Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ghost' = '%WINDIR%\updatevideo.exe'
- %TEMP%\phpa13e.tmp
- %TEMP%\phpa14e.tmp
- %TEMP%\phpa14f.tmp
- <Текущая директория>\hide.exe
- <DRIVERS>\etc\host
- <Текущая директория>\hide.exe
- <Текущая директория>\hide.exe
- 'di###-link.com':80
- http://www.di###-link.com/PDF/thumbs/m1v3/cont/zombie.php?id#############################
- http://www.di###-link.com/PDF/thumbs/m1v3/cont/phar.php?id#
- DNS ASK di###-link.com
- '<Текущая директория>\hide.exe' updatevideo.exe
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v ghost /t REG_SZ /d %WINDIR%\updatevideo.exe /f
- '%WINDIR%\syswow64\reg.exe' add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v ghost /t REG_SZ /d %WINDIR%\updatevideo.exe /f
- '%WINDIR%\syswow64\cmd.exe' /c copy updatevideo.exe %WINDIR%\updatevideo.exe
- '%WINDIR%\syswow64\cmd.exe' /c hide.exe updatevideo.exe
- '%WINDIR%\syswow64\cmd.exe' /c attrib +r +h hide.exe
- '%WINDIR%\syswow64\attrib.exe' +r +h hide.exe