1、文件运行后会释放以下文件
%System32%\System64.exe
2、创建注册表病毒服务项
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WindowsMSG\Description
值: 字符串: "This Is Windows MSG Manager"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WindowsMSG\DisplayName
值: 字符串: "WindowsMSG"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WindowsMSG\ImagePath
值: 字符串: "C:\WINDOWS\system32\System64.exe."
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WindowsMSG\Start
值: DWORD: 2 (0x2)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WindowsMSG\Type
值: DWORD: 272 (0x110)
3、病毒运行后先解压释放并加载必要的资源信息包括(病毒的连网上线地址、端口、服务名):
"nbxmm.3322.org|2009|60|WindowsMSG|WindowsMSG|This Is Windows MSG Manager|1|1|DRAT2009|nbdmm|" |