Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Keyboard Inf.' = '<Полный путь к вирусу>'
- '%TEMP%\syeusiqfhhq\ulntiivsy.exe' -c "%TEMP%\syeusiqfhhq\cfgb"
- %TEMP%\syeusiqfhhq\libusb-1.0.dll
- %TEMP%\syeusiqfhhq\pdcurses.dll
- %TEMP%\syeusiqfhhq\libmicrohttpd-10.dll
- %TEMP%\syeusiqfhhq\libplibc-1.dll
- %TEMP%\syeusiqfhhq\phatk121016.cl
- %TEMP%\syeusiqfhhq\scrypt130511.cl
- %TEMP%\syeusiqfhhq\zlib1.dll
- %TEMP%\syeusiqfhhq\poclbm130302.cl
- %TEMP%\syeusiqfhhq\pthreadGC2.dll
- %TEMP%\syeusiqfhhq\libjansson-4.dll
- %TEMP%\syeusiqfhhq\cfgb
- %TEMP%\syeusiqfhhq\ulntiivsy.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\raw[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\raw[1].php
- %TEMP%\syeusiqfhhq\diablo130302.cl
- %TEMP%\syeusiqfhhq\libblkmaker_jansson-0.1-0.dll
- %TEMP%\syeusiqfhhq\libcurl-4.dll
- %TEMP%\syeusiqfhhq\diakgcn121016.cl
- %TEMP%\syeusiqfhhq\libblkmaker-0.1-0.dll
- 'st#####.give-me-ltc.com':3333
- 'li####inpool.org':3333
- 'mi##.pool-x.eu':8000
- 'pa###bin.com':80
- 'localhost':1037
- pa###bin.com/raw.php?i=########
- DNS ASK st#####.give-me-ltc.com
- DNS ASK li####inpool.org
- DNS ASK pa###bin.com
- DNS ASK mi##.pool-x.eu
- ClassName: 'Indicator' WindowName: '(null)'