Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RSA2296801295' = '<SYSTEM32>\rundll32.exe "%APPDATA%\Microsoft\Crypto\RSA\RSA2296801295.dll",DllInitialize'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BackUp2296801295' = '%APPDATA%\BackUp2296801295.exe'
- '%TEMP%\tmp1.tmp.exe' -q -n "<SYSTEM32>\BOOT.dat" 256000
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\cmd.exe' /C del "<Полный путь к вирусу>"
- '<SYSTEM32>\rundll32.exe' "%APPDATA%\Microsoft\Crypto\RSA\RSA2296801295.dll",DllInitialize
- <SYSTEM32>\svchost.exe
- %APPDATA%\Microsoft\Crypto\RSA\RSA2296801295.dll
- <SYSTEM32>\BOOT.dat
- %TEMP%\tmp1.tmp.exe
- %TEMP%\NTFS.sys
- %APPDATA%\BackUp2296801295.exe
- %TEMP%\tmp1.tmp.exe
- %TEMP%\NTFS.sys
- 'fo###tnice.com':80
- http://fo###tnice.com/login.asp
- DNS ASK fo###tnice.com
- ClassName: 'Indicator' WindowName: ''