中国DOS联盟论坛

China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --
Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
Guest | Log in | Register | Members | Search | China DOS Union
中国DOS联盟论坛
The time now is 2026-08-25 18:33
47,812 topics / 349,910 posts / today 0 new / 48,263 members
其它操作系统综合讨论区 » [Repost] "QQ Auto Sender" and Variant Appear, Spreading Freely with Malicious Web Pages
Printable Version  1,197 / 0
Floor1 红色狂想 Posted 2003-06-02 00:00
金牌会员 Posts 1,501 Credits 4,289 From 河南省
Virus bulletin:

On May 28, Rising's global anti-virus monitoring network intercepted the Trojan virus spread through QQ: "QQ Auto Sender" (Trojan.WebAuto, Trojan.WebAuto.a), and carried out an emergency update. At present, no destructive effect of the virus has been found.

This virus secretly hides in the user's system. When it activates, it looks for QQ windows and every 1 minute sends fake messages such as "Go take a look here, there are quite a lot of good things inside -- " to all QQ friends who are online, luring users to click a website. If someone believes it and clicks the link, they will be ruthlessly infected by the virus, then become a source of infection and continue spreading it.

According to Rising anti-virus experts, this virus began spreading on the Internet yesterday, and some users have already been hit. It is hoped that all users, especially QQ users, will pay close attention to the movements of this virus. Rising will continue tracking this virus and publish the latest news. Rising already carried out an emergency virus update on May 28, with update version 15.37.01. Users are advised to upgrade their anti-virus software as soon as possible to prevent this virus from spreading on the Internet.

This virus has the following specific characteristics:

1. Hides in the system directory and modifies the registry for auto-start:

When the virus runs, it copies itself into the system directory under the name: WebAuto.exe, and adds a virus key value named: WebAuto.exe under the registry item: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run for auto-start.

2. Modifies IE's default home page

The virus changes the default IE home page in the user's system to http://www.***.com, so that users get infected as soon as they go online.

3. Sends fake QQ messages

The virus looks for QQ message sending windows and randomly sends the following messages to all of the user's friends:

1. "Hot movies are great! Let me recommend them to you too, completely free --";

2. "Go take a look here, there are quite a lot of good things inside --";

3. "Last time I saw a pretty good website, go take a look --";

After these messages, a malicious URL is also included to trick users into clicking.

Users who are relatively familiar with computers can manually remove this virus according to the virus characteristics above. The impact of the virus on the user's system can be restored to normal by using Rising's free registry repair tool, download URL: http://it.rising.com.cn/service/technology/RegClean_download.htm.

If any abnormal situation is encountered, users should quickly upgrade their Rising Antivirus 2003 version to 15.37.01 or use Rising online antivirus. If it is inconvenient for users to go out, they can also directly download the "Rising Antivirus 2003 Download Edition" from the Rising website to detect and remove this virus. They can also call Rising's anti-virus emergency hotline at any time: 010-82678800 for consultation. Rising anti-virus experts will provide you with all-round technical support and service!
[ Contact the Union admin team - 中国DOS联盟 - Standard version ]
Sponsored by ifanr Inc | © 2001–2023