Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'Security Service' = 'service.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Security Service' = 'service.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~”ь' = 'DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~”ь:*:Enabled:Security Service'
- '<SYSTEM32>\service.exe' 316 "<Полный путь к вирусу>"
- '%WINDIR%\regedit.exe' /S %TEMP%\1.reg
- '<SYSTEM32>\cmd.exe' /c c:\a.bat
- <SYSTEM32>\service.exe
- %TEMP%\1.reg
- C:\a.bat
- <SYSTEM32>\service.exe
- %TEMP%\1.reg
- 'id###.hopto.org':1993
- DNS ASK id###.hopto.org
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'mIRC' WindowName: '(null)'