Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svehost' = '%HOMEPATH%\My Documents\MSDCE\svehost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = '<SYSTEM32>\userinit.exe,%HOMEPATH%\My Documents\MSDCE\svehost.exe'
- <SYSTEM32>\notepad.exe
- %HOMEPATH%\Templates\skyef.exe
- %HOMEPATH%\Templates\serv1.exe
- %HOMEPATH%\Templates\egsge.exe
- %HOMEPATH%\Templates\operhs.exe
- %HOMEPATH%\My Documents\MSDCE\svehost.exe
- %TEMP%\dw.log
- %TEMP%\2A445.dmp
- %HOMEPATH%\My Documents\MSDCE\svehost.exe
- %HOMEPATH%\Templates\skyef.exe
- 'wp#d':80
- 'ch####p.dyndns.org':80
- '17#.#4.17.18':1515
- http://11#.#11.111.1/wpad.dat via wp#d
- http://ch####p.dyndns.org/
- DNS ASK wp#d
- DNS ASK ch####p.dyndns.org
- '<Полный путь к файлу>'
- '%HOMEPATH%\Templates\skyef.exe'
- '%HOMEPATH%\Templates\serv1.exe'
- '%HOMEPATH%\Templates\egsge.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 372
- '<SYSTEM32>\cmd.exe' /k attrib "%HOMEPATH%\Templates\skyef.exe" +s +h
- '<SYSTEM32>\cmd.exe' /k attrib "%HOMEPATH%\Templates" +s +h
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\attrib.exe' "%HOMEPATH%\Templates\skyef.exe" +s +h
- '<SYSTEM32>\attrib.exe' "%HOMEPATH%\Templates" +s +h