Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\apppatch\vcdgqip.dat,'
- <SYSTEM32>\netsh.exe firewall set allowedprogram \??\<SYSTEM32>\winlogon.exe ENABLE
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\spoolsv.exe
- opera.exe
- ClassName: 'AVP.MainWindow' WindowName: ''
- %WINDIR%\Temp\430A.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\news[1].htm
- %WINDIR%\Temp\483A.tmp
- %TEMP%\esp46FA.tmp
- %WINDIR%\AppPatch\vcdgqip.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\home[1].htm
- %WINDIR%\Temp\483A.tmp
- %WINDIR%\Temp\430A.tmp
- %TEMP%\esp46FA.tmp
- из <Полный путь к вирусу> в %TEMP%\1.tmp
- 'sm###lessly.com':80
- '74.##5.232.51':80
- sm###lessly.com/news.php
- sm###lessly.com/home.php
- DNS ASK sm###lessly.com
- DNS ASK google.com
- '<IP-адрес в локальной сети>':1035
- '<IP-адрес в локальной сети>':1034
- ClassName: '' WindowName: 'Kaspersky Virus Removal Tool 2010'
- ClassName: 'Malwarebytes' WindowName: 'ThunderRT6FormDC'
- ClassName: 'OSAM: Autorun Manager' WindowName: '#32770'
- ClassName: '' WindowName: '???????????? ??????? AVZ'
- ClassName: '' WindowName: 'random'
- ClassName: 'ThunderRT6FormDC' WindowName: ''