Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\aura.bmp
- %HOMEPATH%\Start Menu\Programs\Startup\<Имя вируса>.exe
- '<SYSTEM32>\cmd.exe' /c cleen.bat
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- %APPDATA%\aura.bmp
- <Текущая директория>\cleen.bat
- %ALLUSERSPROFILE%\Application Data\TEMP\RAIDTest
- %TEMP%\C96A7062.TMP
- 'www.de####tindia.com':80
- www.de####tindia.com/close/script.php
- DNS ASK www.de####tindia.com