 This variant, computer system intrusion infections will own copied to the specified directory of the system. Meanwhile, the variety of copying themselves to the system of each disk partition, adding root directory

automatically run the configuration file (autorun. J inf), allows computer users in the open every disk partition will also run automatically Trojan variant program. In addition, this variant will through the modification system registry startup item with the computer system, makes the Trojan boot automatic operation.


In addition, this variant infect computer system in the script, the script's last to add some malicious Web Web addresses. Once the computer users click on open infected script file, it will download other viruses infect computers system again scripts.

cas network connecting active visit specified in the Web server, download other trojans, viruses and other malicious programs, eventually making infected computer system into the "zombie" network.

If malicious attacker using this variant remote control infected computers, an attacker can through records user some operating keyboard and mouse to steal some of the user's system, and will steal confidential information to the information to designated server.


Expert proposal, to have infected the varieties of computer users should immediately upgrade system of anti-virus software, carries on the comprehensive antivirus. Uninfected this variant of

users to open system anti-virus software "system monitoring" function, and from the registry, system process, memory, network and so on various perspectives on various operation active defense, so can the first time monitoring unknown viruses intrusion activities.