左手
著名写手
著名写手
  • 铜币0枚
  • 威望0点
  • 贡献值0点
阅读:321回复:1

SYMANTEC将3721列为‘广告类’病毒

楼主#
更多 发布于:2003-10-07 00:51
如下是SYMANTEC升级的病毒名字:
Adware.CNS3721 File infector 10/01/03
详细看这里:
[a]http://securityresponse.symantec.com/avcenter/venc/data/adware.cns3721.html [/a]
左手
著名写手
著名写手
  • 铜币0枚
  • 威望0点
  • 贡献值0点
1C#
发布于:2003-10-07 01:28
Re: SYMANTEC将3721列为‘广告类’病毒
Adware.CNS3721  
Last Updated on: October 01, 2003 03:54:41 PM

  
  

  
  
Type:  Adware
  
  
  
  
Systems Affected:  Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected:  DOS, Linux, Macintosh, OS/2, UNIX
  
Removal:  Low
Damage:  Low



 
Intelligent Updater Definitions*
 October 01, 2003
 
 
LiveUpdate™ Definitions **
 October 01, 2003
 
 
*
 Intelligent Updater definitions are released daily, but require manual download and installation.
Click here to download manually.
 
**
 LiveUpdate definitions are usually released every Wednesday.
Click here for instructions on using LiveUpdate.
 
 
 


This threat can be detected only by Symantec products that support expanded threats. For more information on expanded threats, please go here.



Behavior
Adware.CNS3721 is an adware program that changes the Internet Explorer home page and contacts the Web site, cns.3721.com, for advertising purposes.

Symptoms
Your home page is changed to we.cn.gs.

Transmission
This adware component must be manually installed or installed as a component of another program that you install.






File names: Linmeimei.exe; Wupdate.exe

When Adware.CNS3721 is executed, it performs the following actions:


Copies itself to %System%\Wupdate.exe.


--------------------------------------------------------------------------------
Note: %System% is a variable. The worm locates the folder (by default, this is C:\Windows\System or C:\Winnt\System32) and copies itself to that location.
--------------------------------------------------------------------------------


Adds the value:

"Windows Update" =  %System%\Wupdate.exe

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the adware runs when you start Windows.


Changes the Internet Explorer home page to we.cn.gs.


Opens a browser window and displays a flash animation downloaded from the Internet.


May contact the Web site, cns.3721.com, for advertising purposes.


May download itself, or its updated version, from we.cn.gs.
游客

返回顶部