Техническая информация
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"%1" %*'
- <SYSTEM32>\route.exe delete 121.14.212.97
- <SYSTEM32>\route.exe delete 121.14.212.67
- <SYSTEM32>\route.exe delete 61.147.99.243
- <SYSTEM32>\route.exe delete 60.18.168.105
- <SYSTEM32>\route.exe delete 61.147.99.247
- <SYSTEM32>\route.exe delete 203.171.230.226
- <SYSTEM32>\cmd.exe /c ""<Текущая директория>\ЗеіэІ»ХэіЈЙиЦГ.bat" end"
- <SYSTEM32>\route.exe delete 202.165.179.217
- <SYSTEM32>\route.exe delete 219.148.37.11
- <SYSTEM32>\route.exe delete 218.3.165.173
- %HOMEPATH%\Desktop\.lnk
- %HOMEPATH%\Desktop\<Имя вируса>.lnk
- <Текущая директория>\ЗеіэІ»ХэіЈЙиЦГ.bat
- %WINDIR%\.exe
- '21#.#48.37.11':20312
- '22#.#.252.39':27262
- '21#.#48.37.11':20313
- '21#.#48.37.11':20311
- '22#.#.252.39':20313
- 'ts###1.vicp.cc':20311
- '20#.#65.179.217':20311
- '22#.#.252.39':20311
- '22#.#.252.39':20312
- '20#.#71.230.226':27262
- '20#.#71.230.226':20313
- '20#.#71.230.226':20311
- '20#.#71.230.226':20312
- '11#.#55.140.136':20312
- '11#.#55.140.136':20311
- '21#.#48.37.11':27262
- '11#.#55.140.136':27262
- '11#.#55.140.136':20313
- DNS ASK ts###1.vicp.cc
- ClassName: 'msctls_updown32' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''