KAVO 另一新毒 mkfght 20090120
生成物
c:\autorun.inf
c:\u26ufgv.exe %System%\rttrwq.exe
%System%\mkfght0.dll
%System%\mkfght2.dll
新進程
rttrwq.exe %System%\rttrwq.exe
調用進程
mkfght2.dll %System%\mkfght2.dll Process name: explorer.exe
mkfght0.dll %System%\mkfght0.dll Process name: dllhost.exe
mkfght0.dll %System%\mkfght0.dll Process name: IEXPLORE.EXE
增加新註冊表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
ertyuop = "%System%\rttrwq.exe"
修改註冊表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
CheckedValue = 0x00000000
木馬下載器
http://dqdq2.co...c.rar %Temp%\cc.rar