|
病毒生成的文件: %ProgramFiles%\Internet Explorer\Plugins\SysWin64.jmp %ProgramFiles%\Internet Explorer\Plugins\WinSys64.sys
病毒创建的注册表项: Key:HKEY_CLASSES_ROOT\CLSID\{5D83AD9C-3BFC-43F5-979D-
2904DBC54A8E}\InProcServer32 Value:"(默认)" Data:"%ProgramFiles%\Internet Explorer\Plugins\WinSys64.sys"
Key:HKEY_CURRENT_USER\Software\Tencent
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D83AD9C-3BFC- 43F5-979D-2904DBC54A8E}
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\ShellExecuteHooks Value:{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}
|