Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sdmmrnm' = '%WINDIR%\temp\sd151.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\temp\sd151.exe' = '%WINDIR%\temp\sd151.exe:*:Enabled:sd151.exe'
- '%WINDIR%\Temp\sd151.exe'
- '%WINDIR%\Temp\10586.exe'
- '<SYSTEM32>\rundll32.exe' "<SYSTEM32>\vjpscc85",DllCanUnloadNow
- <SYSTEM32>\vjpscc85.dll
- <DRIVERS>\vjpscc85.sys
- %WINDIR%\Temp\sd151.exe
- %WINDIR%\Temp\10586.exe
- %TEMP%\tmp2.CAB
- %TEMP%\tmp3.CAB
- %TEMP%\tmp3.CAB
- %TEMP%\tmp2.CAB
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'