Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'cnxerykoz' = '%TEMP%\vnesmatewedkeprp.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = '%TEMP%\wrlczqmavgispdijaac.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = 'jfasqifuqcfqodjldehz.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = 'cvncxmgsluucxjmla.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nboyoynuimhk' = 'vnesmatewedkeprp.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mbparcsapuqul' = 'cvncxmgsluucxjmla.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ndsewiziyebgyh' = 'vnesmatewedkeprp.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vnesmatewedkeprp' = '%TEMP%\cvncxmgsluucxjmla.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qhxkdqisjqounxy' = '%TEMP%\lfyokavicmnwsfjjzy.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qhxkdqisjqounxy' = '%TEMP%\wrlczqmavgispdijaac.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qhxkdqisjqounxy' = '%TEMP%\yvrkjcaqnaeqpfmpikohc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'cnxerykoz' = '%TEMP%\lfyokavicmnwsfjjzy.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = 'wrlczqmavgispdijaac.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ndsewiziyebgyh' = 'lfyokavicmnwsfjjzy.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = '%TEMP%\wrlczqmavgispdijaac.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = '%TEMP%\vnesmatewedkeprp.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = 'lfyokavicmnwsfjjzy.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ndsewiziyebgyh' = 'yvrkjcaqnaeqpfmpikohc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nboyoynuimhk' = 'lfyokavicmnwsfjjzy.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qhxkdqisjqounxy' = '%TEMP%\vnesmatewedkeprp.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vnesmatewedkeprp' = '%TEMP%\vnesmatewedkeprp.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = '%TEMP%\jfasqifuqcfqodjldehz.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = '%TEMP%\yvrkjcaqnaeqpfmpikohc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vnesmatewedkeprp' = '%TEMP%\yvrkjcaqnaeqpfmpikohc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vnesmatewedkeprp' = '%TEMP%\lfyokavicmnwsfjjzy.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ndsewiziyebgyh' = 'cvncxmgsluucxjmla.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = 'jfasqifuqcfqodjldehz.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nboyoynuimhk' = 'yvrkjcaqnaeqpfmpikohc.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mbparcsapuqul' = 'yvrkjcaqnaeqpfmpikohc.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ndsewiziyebgyh' = 'jfasqifuqcfqodjldehz.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vnesmatewedkeprp' = '%TEMP%\wrlczqmavgispdijaac.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qhxkdqisjqounxy' = '%TEMP%\cvncxmgsluucxjmla.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'cnxerykoz' = '%TEMP%\cvncxmgsluucxjmla.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = '%TEMP%\yvrkjcaqnaeqpfmpikohc.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = '%TEMP%\lfyokavicmnwsfjjzy.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = 'wrlczqmavgispdijaac.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = 'vnesmatewedkeprp.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = 'cvncxmgsluucxjmla.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mbparcsapuqul' = 'jfasqifuqcfqodjldehz.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vnesmatewedkeprp' = '%TEMP%\jfasqifuqcfqodjldehz.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'cnxerykoz' = '%TEMP%\yvrkjcaqnaeqpfmpikohc.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = '%TEMP%\cvncxmgsluucxjmla.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = '%TEMP%\cvncxmgsluucxjmla.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vhsaowjoac' = 'lfyokavicmnwsfjjzy.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = 'vnesmatewedkeprp.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qdpynwkqdga' = 'yvrkjcaqnaeqpfmpikohc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nboyoynuimhk' = 'cvncxmgsluucxjmla.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mbparcsapuqul' = 'wrlczqmavgispdijaac.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nboyoynuimhk' = 'wrlczqmavgispdijaac.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nboyoynuimhk' = 'jfasqifuqcfqodjldehz.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'qhxkdqisjqounxy' = '%TEMP%\jfasqifuqcfqodjldehz.exe .'
- <Имя диска съемного носителя>:\sample music.exe
- <Имя диска съемного носителя>:\lvekwcnq.bat
- <Имя диска съемного носителя>:\vhsaowjoac.bat
- <Имя диска съемного носителя>:\nboyoynuimhk.bat
- <Имя диска съемного носителя>:\autorun.inf
- скрытых файлов
- Редактора реестра (RegEdit)
- Средство контроля пользовательских учетных записей (UAC)
- %TEMP%\lfhwczsbtnw.exe
- <SYSTEM32>\inrszagejeqkrpepqamnqvzah.omr
- %ProgramFiles%\inrszagejeqkrpepqamnqvzah.omr
- <LS_APPDATA>\inrszagejeqkrpepqamnqvzah.omr
- %WINDIR%\inrszagejeqkrpepqamnqvzah.omr
- %TEMP%\inrszagejeqkrpepqamnqvzah.omr
- <SYSTEM32>\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- %ProgramFiles%\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- <LS_APPDATA>\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- %TEMP%\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- D:\nboyoynuimhk.bat
- %TEMP%\lvekwcnq\vhsaowjoac.exe
- %TEMP%\lvekwcnq\rcx1.tmp
- C:\lvekwcnq.bat
- C:\vhsaowjoac.bat
- C:\nboyoynuimhk.bat
- C:\autorun.inf
- D:\lvekwcnq.bat
- D:\vhsaowjoac.bat
- %TEMP%\yflox.exe
- %WINDIR%\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- %TEMP%\pnkeeyxomafssjrvpsxrnl.exe
- %WINDIR%\cvncxmgsluucxjmla.exe
- <SYSTEM32>\vnesmatewedkeprp.exe
- <SYSTEM32>\cvncxmgsluucxjmla.exe
- <SYSTEM32>\lfyokavicmnwsfjjzy.exe
- <SYSTEM32>\wrlczqmavgispdijaac.exe
- <SYSTEM32>\jfasqifuqcfqodjldehz.exe
- <SYSTEM32>\yvrkjcaqnaeqpfmpikohc.exe
- <SYSTEM32>\pnkeeyxomafssjrvpsxrnl.exe
- %WINDIR%\vnesmatewedkeprp.exe
- %WINDIR%\lfyokavicmnwsfjjzy.exe
- %TEMP%\jfasqifuqcfqodjldehz.exe
- %WINDIR%\wrlczqmavgispdijaac.exe
- %WINDIR%\jfasqifuqcfqodjldehz.exe
- %WINDIR%\yvrkjcaqnaeqpfmpikohc.exe
- %WINDIR%\pnkeeyxomafssjrvpsxrnl.exe
- %TEMP%\vnesmatewedkeprp.exe
- %TEMP%\cvncxmgsluucxjmla.exe
- %TEMP%\lfyokavicmnwsfjjzy.exe
- %TEMP%\wrlczqmavgispdijaac.exe
- %TEMP%\yvrkjcaqnaeqpfmpikohc.exe
- D:\autorun.inf
- <SYSTEM32>\vnesmatewedkeprp.exe
- %TEMP%\inrszagejeqkrpepqamnqvzah.omr
- <SYSTEM32>\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- %ProgramFiles%\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- <LS_APPDATA>\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- %WINDIR%\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- %TEMP%\ndsewiziyebgyhhdpkhthxmyqctcsyvasbbx.ebn
- C:\lvekwcnq.bat
- <LS_APPDATA>\inrszagejeqkrpepqamnqvzah.omr
- %WINDIR%\inrszagejeqkrpepqamnqvzah.omr
- C:\vhsaowjoac.bat
- D:\lvekwcnq.bat
- D:\vhsaowjoac.bat
- D:\nboyoynuimhk.bat
- D:\autorun.inf
- <Имя диска съемного носителя>:\sample music.exe
- <Имя диска съемного носителя>:\lvekwcnq.bat
- <Имя диска съемного носителя>:\vhsaowjoac.bat
- C:\nboyoynuimhk.bat
- C:\autorun.inf
- %ProgramFiles%\inrszagejeqkrpepqamnqvzah.omr
- <SYSTEM32>\inrszagejeqkrpepqamnqvzah.omr
- %TEMP%\pnkeeyxomafssjrvpsxrnl.exe
- <SYSTEM32>\lfyokavicmnwsfjjzy.exe
- <SYSTEM32>\wrlczqmavgispdijaac.exe
- <SYSTEM32>\jfasqifuqcfqodjldehz.exe
- <SYSTEM32>\yvrkjcaqnaeqpfmpikohc.exe
- <SYSTEM32>\pnkeeyxomafssjrvpsxrnl.exe
- %WINDIR%\vnesmatewedkeprp.exe
- %WINDIR%\cvncxmgsluucxjmla.exe
- %WINDIR%\lfyokavicmnwsfjjzy.exe
- <SYSTEM32>\cvncxmgsluucxjmla.exe
- %WINDIR%\wrlczqmavgispdijaac.exe
- %WINDIR%\yvrkjcaqnaeqpfmpikohc.exe
- %WINDIR%\pnkeeyxomafssjrvpsxrnl.exe
- %TEMP%\vnesmatewedkeprp.exe
- %TEMP%\cvncxmgsluucxjmla.exe
- %TEMP%\lfyokavicmnwsfjjzy.exe
- %TEMP%\wrlczqmavgispdijaac.exe
- %TEMP%\jfasqifuqcfqodjldehz.exe
- %TEMP%\yvrkjcaqnaeqpfmpikohc.exe
- %WINDIR%\jfasqifuqcfqodjldehz.exe
- <Имя диска съемного носителя>:\nboyoynuimhk.bat
- <Имя диска съемного носителя>:\autorun.inf
- %TEMP%\lvekwcnq\vhsaowjoac.exe
- %TEMP%\lvekwcnq\vhsaowjoac.exe
- '93.##3.148.107':13061
- http://wh#####yipaddress.com/
- http://www.wh###smyip.com/
- http://www.sh####ipaddress.com/
- http://www.yo##ube.com/
- http://tg###ulfu.com/
- http://ue###ycs.com/
- DNS ASK wh#####yip.everdot.org
- DNS ASK zl##te.net
- DNS ASK ue###ycs.com
- DNS ASK ni###dmg.net
- DNS ASK qf###mowfal.net
- DNS ASK ca####weacce.org
- DNS ASK no###qpqdy.info
- DNS ASK ou###ccoma.org
- DNS ASK ne###wtihqc.net
- DNS ASK oq##ok.org
- DNS ASK tr###mrwud.net
- DNS ASK xy####whhrun.info
- DNS ASK bo###rf.info
- DNS ASK tg###ulfu.com
- DNS ASK yo##ube.com
- DNS ASK wh###smyip.ca
- DNS ASK sh####ipaddress.com
- DNS ASK wh###smyip.com
- DNS ASK wh#####yipaddress.com
- DNS ASK ci###uwmt.net
- DNS ASK vm###fbl.net
- '%TEMP%\lfhwczsbtnw.exe' "<Полный путь к файлу>*"
- '%TEMP%\yflox.exe' "-%TEMP%\vnesmatewedkeprp.exe"