Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\run] 'virus' = 'C:\XDR.txt'
- C:\xdr.txt
- DNS ASK vi###total.com
- '%WINDIR%\syswow64\cmd.exe' /c copy XDR.txt c:\XDR.txt
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\telnet.exe virustotal.com 443>> C:\XDR.txt
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\PING.exe virustotal.com 443>> C:\XDR.txt
- '%WINDIR%\syswow64\ping.exe' virustotal.com 443
- '%WINDIR%\syswow64\cmd.exe' /c echo 127.3.3.3 www.tr###micro.com >> <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\cmd.exe' /c echo 127.3.3.3 trendmicro.com >> <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\msg.exe * PRESIONE F3 PARA DETENER EL VIRUS