Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Multimedia extensions' = '%WINDIR%\mservice1.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Management Console' = '%WINDIR%\lssas1.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = ''
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Internet Connection Wizard' = '%WINDIR%\stisvsq1.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Office Quick Launcher' = '<Полный путь к вирусу>'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Internet Mail and News' = '%WINDIR%\msqdevl1.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Games Acceleration' = '%WINDIR%\svshost1.exe'
- Диспетчера задач (Taskmgr)
- <SYSTEM32>\regsvr32.exe -u /s shimgvw.dll
- %TEMP%\RGI1.tmp
- <SYSTEM32>\wbem\Logs\wbemess.lo_
- %TEMP%\RGI1.tmp
- 'localhost':1035
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: ''