该后门程序被执行后,创建一线程实现隐藏窗口类名为AVP.Product_Notification、AVP.TrafficMonConnectionTerm的窗口,并关闭窗口类名为Afx:400000:0的窗口;拷贝自身到C:\Documents and Settings\All Users.WINNT\Favorites,重命名为netservice.exe;在目录C:\Documents and Settings\All Users.WINNT\Favorites\plugin下释放动态库001.dll;在目录%systemroot%\system32下释放动态库sysns.dll;修改如下注册表健值使其随系统一起启动;
Quote:
项:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
健值:userinit
指向数据:%systemroot%\system32\userinit.exe,"C:\Documents and Settings\All Users.WINNT\Favorites\netservice.exe"un userinit.exe