Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\RMMNTD6K.pif
- [<HKLM>\SYSTEM\ControlSet001\Services\76NN9PR] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\3NMRJJ] 'Start' = '00000002'
- C:\TA9WFF7G.EXE DAKAYVZWDRDOSY
- <Полный путь к вирусу>.exe
- <SYSTEM32>\regsvr32.exe /u /s itss.dll
- <SYSTEM32>\cmd.exe /c C:\VZK4MYZ.BAT
- <SYSTEM32>\regsvr32.exe /s "%WINDIR%\dakayvzwdrdosy.dll"
- %PROGRAM_FILES%\WRSIILHSI5OU\ZGP89OJE3.exe
- %WINDIR%\dakayvzwdrdosy.dll
- C:\VZK4MYZ.BAT
- %PROGRAM_FILES%\WRSIILHSI5OU\8FLWWUE92SE.exe
- %WINDIR%\DAKAYVZWDRDOSY.txt
- %PROGRAM_FILES%\HUHEINITF7C\K3M5KWG4.exe
- <Полный путь к вирусу>.exe
- C:\TA9WFF7G.EXE
- %PROGRAM_FILES%\HUHEINITF7C\Y8IB4L90Z622.exe
- %PROGRAM_FILES%\WRSIILHSI5OU\ZGP89OJE3.exe
- %PROGRAM_FILES%\WRSIILHSI5OU\8FLWWUE92SE.exe
- <Полный путь к вирусу>.exe
- %PROGRAM_FILES%\HUHEINITF7C\K3M5KWG4.exe
- %PROGRAM_FILES%\HUHEINITF7C\Y8IB4L90Z622.exe
- '22#.73.10.1':443
- ClassName: 'DAKAYVZWDRDOSY' WindowName: ''
- ClassName: 'DAKAYVZWDRDOSY' WindowName: 'tvylauhc'
- ClassName: 'Shell_TrayWnd' WindowName: ''