Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\EFS] 'Start' = '00000002'
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EPUHelp.exe
- '<SYSTEM32>\efsui.exe' /efs /keybackup
- '<SYSTEM32>\taskhost.exe'
- C:\System Volume Information\EFS0.LOG
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EFS0.TMP
- %APPDATA%\Roaming\Microsoft\SystemCertificates\My\Certificates\DECEBD63AE2F2876C0349CDA2B79287EB26A5F68
- %TEMP%\a17119.tmp
- %APPDATA%\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3525224950-2885160813-905547259-1000\eecd6d3328943c05e8b7b10c7477e491_fdaad129-04df-4089-bb80-174ce725f721
- C:\System Volume Information\EFS0.LOG
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EFS0.TMP
- %TEMP%\a17119.tmp в %APPDATA%\Roaming\Adobe\acupx217.dll
- из <Полный путь к вирусу> в %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EPUHelp.exe
- 'aa#####oaseseuke.org':80
- '74.##5.232.51':80
- 74.##5.232.51/
- aa#####oaseseuke.org/
- DNS ASK 1.###.##1.111.in-addr.arpa
- DNS ASK aa#####oaseseuke.org
- DNS ASK www.google.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'