Техническая информация
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"%1" %*'
- <SYSTEM32>\route.exe delete 203.171.230.226
- <SYSTEM32>\cmd.exe /c ""<Текущая директория>\ЗеіэІ»ХэіЈЙиЦГ.bat" end"
- %HOMEPATH%\Desktop\<Имя вируса>.lnk
- <Текущая директория>\ЗеіэІ»ХэіЈЙиЦГ.bat
- '22#.#92.133.50':20311
- '11#.#1.31.39':27262
- '22#.#92.133.50':27262
- '22#.#92.133.50':20313
- '11#.#1.31.39':20313
- 'ts###1.vicp.cc':20311
- '11#.#55.140.136':20311
- '11#.#1.31.39':20311
- '11#.#1.31.39':20312
- '20#.#71.230.226':20313
- '20#.#71.230.226':20311
- '20#.#71.230.226':20312
- '20#.#71.230.226':27262
- '21#.#48.37.11':20313
- '21#.#48.37.11':27262
- '22#.#92.133.50':20312
- '21#.#48.37.11':20311
- '21#.#48.37.11':20312
- DNS ASK ts###1.vicp.cc
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'msctls_updown32' WindowName: ''