Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Server Call (WSC)] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SVKP] 'Start' = '00000002'
- '%WINDIR%\baby.exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\uninstal.bat
- ClassName: 'AVP.AhAppChangedDialog' WindowName: ''
- ClassName: 'AVP.Product_Notification' WindowName: ''
- ClassName: 'AVP.AlertDialog' WindowName: ''
- ClassName: 'AVP.AhLearnDialog' WindowName: ''
- %WINDIR%\uninstal.bat
- %WINDIR%\baby.exe
- <SYSTEM32>\SVKP.sys
- %WINDIR%\baby.exe
- 'wx#####9141.3322.org':8000
- DNS ASK wx#####9141.3322.org
- ClassName: '' WindowName: 'Create rule for IEXPLORE.EXE'
- ClassName: '' WindowName: 'Создать правило для baby.exe'
- ClassName: '' WindowName: '??????? ??????? ??? IEXPLORE.EXE'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'Создать правило для IEXPLORE.EXE'
- ClassName: '' WindowName: '??????? ??????? ??? <Имя вируса>.exe'
- ClassName: '' WindowName: 'Create rule for <Имя вируса>.exe'
- ClassName: '' WindowName: 'Создать правило для <Имя вируса>.exe'
- ClassName: '' WindowName: '??????? ??????? ??? baby.exe'
- ClassName: '' WindowName: 'Create rule for baby.exe'