Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Favoris.lnk
- '<SYSTEM32>\rundll32.exe' cryptext.dll,CryptExtAddCER c:\temp\certificat\cg48.fr-cacert.pem
- '<SYSTEM32>\net1.exe' user administrateur sicg48
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = '192.168.20.3:8080'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyOverride' = '192.168.*;*.local.cg48;*.local.fr;messagerie.cg48.fr;<local>;kokanee'
- C:\temp\certificat\cg48.fr-cacert.pem
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %WINDIR%\<Имя вируса>.exe
- C:\SI\FAVORIS2.3.OK
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %WINDIR%\<Имя вируса>.exe
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'