Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RsTray' = '<SYSTEM32>\scvhost.exe'
- <SYSTEM32>\dllcache\asyncmac.sys файлом <SYSTEM32>\dllcache\asyncmac.sys.new
- <DRIVERS>\asyncmac.sys файлом <DRIVERS>\AsyncMac.sys
- %WINDIR%\extext326156t.exe
- <SYSTEM32>\rundll32.exe %WINDIR%\239203test.dll testall
- <SYSTEM32>\taskkill.exe /im avp.exe /f
- <SYSTEM32>\cacls.exe <SYSTEM32> /e /p everyone:f
- <SYSTEM32>\sc.exe config ekrn start= disabled
- <SYSTEM32>\taskkill.exe /im ekrn.exe /f
- <SYSTEM32>\taskkill.exe /im egui.exe /f
- bdagent.exe
- ccapp.exe
- MCAGENT.EXE
- ekrn.exe
- 360tray.exe
- AVP.EXE
- %WINDIR%\extext326156t.exe
- <DRIVERS>\pcidump.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ttnew[1].txt
- %WINDIR%\239203test.dll
- <DRIVERS>\aec.SYS
- <DRIVERS>\AsyncMac.sys
- %WINDIR%\239203test.dll
- <SYSTEM32>\wbem\Logs\wbemess.lo_
- <DRIVERS>\aec.SYS
- <DRIVERS>\asyncmac.sys
- <SYSTEM32>\dllcache\asyncmac.sys.new в <SYSTEM32>\dllcache\asyncmac.sys
- <DRIVERS>\asyncmac.sys.new в <DRIVERS>\asyncmac.sys
- из <Полный путь к вирусу> в <SYSTEM32>\scvhost.exe
- 'sf##vdew.cn':80
- 'as##swww.cn':80
- 'localhost':1036
- sf##vdew.cn/0007/ttnew.txt
- as##swww.cn/0007/Count.asp?ma##################################
- DNS ASK sf##vdew.cn
- DNS ASK as##swww.cn
- ClassName: '' WindowName: ''