Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RSA2296801295' = '<SYSTEM32>\rundll32.exe "%APPDATA%\Microsoft\Crypto\RSA\RSA2296801295.dll",DllInitialize'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BackUp2296801295' = '%APPDATA%\BackUp2296801295.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\BS2296801295] 'ImagePath' = '%TEMP%\NTFS.sys'
- '<SYSTEM32>\cmd.exe' /C del "<Полный путь к файлу>"
- '<SYSTEM32>\svchost.exe'
- '%TEMP%\tmp1.tmp.exe' -q -n "<SYSTEM32>\BOOT.dat" 256000
- '<SYSTEM32>\rundll32.exe' "%APPDATA%\Microsoft\Crypto\RSA\RSA2296801295.dll",DllInitialize
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\BOOT.dat
- %APPDATA%\Microsoft\Crypto\RSA\RSA2296801295.dll
- %TEMP%\tmp1.tmp.exe
- %TEMP%\NTFS.sys
- %APPDATA%\BackUp2296801295.exe
- %TEMP%\tmp1.tmp.exe
- %TEMP%\NTFS.sys
- 'me###vvads.uk':80
- http://me###vvads.uk/host.dat
- DNS ASK me###vvads.uk