Viking variants Solution
This variant has not been killed by Jiang Min and Kaba, and I used a few special kills to find a EXE file that can be detected and repaired!
After the virus runs, access the network to download multiple * programs (,,,,,,,,) and run them! Generate the following virus files (I feel that the current virus is really perverted):
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Program Files\Internet Explorer\
C:\Program Files\Internet Explorer\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\uninstall\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\
Add registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Soft\DownloadWWW
auto="1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Process Files
load="C:\windows\uninstall\"
wos3="C:\windows\"
ztsa="C:\DOCUME~1\your username\LOCALS~1\Temp\"
rxsa="C:\DOCUME~1\your username\LOCALS~1\Temp\"
mhsa="C:\DOCUME~1\your username\LOCALS~1\Temp\"
wls3="C:\windows\"
mysa="C:\DOCUME~1\admin\LOCALS~1\Temp\"
wgs3="C:\windows\"
wms3="C:\windows\"
jts3="C:\windows\"
qqs3="C:\windows\"
And infect all .exe files except system files, with a size of 72418 bytes!
This variant has not been killed by Jiang Min and Kaba, and I used a few special kills to find a EXE file that can be detected and repaired!
After the virus runs, access the network to download multiple * programs (,,,,,,,,) and run them! Generate the following virus files (I feel that the current virus is really perverted):
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Documents and Settings\your username\Local Settings\Temp\
C:\Program Files\Internet Explorer\
C:\Program Files\Internet Explorer\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\uninstall\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\
C:\WINDOWS\
Add registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Soft\DownloadWWW
auto="1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Process Files
load="C:\windows\uninstall\"
wos3="C:\windows\"
ztsa="C:\DOCUME~1\your username\LOCALS~1\Temp\"
rxsa="C:\DOCUME~1\your username\LOCALS~1\Temp\"
mhsa="C:\DOCUME~1\your username\LOCALS~1\Temp\"
wls3="C:\windows\"
mysa="C:\DOCUME~1\admin\LOCALS~1\Temp\"
wgs3="C:\windows\"
wms3="C:\windows\"
jts3="C:\windows\"
qqs3="C:\windows\"
And infect all .exe files except system files, with a size of 72418 bytes!