wild:
Yes
Reported Infections:
High
Distribution Potential:
Low
Damage Potential:
Low
Static file:
No
General
Methods of propagation:
• Infects files
• Peer to Peer
Aliases:
• Symantec: W32.Polip
• Mcafee: W32/Polip
• Kaspersky: P2P-Worm.Win32.Polip.a
• TrendMicro: PE_POLIP.A
• Sophos: W32/Polipos-A
• VirusBuster: Win32.Polipos.A
• Eset: Win32/Polip
• Bitdefender: Win32.Polip.A
Platforms / OS:
• Windows 98
• Windows 98 SE
• Windows NT
• Windows 2000
• Windows XP
• Windows 2003
Files
It deletes the following files:
• drwebase.vdb
• avg.avi
• vs.vsn
• anti-vir.dat
• avp.crc
• chklist.ms
• ivb.ntz
• ivp.ntz
• chklist.cps
• smartchk.ms
• smartchk.cps
• aguard.dat
• avgqt.dat
• lguard.vps
File infection
Infector type:
Embedded - The virus inserts its code throughout the file (in one or more places).
Self Modification:
Polymorphic - The entire virus code changes from one infection to another. The virus contains a polymorphic engine.
Ignores files that:
Contain any of the following strings in their name:
• vtf; tb; dbg; f-; nav; pav; mon; rav; nvc; fpr; dss; ibm; inoc; scn;
pack; vsaf; vswp; fsav; adinf; sqstart; mc; watch; kasp; nod; setup;
temp; norton; mcafee; anti; tmp; secure; upx; forti; scan; "zone
labs"; alarm; symantec; retina; eeye; virus; firewall; spider;
backdoor; drweb; viri; debug; panda; shield; kaspersky; doctor; "trend
micro"; sonique; cillin; barracuda; sygate; rescue; pebundle; ida;
spf; assemble; pklite; aspack; disasm; gladiator; ort; expl; process;
eliashim; tds3; starforce; sec; avx; root; burn; aladdin; esafe; olly;
grisoft; avg; armor; numega; mirc; softice; norman; neolite; tiny;
ositis; proxy; webroot; hack; spy; iss; pkware; blackice; lavasoft;
aware; pecompact; clean; hunter; common; kerio; route; trojan;
spyware; heal; alwil; qualys; tenable; avast; a2; etrust; spy;
steganos; security; principal; agnitum; outpost; avp; personal;
softwin; defender; intermute; guard; inoculate; sophos; frisk; alwil;
protect; eset; nod32; f-prot; avwin; ahead; nero; blindwrite; clonecd;
elaborate; slysoft; hijack; roxio; imapi; newtech; infosystems;
adaptec; "swift sound"; copystar; astonsoft; "gear software"; sateira;
dfrgntfs; {; }; $
Contain any of the following strings in their path:
• {
• }
• $
• \\?\
• \\.\
•
The following files are infected:
By file type:
• exe
• scr
Files in any of the following directories:
• C:\program files
• C:\windows
• C:\win98
• C:\win98se
• C:\winxp
• C:\win2000
• C:\winnt
• C:\winme
Injection
– It injects itself into a process.
Not into processes containing containing the following string:
• ggf
Rootkit Technology
Method used:
• Hook the Import Address Table (IAT)
Hooks the following API functions:
• CreateFileW
• CreateFileA
• SearchPathW
• SearchPathA
• CreateProcessW
• CreateProcessA
• LoadLibraryExW
• LoadLibraryExA
• ExitProcess
說明撰寫者 Razvan Olteanu 開啟 2010年2月9日星期二
說明更新者 Andrei Ivanes 開啟 2010年2月10日星期三
返回
.
.
.
.
我的帳戶
https
://
為了你的安全,此視窗已加密。
登入
忘記密碼
重設密碼
我的個人檔案
產品
付款歷程記錄
通知
密碼重設
聯絡我們
登出