Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'urlspace' = '%APPDATA%\Spiritsoft\urlspirit\jlguaji.exe -h'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\Spiritsoft\urlspirit\jlguaji.exe' = '%APPDATA%\Spiritsoft\urlspirit\jlguaji.exe:*:Enabled:Microsoft Customer URLSpace'
- %APPDATA%\Spiritsoft\urlspirit\1.exe -p2870508
- <SYSTEM32>\rundll32.exe shimgvw.dll,ImageView_Fullscreen %TEMP%\<Имя вируса>.jpg
- %APPDATA%\Spiritsoft\urlspirit\jlguaji.exe
- %APPDATA%\Spiritsoft\urlspirit\1.exe
- %TEMP%\<Имя вируса>.jpg
- '22#.#34.51.206':8831
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''