Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\AodbeARMHelper.exe
- %HOMEPATH%\Start Menu\Programs\Startup\EFS0.TMP
- <Полный путь к вирусу>
- '<SYSTEM32>\services.exe'
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e041a3da5462a0d284bcd76eae3afe4a_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Microsoft\SystemCertificates\My\Certificates\4412A78D16E3B24BF72D34A6F6A135B61E59F3A7
- C:\System Volume Information\EFS0.LOG
- %TEMP%\a11.tmp
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\cac59cad-1a11-4029-993f-5c5d276b4f19
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- C:\System Volume Information\EFS0.LOG
- %HOMEPATH%\Start Menu\Programs\Startup\EFS0.TMP
- %TEMP%\a11.tmp в %APPDATA%\Adobe\AcorIEHelper.dll
- 'yw#####ywkuuyuye.org':80
- '74.##5.232.51':80
- 74.##5.232.51/
- yw#####ywkuuyuye.org/
- DNS ASK 1.###.##1.111.in-addr.arpa
- DNS ASK yw#####ywkuuyuye.org
- DNS ASK www.google.com