Recently, many people have known this "animal" virus. It is called the "animal" virus because after the virus runs, in the folder option, the text of the hidden file is changed to "the animal is still a little pity, and I have no, so I am not a beast."
This virus is actually the original niu.exe variant, but this variant has greatly increased many new "functions", and the system will be completely unprotected with the help of animal viruses and other Trojans. there is almost no chance of saving the system without any tools
The virus has the following guilt:
1. Disable some system self-protection functions (automatic update, firewall, etc.) in security mode)
2. IFEO image hijacking anti-virus software and common security tools
3. Disable Task Manager
4. Modify the Home Page
5. Close the window with the words "Antivirus"
6. Infected html and other webpage files
7. Delete the gho file so that the user cannot restore the system
8. USB flash drive
9. Download a variety of Trojans and rogue software (up to 20 Trojans)
The following is a detailed analysis of viruses.
1. Release the following files:
% System32 % \ crsss.exe
Autorun. inf and niu.exe are generated under each partition.
2.call reg.exe to perform the following operations:
Add your own startup project
Add hklm \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/V crsss/T REG_SZ/D
Disable windows automatic update
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ WindowsUpdate/v DisableWindowsUpdateAccess/t REG_dword/d 00000001/f
Disable Task Manager
Add HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System/v DisableTaskMgr/t REG_dword/d 00000001/f
Damage the hidden file and change the option name to "the animal is still a little pity, and I have no,
So I am not an animal"
Delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ SHOWALL/f
Add HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ NOHIDDEN/v Text/t REG_SZ/d animals have a little pity, but I have no, so I am not an animal. /f
Sabotage Security Mode
Delete HKLM \ SYSTEM \ ControlSet001 \ Control \ SafeBoot \ Minimal \ {4D36E967-E325-11CE-BFC1-08002BE10318}/f
Delete HKLM \ SYSTEM \ ControlSet001 \ Control \ SafeBoot \ Network \ {4D36E967-E325-11CE-BFC1-08002BE10318}/f
Delete HKLM \ SYSTEM \ CurrentControlSet \ Control \ SafeBoot \ Minimal \ {4D36E967-E325-11CE-BFC1-08002BE10318}/f
Delete HKLM \ SYSTEM \ CurrentControlSet \ Control \ SafeBoot \ Network \ {4D36E967-E325-11CE-BFC1-08002BE10318}/f
3. Add the following Image hijacking project to HKLM \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Image File Execution Options \ to point to % system32 % \ crsss.exe (limited space, only textures)