W32/Tenga-A infects Windows executable files on all drives it can find other than drive A:. W32/Tenga-A also attempts to infect files on network resources.
W32/Tenga-A tries to download and run a file from a remote server. At the time of writing this file is detected as Troj/Penta-A.
W32/Tenga-A attempts to disable Windows File Protection.
W32/Tenga-A attempts to infect files at randomly chosen IP addresses via NetBIOS.
W32/Tenga-A also attempts to connect to a pre-specified server and spawn a remote command prompt that can recieve further commands from a remote intruder.發表人:
bombshell 時間: 2005-11-23 10:29 PM