|
1 、衍生下列副本与文件:
%C:%\autorun.inf
%C:%\rising.exe
%WinDir%\cmdbs.exe
%WinDir%\macfee.exe
%WinDir%\mppds.exe
%WinDir%\msccrt.exe
%WinDir%\testexe.exe
%WinDir%\winform.exe
%System32%\6D52D174.EXE
%System32%\B0B2C20E.DLL
%System32%\B0B2C20E.EXE
%System32%\cmdbs.dll
%System32%\macfee.dll
%System32%\mppds.dll
%System32%\msccrt.dll
%System32%\testdll.dll
%System32%\winform.dll
2 、新建注册表键值:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmdbs
Value: String: "%WINDIR%\cmdbs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\macfee
Value: String: "%WINDIR%\macfee.exe /i"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mppds\
Value: String: "%WINDIR%\mppds.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msccrt
Value: String: "%WINDIR%\msccrt.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\testrun
Value: String: "%WINDIR%\testexe.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\upxdnd
Value: String: "%DOCUME~1%\ 当前用户名 \LOCALS~1\Temp\upxdnd.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winForm
Value: String: "%WINDIR%\winform.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\sgktiq98kfb8xz
Value: String: "%\DOCUME~1%\antiy\LOCALS~1\Temp\c0nime.exe"
3 、访问下列地址获取要更新的病毒体地址:
(2*2.7*.2*0.*5) n*.5*yl*.cn /soft//update.txt
(6*.1*2.9*.9*)p*pw*n.9*8*.com /update.txt
注: % System% 是一个可变路径。病毒通过查询操作系统来决定当前 System 文件夹的位置。 Windows2000/NT 中默认的安装路径是 C:\Winnt\System32 , windows95/98/me 中默认的安装路径是 C:\Windows\System , windowsXP 中默认的安装路径是 C:\Windows\System32 。
|