| 8-04-04 10:38 [Virus] - NETLINK/NETLINK32.exe (II dio)
 
  piše IGOR HITREC
 
 
 Uočeno je da se virus širi i na Windows 2000/XP računalima čiji je OS u potpunosti opskrbljen recentnim zakrpama. Virus promjeni sadržaj HOSTS
 tablice  (<WINDOWS>\System32\Drivers\etc\HOSTS) i unosi slijedeće:
   127.0.0.1 www.symantec.com
 127.0.0.1 securityresponse.symantec.com
 127.0.0.1 symantec.com
 127.0.0.1 www.sophos.com
 127.0.0.1 sophos.com
 127.0.0.1 www.mcafee.com
 127.0.0.1 mcafee.com
 127.0.0.1 liveupdate.symantecliveupdate.com
 127.0.0.1 www.viruslist.com
 127.0.0.1 viruslist.com
 127.0.0.1 viruslist.com
 127.0.0.1 f-secure.com
 127.0.0.1 www.f-secure.com
 127.0.0.1 kaspersky.com
 127.0.0.1 www.avp.com
 127.0.0.1 www.kaspersky.com
 127.0.0.1 avp.com
 127.0.0.1 www.networkassociates.com
 127.0.0.1 networkassociates.com
 127.0.0.1 www.ca.com
 127.0.0.1 ca.com
 127.0.0.1 mast.mcafee.com
 127.0.0.1 my-etrust.com
 127.0.0.1 www.my-etrust.com
 127.0.0.1 download.mcafee.com
 127.0.0.1 dispatch.mcafee.com
 127.0.0.1 secure.nai.com
 127.0.0.1 nai.com
 127.0.0.1 www.nai.com
 127.0.0.1 update.symantec.com
 127.0.0.1 updates.symantec.com
 127.0.0.1 us.mcafee.com
 127.0.0.1 liveupdate.symantec.com
 127.0.0.1 customer.symantec.com
 127.0.0.1 rads.mcafee.com
 127.0.0.1 trendmicro.com
 127.0.0.1 www.trendmicro.com 
   Znači, korisnik zaraženog računala ne može posjetiti web stranice proizvođača antivirunog SWa. Slično se ponaša i od prije poznati W32/Agobot-EM.
   Zaraženo računalo skenira ostala računala u mreži uz primjetan pad performansi (100% zauzeća procesorske snage).
     
 
 |