1、文件运行后会释放以下文件
%Program Files%\DBS.EXE
2、创建注册表病毒服务项
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DBS_Server\Description
值: 字符串: "DBSRemote"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DBS_Server\DisplayName
值: 字符串: "DBS_Server"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DBS_Server\ImagePath
值: 字符串: "C:\Program Files\DBS.EXE."
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DBS_Server\Start
值: DWORD: 2 (0x2)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DBS_Server\Type
值: DWORD: 272 (0x110)
3、病毒运行后先解压释放并加载必要的资源信息包括(病毒的连网上线地址、端口、服务名):
"hackh****.3322.org|10|2|DBS.EXE|0|DBS_Server|DBSRemote|000000" |