Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Windows Logon Service' = '"%APPDATA%\W3Help\winlogonz.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Windows Logon Service' = '"%APPDATA%\W3Help\winlogonz.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{4175C5F3-D47F-143B-DD4D-E67A0EB4E773}] 'StubPath' = '"%APPDATA%\W3Help\winlogonz.exe"'
- [<HKCU>\Software\Microsoft\Active Setup\Installed Components\{4175C5F3-D47F-143B-DD4D-E67A0EB4E773}] 'StubPath' = '"%APPDATA%\W3Help\winlogonz.exe"'
- скрытых файлов
- '%APPDATA%\W3Help\winlogonz.exe' /del <Полный путь к вирусу>
- C:\RECYCLER\blaze.vmx
- %APPDATA%\W3Help\winlogonz.exe
- C:\RECYCLER\blaze.vmx
- %APPDATA%\W3Help\winlogonz.exe
- 'cr###r0x.net':1234
- 'bl####.izthewiz.net':1234
- 'bl#.#rkrxer.net':1234
- DNS ASK cr###r0x.net
- DNS ASK bl####.izthewiz.net
- DNS ASK bl#.#rkrxer.net
- ClassName: '(null)' WindowName: 'System Configuration Utility'
- ClassName: '(null)' WindowName: 'Registry Editor'
- ClassName: 'HijackThis' WindowName: '(null)'