Win32/Forbot.RZ是大小为86,977字节的Win32可运行程序,带有以下特征:
运行时,它复制"storm.exe"到%System%目录,并安装一个服务:
Service name: NDIS DIP Layer Transport Device
Display name: Microsoft Video Capture Controls
Path to executable: %System%\storm.exe -netsvcs
Startup type: Automatic
它还设置以下注册表键值,以确保在系统启动时运行病毒:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Video Capture Controls = "storm.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\Microsoft Video Capture Controls = "storm.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Video Capture Controls = "storm.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\Microsoft Video Capture Controls = "storm.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Video Capture Controls = "storm.exe"