Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{4F5278F6-92B3-EF6E-EBB4-03391563981C}] 'StubPath' = '<Полный путь к вирусу>'
- %TEMP%\_MEI28402\select.pyd
- %TEMP%\_MEI28402\_ctypes.pyd
- %TEMP%\_MEI28402\unicodedata.pyd
- %TEMP%\_MEI28402\evilbro.exe.manifest
- %TEMP%\_MEI28402\bz2.pyd
- %TEMP%\_MEI28402\_hashlib.pyd
- %TEMP%\_MEI28402\msvcr90.dll
- %TEMP%\_MEI28402\Microsoft.VC90.CRT.manifest
- %TEMP%\_MEI28402\msvcp90.dll
- %TEMP%\_MEI28402\python27.dll
- %TEMP%\_MEI28402\msvcm90.dll
- 'c2.#tp.com':80
- DNS ASK c2.#tp.com