Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe] 'Debugger' = 'qpqpdnd_.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'qw7v4x1c4fxsq' = '"C:\ProgramData\svchost0\mwvaztybt.exe"'
- [<HKLM>\SYSTEM\ControlSet001\services\SSDPSRV] 'Start' = '00000002'
- скрытых файлов
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x19CF045A" /TR "C:\ProgramData\svchost0\mwvaztybt.exe" /RL HIGHEST
- <SYSTEM32>\Dwm.exe
- %WINDIR%\explorer.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- <SYSTEM32>\Tasks\Windows Update Check - 0x19CF045A
- из <Полный путь к вирусу> в C:\ProgramData\svchost0\mwvaztybt.exe
- 'yk###ork.biz':80
- '20#.#6.232.182':80
- yk###ork.biz/path/order.php
- DNS ASK yk###ork.biz
- DNS ASK windowsupdate.microsoft.com
- ClassName: 'wsuwsuws' WindowName: 'ooaooaoo'
- ClassName: 'Indicator' WindowName: '(null)'