Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Insreservics' = '%HOMEPATH%\Templates\Inerts.com'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winservices' = '%APPDATA%\svrhosts.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdates' = '%APPDATA%\svrhosts.exe'
- %APPDATA%\Foto-2Web1cd2a.jpg
- %APPDATA%\svchostinf1.dll
- %APPDATA%\Foto-1Scr1cd1a.jpg
- %APPDATA%\svrhosts.exe
- %HOMEPATH%\Templates\Inerts.com
- %HOMEPATH%\Templates\Inerts.com
- %APPDATA%\svrhosts.exe
- <Полный путь к вирусу>
- 'sm##.web.de':25
- DNS ASK sm##.web.de
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''