Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Trojan Killer (32-bit)' = '"<Полный путь к вирусу>" -startupscan '
- %ALLUSERSPROFILE%\Application Data\Gridinsoft\Trojan Killer\database\vs.c
- 'bi##.##tivirus-lab.com':80
- 'gr###nsoft.com':80
- 'tr####-killer.net':80
- 'tr####-killer.com':80
- tr####-killer.net/bases_info.php
- tr####-killer.com/price.php
- tr####-killer.net/check_ver.php?ve######
- gr###nsoft.com/error.php?p=###########
- bi##.##tivirus-lab.com/stats/?p=##############
- DNS ASK bi##.##tivirus-lab.com
- DNS ASK gr###nsoft.com
- DNS ASK tr####-killer.net
- DNS ASK tr####-killer.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'msctls_updown32' WindowName: ''