Note:Win95/98/me default %system% is C:\windows\system
WinNT/2000/XP/2003 default %system% is C:\WinNT\system32
●If you visit a compromised Web server, it will auto-download virus file then
execute it.
●After executing virus, it will create following files to %System% folder:
ro.dll
●Modify the following registry file:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent\
: 0x00000012
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\
Epoch: 0x00000019
●Close the Windows firewall. |