关注恶意软件:
创建文件:
C:\Documents and Settings\Administrator\Local Settings\Application Data\wualct.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\wualct.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\1.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp
修改注册表:
HKLM\System\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations = "C:\Documents and Settings\Administrator\Local Settings\Temp\1.tmp"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSUPS = "C:\Documents and Settings\Administrator\Local Settings\Application Data\wualct.exe
行为描述:
此木马为注入型下载器木马,通过判断系统注册表是否存在某个键值,将恶意代码注入到explorer.exe或者iexplore.exe中。一般用户很难手动清除。不仅如此,木马还会释放和下载其他恶意程序到受感染计算机。将自身设置为开机自动启动,之后删除自身。
目前,卡巴斯基所有产品均可以对该木马进行查杀。
专家预防建议: