Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\apppatch\wbtmqws.dat,'
- <SYSTEM32>\netsh.exe firewall set allowedprogram \??\<SYSTEM32>\winlogon.exe ENABLE
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\spoolsv.exe
- opera.exe
- ClassName: 'AVP.MainWindow' WindowName: ''
- %WINDIR%\AppPatch\wbtmqws.dat
- %TEMP%\esp6FBF.tmp
- %TEMP%\esp6FBF.tmp
- из <Полный путь к вирусу> в %TEMP%\1.tmp
- 'me###alpinx.com':80
- me###alpinx.com/home.php
- DNS ASK google.com
- DNS ASK me###alpinx.com
- '<IP-адрес в локальной сети>':1036
- ClassName: '' WindowName: 'Kaspersky Virus Removal Tool 2010'
- ClassName: 'Malwarebytes' WindowName: 'ThunderRT6FormDC'
- ClassName: 'OSAM: Autorun Manager' WindowName: '#32770'
- ClassName: '' WindowName: '???????????? ??????? AVZ'
- ClassName: '' WindowName: 'random'
- ClassName: 'ThunderRT6FormDC' WindowName: ''