Warning on the 19th: worms using email to spread viruses

The Beijing Information Security Evaluation Center and Jinshan Duba jointly released the popular virus on March 19, 2007.

Today, users are reminded to pay special attention to the following viruses "White House Messenger" variant H (Worm.Glowa.h) and "shaking game thief" variant F (Win32.PswTroj.Cabal.f).

The "White House Messenger" variant H (Worm.Glowa.h) is a worm that uses e-mail to spread the virus.

"Fighting game thief" variant F (Win32.PswTroj.Cabal.f) is a Trojan horse that steals the "shocking" accounts of online games.

1. The threat level of the "White House Messenger" variant H (Worm.Glowa.h):

Virus characteristics: The virus spreads through emails, it will send a large number of emails to well-known websites, its subject is "White House News", the content is fake news related to nuclear war, induce mail recipients to download and open the email The virus attachment reaches the purpose of spreading the virus. Because it will send a lot of spam, it may also cause the user's computer system to slow down, and the network bandwidth will be severely occupied or even paralyzed.

Symptoms: After the virus is running, it will release the wservice.exe and SPQ2x10.exe virus files in the computer system, modify the registry, and automatically start with the boot. In addition, it will forcibly terminate the monitoring process of multiple antivirus software.

2. The threat level of variant F (Win32.PswTroj.Cabal.f):

Virus characteristics The virus is aimed at online games "shocked", it is similar to the general hacking Trojan virus, it will wait for the opportunity to hide itself in the "shocked" game process, and create information hooks to obtain effective information such as game account and password Send the stolen information to Trojan growers through the website. Cause the loss of the user's network virtual property. Methods to prevent Trojan virus:

1. Most Trojan virus programs will automatically hide themselves in some startup items of the system in order to achieve the purpose of automatic loading next time the computer starts. The Windows system will automatically load some specific locations during the startup process. The characteristics of the program achieve the purpose of loading every time the system starts.

2. Because the file names of Trojan horses can be ever-changing, the file names of the same Trojan horse may be completely different. To detect Trojan horses effectively, it must be achieved through a combination of dynamic and static methods.

Duba forVista version listed

Symptoms: After the virus runs, it will release Ghook.dll and svchost.exe virus files. Modify the registry to achieve automatic startup with boot. At the same time, it injects itself into the cabalmain.exe process, and checks the data at a certain frequency, and obtains valid account information.

Kingsoft Anti-Virus Engineer recommends:

1. With the development of computer technology, more viruses will accompany you. In order to protect the security of your system and personal information, please update the virus database of Duba frequently to prevent the invasion of viruses.

2. Establish good safety habits. Do not open some unrecognized e-mails and attachments, do not go to some unfamiliar websites, and do not execute files that have not been processed by anti-virus software after downloading from the Internet, these can ensure your computer is more secure.

Classic SPC Flooring

Classic Spc Flooring,Classic Spc Floor,Classic Spc Plank Flooring,Classic Spc Laminate Flooring

JIANGSU PERFECT NEW MATERIAL TECHNOLOGY CO., LTD. , https://www.bffloor.com