|
1、衍生下列副本与文件
%Program Files%\CNNIC
%Program Files%\CNNIC\Cdn\Images\
%Program Files%\CNNIC\Cdn\Update\
%Program Files%\CNNIC\Cdn\cdnaux.dll
%Program Files%\CNNIC\Cdn\cdnforie.dll
%Program Files%\CNNIC\Cdn\cdnprh.dll
%Program Files%\CNNIC\Cdn\cdnunins.exe
%Program Files%\CNNIC\Cdn\cdnup.exe
%Program Files%\CNNIC\Cdn\idnconvs.dll
%Program Files%\CNNIC\Cdn\cdnvers.dat
%Program Files%\CNNIC\Cdn\src.dat
%WINDOWS\system32%\cdndisp.tmp
%WINDOWS\system32%\cdnns.dll
%WINDOWS\system32%\cdnprot.dat
%WINDOWS\system32\drivers%\cdnprot.sys
2、下载文件列表
%Documents and Settings\用户名\Local Settings\Temp\%1C
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdn.dll
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdnaux.dll
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdnforie.dll
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdnins.dll
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdnprh.dll
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdnprot.dat
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdnprot.sys
%Documents and Settings\用户名\Local Settings\Temp\%1C\idnconvs.dll
%Documents and Settings\用户名\Local Settings\Temp\%1C\setup.exe
%Documents and Settings\用户名\Local Settings\Temp\%1C\cdnup.exe
2、新建注册表键值:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run\CdnCtr键值: 字符串:"%ProgramFiles%\CNNIC\Cdn\cdnup.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion
\Explorer\Browser Helper Objects键值: 字符串: “%programfiles%\cnnic\cdn\cdnforie.dll”
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
\cdnprot\DescriptionName键值: 字符串: "cdnprot"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdnprot\ImagePath
键值: 类型: REG_EXPAND_SZ 长度: 29 (0x1d) 字节system32\drivers\cdnprot.sys.
3、连接下列网址
update.*****.cn(***.208.170.72)
jump.*****.cn:80(***.241.97.33)
注:% System%是一个可变路径。病毒通过查询操作系统来决定当前System文件夹的位置。Windows2000/NT中默认的安装路径是C:\Winnt\System32,windows95/98/me中默认的安装路径是C:\Windows\System,windowsXP中默认的安装路径是C:\Windows\System32。
|