PE_VIRUX.F
概 要

参 照

最新パターンファイル |

ウイルスタイプ: File infector

別 名: Virus.Win32.Virut.ce (Kaspersky), New Win32 !! (McAfee), W32.Virut.CF (Symantec), W32/Virut.Gen (Avira), W32/Scribble-B (Sophos),

感染報告の有無 : なし

破壊活動の有無: なし

言語: English

プラットフォーム: Windows 98, ME, NT, 2000, XP, Server 2003

暗号化: なし

危険度:


感染報告:

ダメージ度:

感染力:


特 徴: 

This file infector may be dropped by other malware. It may also be downloaded unknowingly by a user when visiting malicious Web sites.

It connects to IRC servers to receive and execute commands on the affected system. It then reads the URLs to download files detected as TROJ_DROPPER.JHD. This file infector then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.

It hooks APIs so that when these APIs are called, the malware code is executed which will then infect files.

Infected files are detected as PE_VIRUX.F. It also infects script files. Infected script files are detected as HTML_IFRAME.APX. However, it does not infect files that meet certain criteria.

This file infector modifies the system's HOSTS file by inserting a string at the beginning of the file. It then returns execution to the HOST file's original code after execution.

このウイルスに関しては次の情報も参照してください。
対応方法
詳細
感染状況

情報公開日: 2009/04/07


ウイルスデータベース検索

このウイルス情報に関して. こちらのアンケートにお答えください。