Welcome to中国防火墙网
Add to Favorites | Chinese
Vermian virus Worm_Funny.A analyses a report (1)
From;    Author:Stand originally








Vermian virus Worm_Funny.A analyses a report (1)

Manufacturer Virus analyses a report Handling center of lash-up of national computer virus MSN virus analysis reportsLucky star "MSN cheater " vermian virus analysis reportsGolden hill "MSN small tail " vermian virus analysis reportsJiang Min "MSN clown " vermian virus analyses a report

Virus of MSN of handling center of lash-up of national computer virus analyses a report

Virus name: Worm_Funny.A
Virus alias: WORM_FUNNER.A [Trend]
I-Worm/MsnFunny [Jiang Min]
Star of Worm.MSN.funny [luck]
Worm.MSNFunny [golden hill]
Virus Chinese name:
MSN is antic [Jiang Min]
MSN cheater [lucky star]
MSN small tail [golden hill]
Virus type: Vermian
Virus size: 56, after 320 Bytes (is compressed) ;
312, 832 Bytes (was not compressed)
Get influence system: Win9x/WinMe/WinNT/Win2000/WinXP

Virus character:

This virus basically has transmission through MSN, virus can send virus document to the contact in the MSN in toxic machine, MSN contact can receive an applied order that the name is FUNNY.EXE, receive and click it to be able to affect a machine, can make a few duplicate files of virus oneself. Virus returns what can revise a system to register a watch, make derive from a body to be able to move automatically when the system is started, return meeting screen a few websites.

The user must understand the main feature of this virus, this kind of problem is encountered in use MSN chatting process, the applied order that must not receive dozen of development to deliver or it is a website, prevent the infection of virus and farther transmission. In the meantime, this virus can appear likely a series of varietal, computer user should have been done be on guard measure.

1, make virus file:

After virus moves, RUNDLL32.EXE file and oneself copy can be made below %System% catalog, it is respectively: EXPLORER.EXE, IEXPLORE.EXE,
USERINIT32.EXE,
Still have a log file that the name is BSFIRST2.LOG.
(among them, %System% is C:W below Windows 95/98/MeIndowsSystem, c:W is below Windows NT/2000InntSystem32, c:W is below Windows XPIndowsSystem32)

Additional, in Windows98 and ME system, virus can enclothe original RUNDLL32.EXE document with oneself copy.

2, revise register a watch:

Previous12 Next

About us | Legal Notices | Sitemap | Links | Partner