Note:Win95/98/me default %system% is C:\windows\system
WinNT/2000/XP/2003 default %system% is C:\WinNT\system32
●After executing virus, it will create following files to %System% folder:
sdra64.exe
●Add the following files:
C:\WINDOWS\system32\lowsec\local.ds
C:\WINDOWS\system32\lowsec\user.ds
C:\WINDOWS\system32\lowsec\user.ds.lll
●Add following value to the registry. The virus will run while Windows starting.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
CurrentVersion\Winlogon\Userinit: "C:\WINDOWS\system32\userinit.exe,
C:\WINDOWS\system32\sdra64.exe,"
|