Note:Win95/98/me default %windir% is C:\windows
WinNT/2000/XP/2003 default %windir% is C:\Winnt
●1.It create malwares.
●2.It makes network not normal.
●After executing virus, it will create following files to %Windir% folder:
intersn.exe
●Modify the following registry file, it will execute when service start:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\
LEGACY_APPROPSREN\0000\Control\ActiveService: "AppropSren"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\
LEGACY_APPROPSREN\0000\Service: "AppropSren"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\
AppropSren\ImagePath: "C:\WINDOWS\intersn.exe"
|