Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AGF Start' = '<SYSTEM32>\RIBYAI\AGF.exe'
- <LS_APPDATA>\Xenocode\Sandbox\AMMY\2...2.7\2012.08.12T04.46\Native\STUBEXE\@PROFILE@\Local Settings\Temp\AA_v3.exe
- <LS_APPDATA>\Xenocode\Sandbox\AMMY\2...2.7\2012.08.12T04.46\Native\STUBEXE\@SYSTEM@\RIBYAI\AGF.exe
- <LS_APPDATA>\Xenocode\Sandbox\AMMY\2...2.7\2012.08.12T04.46\Virtual\STUBEXE\@APPDIR@\AA_v2.7.exe
- <LS_APPDATA>\Xenocode\Sandbox\AMMY\2...2.7\2012.08.12T04.46\Native\STUBEXE\@PROFILE@\Local Settings\Temp\SYS.exe
- Библиотека-обработчик для всех процессов: <SYSTEM32>\RIBYAI\AGF.001
- <SYSTEM32>\RIBYAI\AKV.exe
- <SYSTEM32>\RIBYAI\AGF.002
- %ALLUSERSPROFILE%\Application Data\AMMYY\hr
- %ALLUSERSPROFILE%\Application Data\AMMYY\settings3.bin
- %ALLUSERSPROFILE%\Application Data\AMMYY\hr3
- <SYSTEM32>\RIBYAI\AGF.001
- %TEMP%\SYS.exe
- %TEMP%\AA_v3.exe
- <SYSTEM32>\RIBYAI\AGF.004
- <SYSTEM32>\RIBYAI\AGF.exe
- 'rl.##myy.com':80
- rl.##myy.com/
- DNS ASK rl.##myy.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'AmmyyAdmin3Main' WindowName: ''
- ClassName: '' WindowName: 'AKLMW'