Техническая информация
- [HKLM\Software\Microsoft\Windows\CurrentVersion\run] 'virus' = 'C:\virus333.exe'
- C:\333.txt
- '34.##9.100.209':443
- '34.##9.100.209':443
- DNS ASK google.com
- '<SYSTEM32>\cmd.exe' /c copy virus333.exe c:\virus333.exe
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\ping.exe -n 1 google.com >> C:\333.txt
- '<SYSTEM32>\ping.exe' -n 1 google.com
- '<SYSTEM32>\cmd.exe' /c echo 12#.3.3.3 avg.com >> <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c echo 12#.3.3.3 www.avg.com >> <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c echo 12#.3.3.3 eset.com >> <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c echo 12#.3.3.3 www.eset.com >> <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c echo 12#.3.3.3 avira.com >> <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c echo 12#.3.3.3 www.avira.com >> <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\msg.exe * PRESIONE F3 PARA DETENER ESTE VIRUS DE APRENDIZAJE
- '<SYSTEM32>\msg.exe' * PRESIONE F3 PARA DETENER ESTE VIRUS DE APRENDIZAJE