upside
反病毒 反诈骗 反虐犬
|
分享:
x0
|
[病毒蠕虫] Email-Worm.Win32.Brontok.q
Email-Worm.Win32.Brontok.q
在登录档中加入的键值(让病毒自动执行并锁定登录): [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"="1" "DisableCMD"="0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Hidden"="0" "HideFileExt"="1" "ShowSuperHidden"="0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"="1"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "Bron-Spizaetus"="" "Bron-Spizaetus-<random symbols>"="%WinDir%\ShellNew\bbm-<random symbols>.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "Tok-Cirrhatus"="" "Tok-Cirrhatus-<random number>"="%UserProfile%\Local Settings\Application Data\br<random number>on .exe"
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="Explorer.exe "%WinDir%\sembako-<random symbols>.exe""
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot] "AlternateShell"="cmd-bro-<random symbols>.exe"
病毒还会复制以下档案到磁碟上: %UserProfile%\Local Settings\Application Data\br<random number>on.exe %UserProfile%\Local Settings\Application Data\csrss.exe %UserProfile%\Local Settings\Application Data\inetinfo.exe %UserProfile%\Local Settings\Application Data\lsass.exe %UserProfile%\Local Settings\Application Data\services.exe %UserProfile%\Local Settings\Application Data\smss.exe %UserProfile%\Local Settings\Application Data\svchost.exe %UserProfile%\Local Settings\Application Data\winlogon.exe 同一资料夹下的文字档 Kosong.Bron.Tok.txt
%WinDir%\sembako-<随机字串>.exe %WinDir%\ShellNew\bbm-<随机字串>.exe %System%\DXBLBO.exe %System%\cmd-bro-<随机字串>.exe %System%\%UserName%'s Setting.scr
%UserProfile%\%Autorun%\Empty.pif %UserProfile%\Templates\<random number>-NendangBro.com %MyPictures%\Mypictures.exe %MyPictures%\about.Brontok.A.html
病毒还会在系统资料夹下新增档案sistem.sys,记录中毒的资料和时间
|