Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%ALLUSERSPROFILE%\Application Data\Security Essentials Ultimate Pack\SecEls.exe" /hide'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'updatesst' = '"%ALLUSERSPROFILE%\Application Data\Security Essentials Ultimate Pack\SecEls.exe"'
- '%ALLUSERSPROFILE%\Application Data\Security Essentials Ultimate Pack\SecEls.exe' DEL<Полный путь к вирусу>
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Security Essentials Ultimate Pack.lnk
- %ALLUSERSPROFILE%\Application Data\Security Essentials Ultimate Pack\sevibmaqxls\sedkqmalvls.cfg
- %HOMEPATH%\Start Menu\Security Essentials Ultimate Pack.lnk
- %ALLUSERSPROFILE%\Application Data\Security Essentials Ultimate Pack\SecEls.exe
- %HOMEPATH%\Desktop\Security Essentials Ultimate Pack.lnk
- %ALLUSERSPROFILE%\Application Data\Security Essentials Ultimate Pack\sevibmaqxls\sedkqmalvls.cfg
- 'pi####yegruzy.com':80
- '17#.#94.37.104':80
- pi####yegruzy.com/v.txt
- DNS ASK pi####yegruzy.com
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'