Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\netupdate] 'Start' = '00000002'
- '%PROGRAM_FILES%\mpekj.exe' "<Полный путь к вирусу>"
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 2
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost" /v netupdate /t REG_MULTI_SZ /d netupdate /F
- '<SYSTEM32>\svchost.exe' -k netupdate
- '<SYSTEM32>\net1.exe' start netupdate
- '<SYSTEM32>\reg.exe' add HKLM\SYSTEM\CurrentControlSet\services\netupdate\Parameters /v ServiceDll /t REG_EXPAND_SZ /d "%CommonProgramFiles%\System\ado\msrtm.dll" /F
- '<SYSTEM32>\net1.exe' stop netupdate
- '<SYSTEM32>\net.exe' stop netupdate
- '<SYSTEM32>\sc.exe' description netupdate "Network Settings Update Manager service, used to check new updates from Microsoft server."
- '<SYSTEM32>\sc.exe' create netupdate type= share start= auto binpath= "%SystemRoot%\system32\svchost.exe -k netupdate" displayname= "Network Update Service"
- %CommonProgramFiles%\System\ado\msrtm.dll
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\updaterc[1].php
- %PROGRAM_FILES%\mpekj.exe
- %TEMP%\msrtm.tmp
- %TEMP%\msrtm.tmp
- 'localhost':1039
- 'www.do###ys5.com':80
- 'localhost':1036
- http://www.do###ys5.com/rc/updaterc.php?no#############################################################################################
- http://www.do###ys5.com/rc/secondinstall.php?ty#####################
- DNS ASK www.do###ys5.com