Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aspnet_states] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\DSLserverorm] 'Start' = '00000002'
- '%TEMP%\100.exe'
- '<SYSTEM32>\kkwgks.exe'
- '%TEMP%\vip.exe'
- '<SYSTEM32>\nannaa.exe'
- '<SYSTEM32>\taskkill.exe' /f /t /im <Имя вируса>.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\\up.bat
- <SYSTEM32>\kkwgks.exe
- %TEMP%\up.bat
- <SYSTEM32>\nannaa.exe
- %TEMP%\vip.exe
- %TEMP%\100.exe
- %TEMP%\100.exe в %TEMP%\SOFTWARE.LOG
- 'co####.api.css361.com':80
- 'ge###.api520.com':1001
- 'cc.##i520.com':1002
- co####.api.css361.com/m4a1/wb/update.txt
- DNS ASK co####.api.css361.com
- DNS ASK ge###.api520.com
- DNS ASK cc.##i520.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''