請參見:
http://www.trendmicro.com/vinfo/zh-cn/viru...=TROJ_DLOADER.E
http://www.trendmicro.co.jp/vinfo/virusenc...OADER.E&VSect=S
說明:
This Trojan connects to a specified Web site, where it may download and install other applications. It runs on Windows 95, 98, ME, NT, 2000, and XP.
---------------------------------------------------------------------------
詳細內容:(
http://www.trendmicro.com/vinfo/zh-cn/virusencyclo/default5.asp?VName=TROJ_DLOADER.E&VSect=T)
Upon execution, this memory resident Trojan may drop a copy of itself in any of the following locations using a random file name:
C:Documents and SettingsAdministratorApplication Data
C:WindowsLocal SettingsApplication Data
It adds the following registry entry to ensure its automatic execution upon Windows startup:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
<random value> = ?lt;malware file>?
It then connects to a Web site, specified in the Trojan body, where it may download and install other applications.
This Trojan usually arrives UPX-compressed, and is written in Visual C++.
-----------------------------------------------------------------------------
解決方案:
http://www.trendmicro.com/vinfo/zh-cn/viru...=TROJ_DLOADER.E.......Good luck! :sun: