●1.Spread through USB Flash or USB drive
●2.Infecte files after executing
●3.Open UDP 5703 Port
●Spread through USB Flash or USB drive
●create the files in USB Flash or USB drive:
[RANDOM NAME].exe
[RANDOM NAME].cmd
[RANDOM NAME].pif
●Modify the following registry file, it will change user:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\
EnableLUA=0x00000000
●Infected the files:
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\Microsoft Office\Office10\OSA.EXE
..................
●Open UDP 5703 Port.
|