Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Processus hote pour les services Windows' = '%APPDATA%\sys32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'q16I68zT' = '%HOMEPATH%\v92R74oE\svchost.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %APPDATA%\imlgs\11-06-2014
- %APPDATA%\sys32\svchost.exe
- %APPDATA%\install.imp
- %HOMEPATH%\b30Q98xM.txt
- %TEMP%\aut1.tmp
- %HOMEPATH%\p94H69fQ.AI2
- C:\<Имя вируса>.exe
- %HOMEPATH%\b30Q98xM.txt
- %HOMEPATH%\p94H69fQ.AI2
- %TEMP%\aut1.tmp
- 'ki######urgy22.no-ip.biz':4547
- DNS ASK ki######urgy22.no-ip.biz
- ClassName: 'Indicator' WindowName: '(null)'