When W32.HLLW.Bodiru is executed, it performs the following actions:
1. Attempts to copy itself as the following files:
* C:\W32.rudeboi.exe
* A:\Home Work.doc.pif
* C:\Norton Anitivirus 2004.exe
* C:\Rude Boi(Full Screen Saver).scr
* C:\Windows\System\Windows Tools.exe
* C:\Windows\System\W32.rudeboi.exe
* C:\WINNT\System32\Windows Tools.exe
* C:\WINNT\System32\W32.rudeboi.exe
* C:\Windows\System32\Darkness_Krew (OWnZ ya).exe
* C:\Windows\System\Live
update.pif
* C:\WINNT\System32\Windows Update.exe
* C:\Windows\System32\Windows Update.pif
* C:\Win98\Start menu\Programs\Startup\Windows Update.exe
* C:\Win95\Start menu\Programs\Startup\Config.pif
* C:\WinMe\Start menu\Programs\Startup\System.scr
* C:\Windows\Start menu\Programs\Startup\Help.exe
* C:\Documents and Settings\All Users\Start menu\Programs\Startup\Windows Update.exe
* C:\Documents and Settings\Administrator\Start menu\Programs\Startup\Config.pif
* C:\Documents and Settings\Default User\Start menu\Programs\Startup\Windows Update.exe
* C:\WINNT\Profiles\All Users\Start menu\Programs\Startup\windows Update.exe
* C:\WINNT\Profiles\Administrator\Start menu\Programs\Startup\windows Update.exe
In each case, the attempt will fail if the folder does not exist.
Lesezeichen