Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'is_CRNJEUFU' = '%APPDATA%\is_%USERNAME%.exe'
- '%APPDATA%\is_%USERNAME%.exe' "<Полный путь к вирусу>"
- %APPDATA%\is_%USERNAME%.exe
- <SYSTEM32>\d3d9caps.dat
- <SYSTEM32>\d3d9caps.tmp в <SYSTEM32>\d3d9caps.dat
- '37.##.224.107':80
- 37.##.224.107/BTS/mtm.drx
- ClassName: '獡彷癡灟灯灵睟摮汣獡s睹䅺䍂䕄䝆䥈䭊䵌低児卒啔坖奘ず㈱㐳㘵㠷9' WindowName: ''
- ClassName: '??????????s???????????????????9' WindowName: ''
- ClassName: 'TFMAppClass' WindowName: 'is_%USERNAME%'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'OSKMainClass' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'TFMAppClass' WindowName: '<Имя вируса>'