|
本地行为:
1、文件运行后会衍生副本:
%WinDir%\New-Year2008-imgaes.zip
%WinDir%\msmsgrsu.exe
2、新增注册表:
HKEY_LOCAL_MACHINE\SOFTWARE
\Microsoft\Windows\CurrentVersion\Run\
键值:MsnLiveMessenger
字符串: "msmsgrsu.exe"
3、随机选取文本信息以诱使联系人接收病毒体,病毒体内的字符序列如下:
"Heeey :) <3 Check out theese New year p"...
"Happy new year xD! :D see"
"New year + Christmas pictures! :D"
"you gotta see this, me in my noughty sa"...
"Hey, have u seen these Christmas images"...
"Check theese out, Christmas + New year!"...
'Check theese out, Christmas + New year!',0
'Hey, have u seen these Christmas images?',0
'you gotta see this, me in my noughty santa suit!! :P',0
'New year + Christmas pictures! :D',0
'Happy new year xD! :D see',0 ;
'Heeey :) <3 Check out theese New year photos!',
'\New-Year2008-imgaes.zip'
4、连接的IRC服务器名称:
secure.bindshell.info
注: %System32% 是一个可变路径。病毒通过查询操作系统来决定当前 System文件夹的
位置。
%Windir% WINDODWS所在目录
%DriveLetter% 逻辑驱动器根目录
%ProgramFiles% 系统程序默认安装目录
%HomeDrive% 当前启动的系统的所在分区
%Documents and Settings% 当前用户文档根目录
%Temp% \Documents and Settings
\当前用户\Local Settings\Temp
%System32% 系统的 System32文件夹
Windows2000/NT中默认的安装路径是C:\Winnt\System32
windows95/98/me中默认的安装路径是C:\Windows\System
windowsXP中默认的安装路径是C:\Windows\System32
|