Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdates' = '%WINDIR%\winupdatex.exe'
- '%WINDIR%\winupdatex.exe' <Полный путь к вирусу>
- '<SYSTEM32>\net1.exe' start sharedaccess
- '<SYSTEM32>\alg.exe'
- '<SYSTEM32>\net1.exe' stop sharedaccess
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v WindowsUpdates /t REG_SZ /d %WINDIR%\winupdatex.exe
- '<SYSTEM32>\net.exe' stop sharedaccess
- %TEMP%\%USERNAME%.txt
- %WINDIR%\winupdatex.exe
- %TEMP%\%USERNAME%.txt
- 'ft#.#bwarez.com':21
- DNS ASK ft#.#bwarez.com
- ClassName: 'MS_WINHELP' WindowName: '(null)'