-Поиск по дневнику

Поиск сообщений в Ballard_Mcdaniel

 -Подписка по e-mail

 

 -Статистика

Статистика LiveInternet.ru: показано количество хитов и посетителей
Создан: 06.06.2020
Записей:
Комментариев:
Написано: 191


Killer 13 (Worm. KillOnce), spreading on the internet some days ago, it has a very strong capability to attack the LAN, and it can be extremely difficult to eliminate, please be careful of laptop or computer customers.

Понедельник, 08 Июня 2020 г. 10:56 + в цитатник

Virus variety: Worm
Attack time: December 13
Transmission method: World-wide-web
Infected object: network
Virus size: 81,920 bytes
Virus introduction:
This virus can run ordinarily beneath operating systems such as Windows2000 and WindowsXP. When it runs, it will create itself in to the method directory and recycle bin, and begin itself by modifying the registry, in the exact same time, it will spread wildly within the LAN, establish many threads, kill the recognized anti-virus computer software, and use the NET command to open the laptop on the LAN Back door. When the virus broke out on December 13th, it would also bring a devastating attack to the infected laptop or computer: delete all directories and all files on the C drive!
data recovery software free download and removal:
This virus has the following qualities. When file recovery software finds these characteristics inside the pc, it is probably to be infected with this virus.
1st, the virus will copy itself towards the method directory and recycle bin and named Killonce.exe
Second, the virus are going to be within the registry when running:
In HKEY_LOCAL_MACHINE \\ Computer software \\ Microsoft \\ Windows \\ CurrentVersion \\ Run, add the essential worth: Killonce, the content material is: C: \\ WINNT \\ SYSTEM32 \\ KillOnce.exe's self-starting essential.
3. If the user runs tools which include regedit.exe, msconfig.exe just after poisoning, a prompt box titled: 'Illegal User' with all the content: 'You don't have permission to execute this file' will appear.
four. When the * .doc file exists within the 'My Documents' directory, the virus will copy itself to this directory, named: RICHED20.DLL and SHDOCVW.DLL.
5. The virus will create a GUEST user in the management group, and raise the access authority of this user account to the authority with the administrator, and leave a backdoor within the method.
Sixth, on December 13, the virus will add the command deltree / yc: \\ *. * To the autoexec.bat file.
When the user finds all or a part of the above phenomenon on his computer system, he is likely to become hit by the 'Killer 13 (Worm.KillOnce)' virus. diskgetor data recovery can delete the virus file directly and delete the virus important inside the registry Do away with the effects of viruses,

Метки:  

 

Добавить комментарий:
Текст комментария: смайлики

Проверка орфографии: (найти ошибки)

Прикрепить картинку:

 Переводить URL в ссылку
 Подписаться на комментарии
 Подписать картинку