病毒预警:光华反病毒资讯(8.1—8.7)
 收藏

  光华反病毒研究中心近日进行病毒特征码更新,请用户尽快到光华网站www.viruschina.com下载升级包,以下是几个重要病毒的简介:

  一、邮件病毒:W32.Mytob.IK@mm 危害级别:★★★★☆

  根据光华反病毒研究中心专家介绍,该病毒长度为 36,352 字节,感染 Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP系统,它打开后门并降低计算机安全设置,当收到、打开此病毒时,有以下危害:

  A 复制自身到系统目录为 msnl.exe
  B 增加注册表项"WINDOWS SYSTEM" = "msnl.exe"
   到
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
   和HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
   使得病毒在每次开机后自动能够执行。
  C 修改注册表项 "Start" = "4"
   在HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess
   使得计算机安全设置降低
  D 创建互斥量 H-E-L-L-B-O-T-P-O-L-Y-M-O-R-P-H
   使得病毒在感染的计算机中只执行一份
  E 从地址簿和以下位置收集邮件地址
   Windows目录的Temporary Internet Files
   用户目录的Local Settings\Temporary Internet Files
   系统目录
  F 从C盘到Z盘的以下扩展名文件中收集邮件地址
   .txt
   .htm
   .sht
   .jsp
   .cgi
   .xml
   .php
   .asp
   .dbx
   .tbb
   .adb
   .pl
   .html
   .wab
  G 在找到的邮件服务器名前增加以下前缀
   mx.
   mail.
   smtp.
   mx1.
   mxs.
   mail1.
   relay.
   ns.
   gate.
  H 使用自带的SMTP引擎发送病毒邮件到上述找到的邮件地址
   发件人为邮件中的地址或以下之一:
   adam
   alex
   andrew
   anna
   bill
   bob
   brenda
   brent
   brian
   claudia
   dan
   dave
   david
   debby
   frank
   fred
   george
   helen
   jack
   james
   jane
   jerry
   jim
   jimmy
   joe
   john
   jose
   josh
   julie
   kevin
   leo
   linda
   maria
   mary
   matt
   michael
   mike
   paul
   peter
   ray
   robert
   sales
   sam
   sandra
   serg
   smith
   stan
   steve
   ted
   tom
  I 主题为以下之一:
   Your password has been updated
   Your password has been successfully updated
   You have successfully updated your password
   Your new account password is approved
   Your Account is Suspended
   *DETECTED* Online User Violation
   Your Account is Suspended For Security Reasons
   Warning Message: Your services near to be closed.
   Important Notification
   Members Support
   Security measures
   Email Account Suspension
   Notice of account limitation

  J 内容为以下之一:
   Dear user [用户名],
   You have successfully [删除]
   +++ [主机名] Antivirus - www.[主机名]

   Dear user [用户名],
   It has come to  [删除]
   +++ [主机名] Antivirus - www.[主机名]

   Dear [主机名] Member,
   We have temporarily [删除]
   +++ [主机名] Antivirus - www.[主机名]

   Dear [主机名] Member,
   Your e-mail account [删除]
   +++ [主机名] Antivirus - www.[主机名]

  K 附件为以下之一:
   updated-password
   email-password
   new-password
   password
   approved-password
   account-password
   accepted-password
   important-details
   account-details
   email-details
   account-info
   document
   readme
   account-report

  L 附件扩展名为以下之一:
   .bat
   .cmd
   .exe
   .pif
   .scr

  M 病毒回避以下用户名的邮件地址
   root
   info
   samples
   postmaster
   webmaster
   noone
   nobody
   nothing
   anyone
   someone
   your
   you
   me
   bugs
   rating
   site
   contact
   soft
   no
   somebody
   privacy
   service
   help
   not
   submit
   feste
   ca
   gold-certs
   the.bat
   page
   spm
   spam
   www
   secur
   abuse
  N 病毒回避以下主机名的邮件地址
   berkeley
   unix
   math
   bsd
   mit.e
   gnu
   fsf.
   ibm.com
   google
   kernel
   linux
   fido
   usenet
   iana
   ietf
   rfc-ed
   sendmail
   arin.
   ripe.
   isi.e
   isc.o
   secur
   acketst
   pgp
   tanford.e
   utgers.ed
   mozilla
   syma
   icrosof
   msn.
   hotmail
   panda
   sopho
   borlan
   inpris
   example
   mydomai
   nodomai
   ruslis
   .gov
   gov.
   .mil
   foo.
  O 连接到novi.bukers.org的 TCP 端口 8881 ,等待黑客下达以下命令
   执行任意文件
   下载文件
   执行IRC命令
   重启计算机
   发送计算机资料
   开始或停止发送病毒邮件
   病毒自杀
  P 修改以下注册表值,降低 IE 安全性
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"CurrentLevel" = "1"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"Flags" = "1"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1001" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1004" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1200" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1201" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1206" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1400" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1402" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1405" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1406" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1407" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1601" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1604" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1605" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1606" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1607" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1608" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1609" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1800" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1802" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1803" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1804" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1805" = "1"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1A00" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1A02" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1A03" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1A04" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1A05" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1A06" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1A10" = "1"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"2001" = "0"
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"2004" = "0"
  Q 禁止以下网站的访问(多数为安全网站)
   www.symantec.com
   securityresponse.symantec.com
   symantec.com
   www.sophos.com
   sophos.com
   www.mcafee.com
   mcafee.com
   liveupdate.symantecliveupdate.com
   www.viruslist.com
   viruslist.com
   viruslist.com
   f-secure.com
   www.f-secure.com
   kaspersky.com
   kaspersky-labs.com
   www.avp.com
   www.kaspersky.com
   avp.com
   www.networkassociates.com
   networkassociates.com
   www.ca.com
   ca.com
   mast.mcafee.com
   my-etrust.com
   www.my-etrust.com
   download.mcafee.com
   dispatch.mcafee.com
   secure.nai.com
   nai.com
   www.nai.com
   update.symantec.com
   updates.symantec.com
   us.mcafee.com
   liveupdate.symantec.com
   customer.symantec.com
   rads.mcafee.com
   trendmicro.com 
   www.pandasoftware.com
   www.trendmicro.com
   www.grisoft.com
   www.microsoft.com
   microsoft.com
   www.virustotal.com
   virustotal.com
   www.amazon.com
   www.amazon.co.uk
   www.amazon.ca
   www.amazon.fr
   www.paypal.com
   moneybookers.com
   www.moneybookers.com
   www.ebay.com
   ebay.com
  R 关闭以下进程并禁止执行(多为杀毒软件)
   ACKWIN32.EXE
   ADAWARE.EXE
   ADVXDWIN.EXE
   AGENTSVR.EXE
   AGENTW.EXE
   ALERTSVC.EXE
   ALEVIR.EXE
   ALOGSERV.EXE
   AMON9X.EXE
   ANTI-TROJAN.EXE
   ANTIVIRUS.EXE
   ANTS.EXE
   APIMONITOR.EXE
   APLICA32.EXE
   APVXDWIN.EXE
   ARR.EXE
   ATCON.EXE
   ATGUARD.EXE
   ATRO55EN.EXE
   ATUPDATER.EXE
   ATWATCH.EXE
   AU.EXE
   AUPDATE.EXE
   AUTO-PROTECT.NAV80TRY.EXE
   AUTODOWN.EXE
   AUTOTRACE.EXE
   AUTOUPDATE.EXE
   AVCONSOL.EXE
   AVE32.EXE
   AVGCC32.EXE
   AVGCTRL.EXE
   AVGNT.EXE
   AVGSERV.EXE
   AVGSERV9.EXE
   AVGUARD.EXE
   AVGW.EXE
   AVKPOP.EXE
   AVKSERV.EXE
   AVKSERVICE.EXE
   AVKWCTl9.EXE
   AVLTMAIN.EXE
   AVNT.EXE
   AVP.EXE
   AVP32.EXE
   AVPCC.EXE
   AVPDOS32.EXE
   AVPM.EXE
   AVPTC32.EXE
   AVPUPD.EXE
   AVSCHED32.EXE
   AVSYNMGR.EXE
   AVWINNT.EXE
   AVWUPD.EXE
   AVWUPD32.EXE
   AVWUPSRV.EXE
   AVXMONITOR9X.EXE
   AVXMONITORNT.EXE
   AVXQUAR.EXE
   BACKWEB.EXE
   BARGAINS.EXE
   BD_PROFESSIONAL.EXE
   BEAGLE.EXE
   BELT.EXE
   BIDEF.EXE
   BIDSERVER.EXE
   BIPCP.EXE
   BIPCPEVALSETUP.EXE
   BISP.EXE
   BLACKD.EXE
   BLACKICE.EXE
   BLSS.EXE
   BOOTCONF.EXE
   BOOTWARN.EXE
   BORG2.EXE
   BPC.EXE
   BRASIL.EXE
   BS120.EXE
   BUNDLE.EXE
   BVT.EXE
   CCAPP.EXE
   CCEVTMGR.EXE
   CCPXYSVC.EXE
   CDP.EXE
   CFD.EXE
   CFGWIZ.EXE
   CFIADMIN.EXE
   CFIAUDIT.EXE
   CFINET.EXE
   CFINET32.EXE
   CLAW95CF.EXE
   CLEAN.EXE
   CLEANER.EXE
   CLEANER3.EXE
   CLEANPC.EXE
   CLICK.EXE
   CMD.EXE
   CMD32.EXE
   CMESYS.EXE
   CMGRDIAN.EXE
   CMON016.EXE
   CONNECTIONMONITOR.EXE
   CPD.EXE
   CPF9X206.EXE
   CPFNT206.EXE
   CTRL.EXE
   CV.EXE
   CWNB181.EXE
   CWNTDWMO.EXE
   DATEMANAGER.EXE
   DCOMX.EXE
   DEFALERT.EXE
   DEFSCANGUI.EXE
   DEFWATCH.EXE
   DEPUTY.EXE
   DIVX.EXE
   DLLCACHE.EXE
   DLLREG.EXE
   DOORS.EXE
   DPF.EXE
   DPFSETUP.EXE
   DPPS2.EXE
   DRWATSON.EXE
   DRWEB32.EXE
   DRWEBUPW.EXE
   DSSAGENT.EXE
   DVP95.EXE
   DVP95_0.EXE
   ECENGINE.EXE
   EFPEADM.EXE
   EMSW.EXE
   ENT.EXE
   ESAFE.EXE
   ESCANHNT.EXE
   ESCANV95.EXE
   ESPWATCH.EXE
   ETHEREAL.EXE
   ETRUSTCIPE.EXE
   EVPN.EXE
   EXANTIVIRUS-CNET.EXE
   EXE.AVXW.EXE
   EXPERT.EXE
   EXPLORE.EXE
   F-PROT.EXE
   F-PROT95.EXE
   F-STOPW.EXE
   FAMEH32.EXE
   FAST.EXE
   FCH32.EXE
   FIH32.EXE
   FINDVIRU.EXE
   FIREWALL.EXE
   FNRB32.EXE
   FP-WIN.EXE
   FP-WIN_TRIAL.EXE
   FPROT.EXE
   FRW.EXE
   FSAA.EXE
   FSAV.EXE
   FSAV32.EXE
   FSAV530STBYB.EXE
   FSAV530WTBYB.EXE
   FSAV95.EXE
   FSGK32.EXE
   FSM32.EXE
   FSMA32.EXE
   FSMB32.EXE
   GATOR.EXE
   GBMENU.EXE
   GBPOLL.EXE
   GENERICS.EXE
   GMT.EXE
   GUARD.EXE
   GUARDDOG.EXE
   HACKTRACERSETUP.EXE
   HBINST.EXE
   HBSRV.EXE
   HOTACTIO.EXE
   HOTPATCH.EXE
   HTLOG.EXE
   HTPATCH.EXE
   HWPE.EXE
   HXDL.EXE
   HXIUL.EXE
   IAMAPP.EXE
   IAMSERV.EXE
   IAMSTATS.EXE
   IBMASN.EXE
   IBMAVSP.EXE
   ICLOADNT.EXE
   ICMON.EXE
   ICSUPP95.EXE
   ICSUPPNT.EXE
   IDLE.EXE
   IEDLL.EXE
   IEDRIVER.EXE
   IEXPLORER.EXE
   IFACE.EXE
   IFW2000.EXE
   INETLNFO.EXE
   INFUS.EXE
   INFWIN.EXE
   INIT.EXE
   INTDEL.EXE
   INTREN.EXE
   IOMON98.EXE
   ISTSVC.EXE
   JAMMER.EXE
   JDBGMRG.EXE
   JEDI.EXE
   KAVLITE40ENG.EXE
   KAVPERS40ENG.EXE
   KAVPF.EXE
   KAZZA.EXE
   KEENVALUE.EXE
   KERIO-PF-213-EN-WIN.EXE
   KERIO-WRL-421-EN-WIN.EXE
   KERIO-WRP-421-EN-WIN.EXE
   KERNEL32.EXE
   KILLPROCESSSETUP161.EXE
   LAUNCHER.EXE
   LDNETMON.EXE
   LDPRO.EXE
   LDPROMENU.EXE
   LDSCAN.EXE
   LNETINFO.EXE
   LOADER.EXE
   LOCALNET.EXE
   LOCKDOWN.EXE
   LOCKDOWN2000.EXE
   LOOKOUT.EXE
   LORDPE.EXE
   LSETUP.EXE
   LUALL.EXE
   LUAU.EXE
   LUCOMSERVER.EXE
   LUINIT.EXE
   LUSPT.EXE
   MAPISVC32.EXE
   MCAGENT.EXE
   MCMNHDLR.EXE
   MCSHIELD.EXE
   MCTOOL.EXE
   MCUPDATE.EXE
   MCVSRTE.EXE
   MCVSSHLD.EXE
   MD.EXE
   MFIN32.EXE
   MFW2EN.EXE
   MFWENG3.02D30.EXE
   MGAVRTCL.EXE
   MGAVRTE.EXE
   MGHTML.EXE
   MGUI.EXE
   MINILOG.EXE
   MMOD.EXE
   MONITOR.EXE
   MOOLIVE.EXE
   MOSTAT.EXE
   MPFAGENT.EXE
   MPFSERVICE.EXE
   MPFTRAY.EXE
   MRFLUX.EXE
   MSAPP.EXE
   MSBB.EXE
   MSBLAST.EXE
   MSCACHE.EXE
   MSCCN32.EXE
   MSCMAN.EXE
   MSCONFIG.EXE
   MSDM.EXE
   MSDOS.EXE
   MSIEXEC16.EXE
   MSINFO32.EXE
   MSLAUGH.EXE
   MSMGT.EXE
   MSMSGRI32.EXE
   MSSMMC32.EXE
   MSSYS.EXE
   MSVXD.EXE
   MU0311AD.EXE
   MWATCH.EXE
   N32SCANW.EXE
   NAV.EXE
   NAVAP.NAVAPSVC.EXE
   NAVAPSVC.EXE
   NAVAPW32.EXE
   NAVDX.EXE
   NAVLU32.EXE
   NAVNT.EXE
   NAVSTUB.EXE
   NAVW32.EXE
   NAVWNT.EXE
   NC2000.EXE
   NCINST4.EXE
   NDD32.EXE
   NEC.EXE
   NEOMONITOR.EXE
   NEOWATCHLOG.EXE
   NETARMOR.EXE
   NETD32.EXE
   NETINFO.EXE
   NETMON.EXE
   NETSCANPRO.EXE
   NETSPYHUNTER-1.2.EXE
   NETSTAT.EXE
   NETUTILS.EXE
   NISSERV.EXE
   NISUM.EXE
   NMAIN.EXE
   NOD32.EXE
   NORMIST.EXE
   NORTON_INTERNET_SECU_3.0_407.EXE
   NOTSTART.EXE
   NPF40_TW_98_NT_ME_2K.EXE
   NPFMESSENGER.EXE
   NPROTECT.EXE
   NPSCHECK.EXE
   NPSSVC.EXE
   NSCHED32.EXE
   NSSYS32.EXE
   NSTASK32.EXE
   NSUPDATE.EXE
   NT.EXE
   NTRTSCAN.EXE
   NTVDM.EXE
   NTXconfig.EXE
   NUI.EXE
   NUPGRADE.EXE
   NVARCH16.EXE
   NVC95.EXE
   NVSVC32.EXE
   NWINST4.EXE
   NWSERVICE.EXE
   NWTOOL16.EXE
   OLLYDBG.EXE
   ONSRVR.EXE
   OPTIMIZE.EXE
   OSTRONET.EXE
   OTFIX.EXE
   OUTPOST.EXE
   OUTPOSTINSTALL.EXE
   OUTPOSTPROINSTALL.EXE
   PADMIN.EXE
   PANIXK.EXE
   PATCH.EXE
   PAVCL.EXE
   PAVPROXY.EXE
   PAVSCHED.EXE
   PAVW.EXE
   PCFWALLICON.EXE
   PCIP10117_0.EXE
   PCSCAN.EXE
   PDSETUP.EXE
   PERISCOPE.EXE
   PERSFW.EXE
   PERSWF.EXE
   PF2.EXE
   PFWADMIN.EXE
   PGMONITR.EXE
   PINGSCAN.EXE
   PLATIN.EXE
   POP3TRAP.EXE
   POPROXY.EXE
   POPSCAN.EXE
   PORTDETECTIVE.EXE
   PORTMONITOR.EXE
   POWERSCAN.EXE
   PPINUPDT.EXE
   PPTBC.EXE
   PPVSTOP.EXE
   PRIZESURFER.EXE
   PRMT.EXE
   PRMVR.EXE
   PROCDUMP.EXE
   PROCESSMONITOR.EXE
   PROCEXPLORERV1.0.EXE
   PROGRAMAUDITOR.EXE
   PROPORT.EXE
   PROTECTX.EXE
   PSPF.EXE
   PURGE.EXE
   QCONSOLE.EXE
   QSERVER.EXE
   RAPAPP.EXE
   RAV7.EXE
   RAV7WIN.EXE
   RAV8WIN32ENG.EXE
   RAY.EXE
   RB32.EXE
   RCSYNC.EXE
   REALMON.EXE
   REGED.EXE
   REGEDIT.EXE
   REGEDT32.EXE
   RESCUE.EXE
   RESCUE32.EXE
   RRGUARD.EXE
   RSHELL.EXE
   RTVSCAN.EXE
   RTVSCN95.EXE
   RULAUNCH.EXE
   RUN32DLL.EXE
   RUNDLL.EXE
   RUNDLL16.EXE
   RUXDLL32.EXE
   SAFEWEB.EXE
   SAHAGENT.EXE
   SAVE.EXE
   SAVENOW.EXE
   SBSERV.EXE
   SC.EXE
   SCAM32.EXE
   SCAN32.EXE
   SCAN95.EXE
   SCANPM.EXE
   SCRSCAN.EXE
   SETUPVAMEEVAL.EXE
   SETUP_FLOWPROTECTOR_US.EXE
   SFC.EXE
   SGSSFW32.EXE
   SH.EXE
   SHELLSPYINSTALL.EXE
   SHN.EXE
   SHOWBEHIND.EXE
   SMC.EXE
   SMS.EXE
   SMSS32.EXE
   SOAP.EXE
   SOFI.EXE
   SPERM.EXE
   SPF.EXE
   SPHINX.EXE
   SPOLER.EXE
   SPOOLCV.EXE
   SPOOLSV32.EXE
   SPYXX.EXE
   SREXE.EXE
   SRNG.EXE
   SS3EDIT.EXE
   SSGRATE.EXE
   SSG_4104.EXE
   ST2.EXE
   START.EXE
   STCLOADER.EXE
   SUPFTRL.EXE
   SUPPORT.EXE
   SUPPORTER5.EXE
   SVC.EXE
   SVCHOSTC.EXE
   SVCHOSTS.EXE
   SVSHOST.EXE
   SWEEP95.EXE
   SWEEPNET.SWEEPSRV.SYS.SWNETSUP.EXE
   SYMPROXYSVC.EXE
   SYMTRAY.EXE
   SYSEDIT.EXE
   SYSTEM.EXE
   SYSTEM32.EXE
   SYSUPD.EXE
   TASKMG.EXE
   TASKMGR.EXE
   TASKMO.EXE
   TASKMON.EXE
   TAUMON.EXE
   TBSCAN.EXE
   TC.EXE
   TCA.EXE
   TCM.EXE
   TDS-3.EXE
   TDS2-NT.EXE
   TEEKIDS.EXE
   TFAK.EXE
   TFAK5.EXE
   TGBOB.EXE
   TITANIN.EXE
   TITANINXP.EXE
   TRACERT.EXE
   TRICKLER.EXE
   TRJSCAN.EXE
   TRJSETUP.EXE
   TROJANTRAP3.EXE
   TSADBOT.EXE
   TVMD.EXE
   TVTMD.EXE
   UNDOBOOT.EXE
   UPDAT.EXE
   UPDATE.EXE
   UPGRAD.EXE
   UTPOST.EXE
   VBCMSERV.EXE
   VBCONS.EXE
   VBUST.EXE
   VBWIN9X.EXE
   VBWINNTW.EXE
   VCSETUP.EXE
   VET32.EXE
   VET95.EXE
   VETTRAY.EXE
   VFSETUP.EXE
   VIR-HELP.EXE
   VIRUSMDPERSONALFIREWALL.EXE
   VNLAN300.EXE
   VNPC3000.EXE
   VPC32.EXE
   VPC42.EXE
   VPFW30S.EXE
   VPTRAY.EXE
   VSCAN40.EXE
   VSCENU6.02D30.EXE
   VSCHED.EXE
   VSECOMR.EXE
   VSHWIN32.EXE
   VSISETUP.EXE
   VSMAIN.EXE
   VSMON.EXE
   VSSTAT.EXE
   VSWIN9XE.EXE
   VSWINNTSE.EXE
   VSWINPERSE.EXE
   W32DSM89.EXE
   W9X.EXE
   WATCHDOG.EXE
   WEBDAV.EXE
   WEBSCANX.EXE
   WEBTRAP.EXE
   WFINDV32.EXE
   WHOSWATCHINGME.EXE
   WIMMUN32.EXE
   WIN-BUGSFIX.EXE
   WIN32.EXE
   WIN32US.EXE
   WINACTIVE.EXE
   WINDOW.EXE
   WINDOWS.EXE
   WININETD.EXE
   WININIT.EXE
   WININITX.EXE
   WINLOGIN.EXE
   WINMAIN.EXE
   WINNET.EXE
   WINPPR32.EXE
   WINRECON.EXE
   WINSERVN.EXE
   WINSSK32.EXE
   WINSTART.EXE
   WINSTART001.EXE
   WINTSK32.EXE
   WINUPDATE.EXE
   WKUFIND.EXE
   WNAD.EXE
   WNT.EXE
   WRADMIN.EXE
   WRCTRL.EXE
   WSBGATE.EXE
   WUPDATER.EXE
   WUPDT.EXE
   WYVERNWORKSFIREWALL.EXE
   XPF202EN.EXE
   ZAPRO.EXE
   ZAPSETUP3001.EXE
   ZATUTOR.EXE
   ZONALM2601.EXE
   ZONEALARM.EXE
   _AVP32.EXE
   _AVPCC.EXE
   _AVPM.EXE 
  
  光华反病毒软件已经对这种病毒进行了处理,请用户升级后,使用光华反病毒软件清除。

  二、手机病毒 SymbOS.Cabir.U 危害级别:★★☆☆☆

  根据光华反病毒研究中心专家介绍,SymbOS.Cabir.U 是一个手机病毒,该病毒长度 7,403 字节,感染 Symbin S60 系统的智能手机,它使用蓝牙技术传播,当收到、打开此病毒时,有以下危害:

  A 创建以下文件
   \SYSTEM\APPS\qex00r\qex00r.app
   \SYSTEM\APPS\qex00r\qex00r.RSC
   \SYSTEM\APPS\qex00r\FLO.MDL 

C:\SYSTEM\SYMBIANSECUREDATA\QEX00RSECURITYMANAGER\QEX00R.APP
C:\SYSTEM\SYMBIANSECUREDATA\QEX00RSECURITYMANAGER\QEX00R.RSC
C:\SYSTEM\SYMBIANSECUREDATA\QEX00RSECURITYMANAGER\QEX00R.SIS
   C:\SYSTEM\RECOGS\FLO.MDL
   C:\QEX00R.APP
   C:\QEX00R.RSC
   C:\FLO.MDL
  B 添加病毒到系统启动列表,使得病毒无法通过关机清除,每次开机时显示信息Jokerr
  C 搜索蓝牙设备传播

  请用户使用光华反病毒软件手机版清除,免费下载地址为:http://www.viruschina.com/html/update.asp

  北京日月光华软件公司网站(http://www.viruschina.com)每日进行病毒特征码更新,光华反病毒研究中心专家提醒您:请尽快到光华安全网站在线订购光华反病毒软件来防范病毒的入侵,时刻保护您的电脑安全。光华反病毒软件用户升级到8月1日的病毒库就可以完全查杀这些病毒。