Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Defender' = '"%WINDIR%\lsassr.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Skype' = '"%PROGRAM_FILES%\Skype\Phone\Skype.exe" /minimized /regrun'
- '%WINDIR%\winliv-15m.exe'
- '%WINDIR%\lsassr.exe'
- '%WINDIR%\svchbs-5m.exe'
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:1742194 "__IRAFN:<Полный путь к вирусу>" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-2052111302-484763869-725345543-1003"
- '%WINDIR%\onereal-9m.exe'
- '<SYSTEM32>\reg.exe' import svhot.reg
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\svhot.bat" "
- %WINDIR%\onereal-9m.exe
- %WINDIR%\winliv-15m.exe
- %WINDIR%\svchbs-5m.exe
- %WINDIR%\svhot.reg
- %WINDIR%\svhot.bat
- %WINDIR%\lsassr.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\lua5.1.dll
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\FlashPlayer Setup Log.txt
- %TEMP%\_ir_sf_temp_0\IRIMG2.JPG
- %TEMP%\_ir_sf_temp_0\IRIMG1.JPG
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\lua5.1.dll
- %TEMP%\_ir_sf_temp_0\IRIMG2.JPG
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\IRIMG1.JPG
- '12#.#17.251.175':8888
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'