该病毒会在磁盘中释放出文件,会修改注册表。
在磁盘中释放出以下文件:
C:DOCUME~1SANDBOXLocal SettingsTemporary Internet Files
Application DataMicrosoftOffice
会从以下注册表中读取信息:
"HKCUSoftwareBorlandLocales"
"HKCUSoftwareBorlandDelphiLocales"
"HKCR.key"
"HKLMSoftwareClassesCLSID{F9BA1AA9-CAD4-4C14-BDE6-922DFF5F6F38}"
病毒会连接作者指定的网址:
http://hq-pharma.org/manda.php?id=1094245954&t=335117&v=wwg&p=16028
域名:"hq-pharma.org" 端口:80 (TCP)
hq-pharma.org/manda.php?id=1094245954&t=335117&v=wwg&p=16028