Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-BIFROST999999}] 'stubpath' = '<SYSTEM32>\dllcache\fudeu.exe s'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{43EB5254-E4B3-4E69-6484-8E4E2C23A78E}] 'StubPath' = '<Полный путь к вирусу>'
- [<HKLM>\SYSTEM\ControlSet001\Services\Oddysee] 'ImagePath' = '<SYSTEM32>\ntoskrnl.exe:kernel'
- '<SYSTEM32>\oddysee.exe' -rk Oddysee
- '<SYSTEM32>\oddysee.exe' -rk {C9E9A340-D1F1-11D0-821E-BIFROST999999}
- '<SYSTEM32>\oddysee.exe' -i
- '<SYSTEM32>\oddysee.exe' -pnm explorer.exe
- '<SYSTEM32>\net1.exe' start Oddysee
- '<SYSTEM32>\oddysee.exe' -pnm explorer.exe
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- '<SYSTEM32>\oddysee.exe' -rk {C9E9A340-D1F1-11D0-821E-BIFROST999999}
- '<SYSTEM32>\oddysee.exe' -rk Oddysee
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\net.exe' start Oddysee
- '<SYSTEM32>\oddysee.exe' -i
- %WINDIR%\explorer.exe
- NtQuerySystemInformation, драйвер-обработчик: kernel
- NtEnumerateValueKey, драйвер-обработчик: kernel
- NtEnumerateKey, драйвер-обработчик: kernel
- %WINDIR%\explorer.exe
- %ProgramFiles%\Internet Explorer\IEXPLORE.EXE
- <SYSTEM32>\ntoskrnl.exe:kernel
- <SYSTEM32>\dllcache\fudeu.exe
- <SYSTEM32>\dllcache\ntkrnlmp.exe.new
- <SYSTEM32>\oddysee.exe
- <SYSTEM32>\ssvschost.sys
- %APPDATA%\addon.dat
- %APPDATA%\addon.dat
- <SYSTEM32>\dllcache\fudeu.exe
- 'na#####nta3.no-ip.org':1201
- 'my#####og.dyndns.org':1201
- 'na#####nta1.no-ip.org':1201
- 'na#####nta2.no-ip.org':1201
- 'na#####nta1.no-ip.org':2201
- 'my#####og.dyndns.org':2201
- 'na#####nta3.no-ip.org':2201
- 'na#####nta2.no-ip.org':2201
- DNS ASK na#####nta2.no-ip.org
- DNS ASK na#####nta3.no-ip.org
- DNS ASK my#####og.dyndns.org
- DNS ASK na#####nta1.no-ip.org