病毒会开启80端口连接以下IP地址:
79.125.43.** 中东及欧洲地区
75.101.212.** 美国
以上2个IP地址已无法PING通
病毒会开启8585端口连接到以下IP地址:
59.36.101.*** 广东省东莞市
200.55.186.** 巴西
以上2个IP已无法PING通
该域名的WHOIS信息:
Domain Name:update-adobe.com
Record created:2009/12/9
Record expired:2010/12/9
Domain servers in listed order:
ns1.lunarbre***.com ns2.lunarbre***.com
Administrat:
name-- DNS MANAGER
org-- ABSOLUTEE CORP. LTD.
country-- CN
province-- Hongkong
city-- Hongkong
address-- FLAT/RM B 8/F CHONG MING BUILDING 72 CHEUNG SHA WAN RD KL
postalcode-- 999077
telephone-- +852.23192933
fax-- +852.23195168
E-mail-- up3943324131001@absolutee.com
Technical Contact:
name-- DNS MANAGER
org-- ABSOLUTEE CORP. LTD.
country-- CN
province-- Hongkong
city-- Hongkong
address-- FLAT/RM B 8/F CHONG MING BUILDING 72 CHEUNG SHA WAN RD KL
postalcode-- 999077
telephone-- +852.23192933
fax-- +852.23195168
E-mail-- up3943324906102@absolutee.com
Billing Contact:
name-- DNS MANAGER
org-- ABSOLUTEE CORP. LTD.
country-- CN
province-- Hongkong
city-- Hongkong
address-- FLAT/RM B 8/F CHONG MING BUILDING 72 CHEUNG SHA WAN RD KL
postalcode-- 999077
telephone-- +852.23192933
fax-- +852.23195168
E-mail-- up3943324906103@absolutee.com
Registrant Contact:
name-- DNS MANAGER
org-- ABSOLUTEE CORP. LTD.
country-- CN
province-- Hongkong
city-- Hongkong
address-- FLAT/RM B 8/F CHONG MING BUILDING 72 CHEUNG SHA WAN RD KL
postalcode-- 999077
telephone-- +852.23192933
fax-- +852.23195168
E-mail-- up3943324774804@absolutee.com
[HiChina Format]
Domain Name ..................... update-adobe.com
注:%System32%是一个可变路径。病毒通过查询操作系统来决定当前System文件夹的位置。Windows2000/NT中默认的安装路径是C:\Winnt\System32,windows95/98/me中默认的安装路径是C:\Windows\System,windowsXP中默认的安装路径是C:\Windows\System32。
%Temp% = C:\Documents and Settings\AAAAA\Local Settings\Temp 当前用户TEMP缓存变量
%Windir%\ WINDODWS所在目录
%DriveLetter%\ 逻辑驱动器根目录
%ProgramFiles%\ 系统程序默认安装目录
%HomeDrive% = C:\ 当前启动的系统的所在分区
%Documents and Settings%\ 当前用户文档根目录
|