các bác ơi có ai biết diệt con virus này không

cmhoahongxanh

Donkey Kong
Tham gia ngày
10/5/06
Bài viết
498
Reaction score
25
"GrayPigeonServe" là tên của nó vào nó thường tạo files : 1.exe, g_sever....exe (ko nhớ) và g_server....dll ở forlder windows. Ai làm ơn chỉ em cái huhuhuhu,
À wen cái file "ntvdm.exe" là files gì vậy có phải virus ko . Em cứ bị virus là hay chạy file này
 
đây là 1 vài thông tin về con virus này:
Upon execution, this backdoor program drops a copy of itself as G_Server2006.exe in the Windows system folder. This file's attributes are set to Hidden, Read-only, and System to prevent detection.

This backdoor program also drops its component files, which are as follows, in the same folder:

G_Server2006.DLL
G_Server2006Key.DLL
To ensure its automatic execution at every system startup, it registers itself as a service by creating the following registry entry:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\GrayPigeonServer
ImagePath = "%Windows%\G_Server2006.exe"

(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)

Backdoor Routine

This backdoor program opens varying ports and allows a remote malicious user to perform the following commands on affected machines:

Create files in any folder
Create registry entries
Create threads
Download files from the Internet
Get disk status
Inject processes
Log keystrokes
Start or terminate services and processes
Affected Platforms

This backdoor program runs on Windows 95, 98, ME, NT, 2000, XP, and Server 2003.
 
Back
Top