KAVO 另一新毒 mkfght 20090120
生成物
c:\autorun.inf
c:\u26ufgv.exe %System%\rttrwq.exe
%System%\mkfght0.dll
%System%\mkfght2.dll
新进程
rttrwq.exe %System%\rttrwq.exe
调用进程
mkfght2.dll %System%\mkfght2.dll Process name: explorer.exe
mkfght0.dll %System%\mkfght0.dll Process name: dllhost.exe
mkfght0.dll %System%\mkfght0.dll Process name: IEXPLORE.EXE
增加新注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
ertyuop = "%System%\rttrwq.exe"
修改注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
CheckedValue = 0x00000000
木马下载器
http://dqdq2.co...c.rar %Temp%\cc.rar