|
1、病毒运行后复制自身到:%SYSTEM32%\anti_troj.exe
2、修改注册表文件,添加启动项:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run\anti_tro
键值: 字串: "C:\WINNT\System32\anti_troj.exe"
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion
\Run\anti_troj
键值: 字串: "C:\WINNT\System32\anti_troj.exe"
3、病毒第一次运行后会打开%system%\ntimage.gif,并在注册表文件中添加键值,表示该主机已经被感染:
HKEY_USERS\Software\FirstRRRun\FirstRRRun
键值: DWORD: 1 (0x1)
4、病毒尝试连接一些网站并且下载病到%WINDOWS%\exefld\< RANDOM NAME >.exe,而后运行。
http://www.bbrealservis.sk/mul.php
http://www.befag.ru/mul.php
http://www.benininfo.com/mul.php
http://www.bennylife.com/mul.php
http://www.bestcheapdomainregistration.info/mul.php
http://www.bidsforbaby.com/mul.php
http://www.binhaigolf.com/mul.php
http://www.biotenk.com/mul.php
http://www.bitsolution.ro/mul.php
http://www.nmtltd.com/mul.php
http://www.vnettools.com/mul.php
http://www.boldrussell.com/mul.php
http://www.bronko-m.ru/mul.php
http://www.bulkemailservicenow.com/mul.php
http://www.bulkemaildirectmarketing.com/mul.php
http://www.calidad.biz/mul.php
http://www.cansew.ca/mul.php
http://www.cansultdubai.ae/mul.php
http://www.casaquecanta.com/mul.php
http://www.chilotitomarino.cl/mul.php
http://www.chinaculturedpearl.com/mul.php
http://www.casino-malibu.ru/mul.php
http://www.colin18.com/mul.php
http://www.khonkaenpoc.com/mul.php
http://www.connectesl.com/mul.php
http://ala-bg.net/mul.php
http://allinfo.com.au/mul.php
http://eleceltek.com/mul.php
http://alevibirligi.ch/mul.php
http://alfaclassic.sk/mul.php
http://allanconi.it/mul.php
http://www.americarising.com/mul.php
http://americasenergyco.com/mul.php
http://amerykaameryka.com/mul.php
http://amistra.com/mul.php
http://analisisyconsultoria.com/mul.php
http://calamarco.com/mul.php
注:% System%是一个可变路径。病毒通过查询操作系统来决定当前System文件夹的位置。Windows2000/NT中默认的安装路径是C:\Winnt\System32,windows95/98/me中默认的安装路径是C:\Windows\System,windowsXP中默认的安装路径是C:\Windows\System32。
|