1、生成的文件,并将病毒文件设置属性为隐藏
%DOCUME~1%\ADMINI~1\LOCALS~1\Temp\E_4\krnln.fnr
%DOCUME~1%\ADMINI~1\LOCALS~1\Temp\E_4\shell.fne
%Documents and Settings%\administrator\「开始」菜单\程序\启动\svchost.com
%Documents and Settings%\administrator\Application Data\Microsoft\win1ogon.exe
%Documents and Settings%\administrator\桌面\警告.h
2、添加启动项
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"svchost.exe" = "%Documents and Settings%\administrator\Application Data\Microsoft\win1ogon.exe"
3、修改txt文件关联
HKCR\txtfile\shell\open\command
"(Default)" = "%Documents and Settings%\administrator\Application Data\Microsoft\win1ogon.exe"