|
本地行为:
1、病毒件运行后会衍生以下文件:
%WinDir%\112.exe 20,480 字节
%WinDir%\121.exe 25,088 字节
%WinDir%\123.exe 22,993 字节
%WinDir%\444.exe 234,496 字节
%WinDir%\817.exe 143,360 字节
%WinDir%\concmd.dll 4,096 字节
%WinDir%\netcom.dll 237 字节
%System32%\449.exe 13,878 字节
%WinDir%\Temp\~myC.tmp 176,128 字节
%System32%\dirvers\2dfgbu9.sys 17,664 字节
%System32%\dirvers\acpidisk.sys 199,268 字节
%System32%\dirvers\mjaife1jj.sys 20,352 字节
%Temp%\install.exe
2、新增注册表:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: " Description "
字符串:" Network Connections Management "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: " DisplayName "
字符串:"Windows Accounts Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: "ImagePath "
字符串:" C:\WINDOWS\System32\449.exe "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mjaife1jj\]
注册表值: " DisplayName "
字符串:"mjaife1jj"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: "ImagePath "
字符串:" C:\WINDOWS\System32\drivers\mjaife1jj.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: " DisplayName "
字符串:"acpidisk"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: "ImagePath "
字符串:" C:\WINDOWS\System32\drivers\acpidisk.sys "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: "2dfgbu9System Bus Extender"
字符串:"acpidisk"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windows_0\]
注册表值: "ImagePath "
字符串: " C:\WINDOWS\System32\drivers\2dfgbu9.sys"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\]
注册表值: " MSetup "
字符串: " %Temp%\install.exe "
3、修改注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows NT\CurrentVersion\Winlogon\Userinit]
新建键值:字串:" C:\WINDOWS\system32
\userinit.exe,c:\WINDOWS\病毒副本名.exe "
原键值:字串:""C:\WINDOWS\system32\userinit.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Explorer\Advanced\Folder\Hidden
\SHOWALL\CheckedValue]
新建键值:字串:" 0"
原键值:字串:""1"
类型:DWORD
[HKEY_USERS\.DEFAULT\Software\Microsoft
\Windows\CurrentVersion\Explorer\Shell Folders\Cache]
新建键值:字串:"C:\Documents and Settings
\当前用户名\Local Settings\Temporary Internet Files"
原键值:字串:"C:\WINDOWS\system32\config\systemprofile
\Local Settings\Temporary Internet Files "
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows
\CurrentVersion\Explorer\Shell Folders\Cache]
新建键值:字串:"C:\Documents and Settings\当前用户名\Cookies"
原键值:字串:"C:\WINDOWS\system32\config\systemprofile\Cookies"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows
\CurrentVersion\Explorer\Shell Folders\History]
新建键值:字串:"C:\Documents and Settings\当前用户名
\Local Settings\History"
原键值:字串:"C:\WINDOWS\system32\config\systemprofile
\Local Settings\History "
4、删除注册表键值
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
注册表值:" MSConfig "
类型:Stirng
字符串:" C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto "
网络行为:
1、连接目标主机:
协议:TCP
域名或IP地址:
218.61.15.**端口: 7000
218.61.19.***端口: 7000
61.176.194.***端口: 7000
61.176.204.***端口: 7000
61.176.22.2.***端口: 7000
2、连接地址cha.onniro.cn(221.8.74.***)/text/****.txt病毒下载地址继而下载病毒体:
协议:TCP
端口:80
http://www.qqxi***ng.cn/svchost.exe
http://www.51**t.com/haohao.exe
http://huimie.xi**.net/qqqyyy.exe
http://www.jzm***.com(61.176.195.***)/m/xy.exe
http://www.48**.com(221.8.74.***)/rar/my_70136.rar
http://qqqyyy2.33**.org(218.61.18.**)/Server.exe
http://www.ad99**.com(218.61.18.**)/qqqyyy.exe
http://www.48**.com(221.8.74.***)/rar/socvher.rar
http://www.4***.com/rar/my_70136.rar
http://www.tud***.net(222.169.224.**)/ad/bd2.rar
http://www.tud***.net(222.169.224.**)/ad/bd4.rar
http://www.tud***.net(222.169.224.**)/ad/bd6.rar
http://www.tud***.net(222.169.224.**)/ad/bd8.rar
注: %Windir% WINDODWS所在目录
%DriveLetter% 逻辑驱动器根目录
%ProgramFiles% 系统程序默认安装目录
%HomeDrive% 当前启动的系统的所在分区
%Documents and Settings% 当前用户文档根目录
%Temp% \Documents and Settings
\当前用户\Local Settings\Temp
%System32% 系统的 System32文件夹
Windows2000/NT中默认的安装路径是C:\Winnt\System32
windows95/98/me中默认的安装路径是C:\Windows\System
windowsXP中默认的安装路径是C:\Windows\System32
|