Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Processus hote pour les services Windows' = '%APPDATA%\sys32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Processus hote pour les services Windows' = '\sys32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'l39K50wK' = '%HOMEPATH%\s97C37hE\svchost.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- C:\sys32\svchost.exe
- %APPDATA%\imlgs\23-04-2014
- %APPDATA%\install.imp
- %APPDATA%\sys32\svchost.exe
- %HOMEPATH%\w99M14mZ.XG9
- %TEMP%\aut1.tmp
- %HOMEPATH%\x82W96uO.txt
- C:\<Имя вируса>.exe
- %HOMEPATH%\x82W96uO.txt
- %HOMEPATH%\w99M14mZ.XG9
- %TEMP%\aut1.tmp
- 'ki######urgy22.no-ip.biz':4547
- DNS ASK ki######urgy22.no-ip.biz
- ClassName: 'Indicator' WindowName: '(null)'