%System32%\Program Files\Common Files\realteck\heoifz.pif
%system32%\5866250.OCX(文件名随机)
%Documents and Settings%\Administrator\Local Settings\Temporary Internet Files\Content.IE5\J1BAZ6S5\t[1].exe
%SystemRoot%\Temp\occ.ini
%Documents and Settings%\All Users\Documents\eck1.tmp
2.删除注册表
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths
\REGISTRY\USER\S-1-5-21-1220945662-2077806209-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ History
变量声明:
%System32% win32子系统文件目录, 通常为“C:\Windows\System32”
%SystemDriver% 系统所在分区,通常为“C:\”
%SystemRoot% WINDODWS所在目录,通常为“C:\Windows”
%Documents and Settings% 用户文档目录,通常为“C:\Documents and Settings”
%Temp% 临时文件夹,通常为“C:\Documents and Settings\当前用户名称\Local Settings\Temp”
%ProgramFiles% 系统程序默认安装目录,通常为:“C:\Program Files”作者: pioneer 时间: 2011-8-1 16:18 病毒分析:
%System32%\Program Files\Common Files\realteck\heoifz.pif
%system32%\5866250.OCX(文件名随机)
%Documents and Settings%\Administrator\Local Settings\Temporary Internet Files\Content.IE5\J1BAZ6S5\s[1].gif
%Documents and Settings%\Administrator\Local Settings\Temporary Internet Files\Content.IE5\J1BAZ6S5\t[1].exe
%SystemRoot%\Temp\occ.ini
%Documents and Settings%\All Users\Documents\eck1.tmp
病毒创建注册表:
\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths
= C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
\USER\S-1-5-21-1220945662-2077806209-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\ History =C:\Documents and Settings\Administrator\Local Settings\History
病毒删除文件:
%Documents and Settings%\Administrator\Local Settings\Temporary Internet Files\Content.IE5\J1BAZ6S5\s[1].gif