Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Cleanup' = 'C:\cleanup.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Google Chrome' = '<Полный путь к файлу>'
- [<HKLM>\SYSTEM\ControlSet001\Services\uohrd] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\uohrd] 'ImagePath' = 'system32\drivers\nyqkhdq.sys'
- '%WINDIR%\regedit.exe' /e C:\1.reg "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gbpkm.sys"
- '%WINDIR%\regedit.exe' /e C:\2.reg "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gbpndisrd.sys"
- '%WINDIR%\regedit.exe' /e C:\3.reg "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gbpndisrd.sys"
- '<SYSTEM32>\cmd.exe' /k avenger.exe /nogui /reboot Log.txt
- '<Текущая директория>\avenger.exe' /nogui /reboot Log.txt
- '<SYSTEM32>\cmd.exe' /c ""C:\avexport.bat" "
- C:\cleanup.bat
- C:\zip.exe
- C:\avexport.bat
- C:\cleanup.exe
- <Текущая директория>\avenger.exe
- <Текущая директория>\Log.txt
- <DRIVERS>\nyqkhdq.sys
- C:\ldmuskoh.txt
- <Полный путь к файлу>
- 'www.co#####farmshop.co.uk':80
- http://www.co#####farmshop.co.uk/administrator/barata/index.php?ma######
- DNS ASK www.co#####farmshop.co.uk
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Notepad' WindowName: ''