Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\apppatch\qzbealb.dat,'
- <SYSTEM32>\netsh.exe firewall set allowedprogram \??\<SYSTEM32>\winlogon.exe ENABLE
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\spoolsv.exe
- opera.exe
- ClassName: 'AVP.MainWindow' WindowName: ''
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\home[1].htm
- %WINDIR%\Temp\2FC0.tmp
- %TEMP%\espC382.tmp
- %WINDIR%\AppPatch\qzbealb.dat
- %WINDIR%\Temp\2FC0.tmp
- %TEMP%\espC382.tmp
- из <Полный путь к вирусу> в %TEMP%\1.tmp
- '74.##5.232.51':80
- 'me###alpinx.com':80
- me###alpinx.com/news.php
- me###alpinx.com/home.php
- DNS ASK google.com
- DNS ASK me###alpinx.com
- '<IP-адрес в локальной сети>':1034
- '<IP-адрес в локальной сети>':1035
- ClassName: '' WindowName: 'Kaspersky Virus Removal Tool 2010'
- ClassName: 'Malwarebytes' WindowName: 'ThunderRT6FormDC'
- ClassName: 'OSAM: Autorun Manager' WindowName: '#32770'
- ClassName: '' WindowName: '???????????? ??????? AVZ'
- ClassName: '' WindowName: 'random'
- ClassName: 'ThunderRT6FormDC' WindowName: ''