Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Explorer Controler' = '%WINDIR%\VistaXPUpgrade.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- %WINDIR%\xtremeVideoDriver_regXX1.exe
- %WINDIR%\xtremeVideoDriver_regXX02.exe
- %WINDIR%\xtremeVideoDriver_regXX1.exe (загружен из сети Интернет)
- %WINDIR%\xtremeVideoDriver_regXX02.exe (загружен из сети Интернет)
- <SYSTEM32>\netsh.exe firewall set opmode mode=disable
- %WINDIR%\xtremeVideoDriver_regXX02.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\double_worm[1].exe
- %WINDIR%\xtremeVideoDriver_regXX1.exe
- %WINDIR%\VistaXPUpgrade.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Menssagen[1].exe
- 'fs####.sendspace.com':80
- 'localhost':1035
- fs####.sendspace.com/dl/57add1b69fc517eddbc3f1c2fe4a920b/4ba8064f73e36fa6/30962s/double_worm.exe
- fs####.sendspace.com/dl/0e1d26ac4df5f9fad0eb08fce3a32f36/4ba8093a2bc9e473/ilden0/Menssagen.exe
- DNS ASK fs####.sendspace.com
- ClassName: 'Indicator' WindowName: ''