此毒为一个远程木马。它拥有较多的变种,运行后能帮助黑客对用户电脑进行远程控制。
在磁盘中释放出以下文件:
C:\Documents and Settings\All Users\zyndf16.ini
C:\WINDOWS\SYSTEM\zyndle080922.exe
C:\WINDOWS\SYSTEM\zyndld32080922.dll
C:\WINDOWS\SYSTEM\zyndld32080922jt.dll
在磁盘中删除了以下文件:
C:\WINDOWS\SYSTEM\zyndld32080922jt.dll
会从以下注册表中读取信息:
"HKCU\Software\Borland\Locales"
"HKLM\Software\Borland\Locales"
"HKCU\Software\Borland\Delphi\Locales"
病毒会连接作者指定的网址:
域名:"n*.u*2.net" 端口:53 (IP)
域名:"www.ya*oo.com" 端口:80 (IP)
域名:"www.w*b.de" 端口:80 (IP)
域名:"FAKE" 端口:4660 (IP)
在磁盘中创建以下配置文件:
C:\Documents and Settings\All Users\zyndf16.ini [install] "Tick" "573491"
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "old_exe" ""
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "old_dll32" ""
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "old_dll32_ls" ""
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "ver" "080922"
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "fn_exe" "C:\WINDOWS\SYSTEM\zyndle080922.exe"
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "regstart" "nmzy_df"
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "fn_dll" "C:\WINDOWS\SYSTEM\zyndld32080922.dll"
C:\Documents and Settings\All Users\zyndf16.ini [mydown] "fn_dll_ls" "C:\WINDOWS\SYSTEM\zyndld32080922jt.dll"