HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\mserv
键值: 字符串: "C:\Documents and Settings\ring\Application Data\svcst.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\svchost
键值: 字符串: "C:\Documents and Settings\ring\Application Data\svcst.exe"
描述:添加注册表开机启动项
4、衍生病毒文件并将自身拷贝到以下目录内:
%Documents and Settings%\Administrator\Application Data\seres.exe
%Documents and Settings%\Administrator\Application Data\svcst.exe
%Documents and Settings%\Administrator\Application Data\lizkavd.exe