论文部分内容阅读
近日,知名信息安全厂商卡巴斯基发布病毒播报,提醒用户注意一款恶意程序名为Trojan.Win32.Wiclir.a的后门木马程序。据悉,该木马通常会被和某些工具软件捆绑,以诱使用户下载运行。木马运行后会释放文件并通过修改注册表服务启动项来创建一个服务。其运行后会检测调试器和模拟器,以此来增加逆向人员的分析难度。黑客可以通过它窃取用户计算
Recently, well-known information security company Kaspersky released a virus broadcast to remind users to pay attention to a malicious program called Trojan.Win32.Wiclir.a backdoor Trojan program. It is reported that the Trojans are usually bundled with some tools to induce users to download and run. Trojans will release files after running and create a service by modifying registry service startup items. After running it will detect the debugger and simulator, in order to increase the difficulty of reverse personnel analysis. Hackers can steal user computing through it