Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'DisableNotifications' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- Центр обеспечения безопасности (Security Center)
- <LS_APPDATA>\ire.exe -gav <Полный путь к вирусу>
- %TEMP%\168mxu41n458lg81g3exk2y007287e72k6837
- %HOMEPATH%\Templates\168mxu41n458lg81g3exk2y007287e72k6837
- %ALLUSERSPROFILE%\Application Data\168mxu41n458lg81g3exk2y007287e72k6837
- <LS_APPDATA>\ire.exe
- <LS_APPDATA>\168mxu41n458lg81g3exk2y007287e72k6837
- 'wi###iwaji.com':80
- 'ol##as.com':80
- wi###iwaji.com/1032000112
- ol##as.com/summer.htm
- DNS ASK wi###iwaji.com
- DNS ASK ol##as.com
- '<IP-адрес в локальной сети>':1037