Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\tkkxfhbp] 'Start' = '00000002'
- '%WINDIR%\tkkxfhbp.exe' "" "<Полный путь к вирусу>"
- '%WINDIR%\tkkxfhbp.exe'
- %WINDIR%\libeay32.dll
- %WINDIR%\ssleay32.dll
- %WINDIR%\tkkxfhbp.exe
- <SYSTEM32>\config\systemprofile\KeyF64.txt
- 'me##slon.us':80
- me##slon.us/wedstat/dll/64/libeay32.dll
- me##slon.us/wedstat/dll/64/ssleay32.dll
- me##slon.us/wedstat/
- DNS ASK me##slon.us
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'