Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Evntconnections] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\NetDDE] 'Start' = '00000002'
- %WINDIR%\inf\svchost.exe
- %WINDIR%\inf\sc.exe delete NetDDE config NetDDE start= auto
- %WINDIR%\inf\NTService.exe
- <SYSTEM32>\sc.exe delete NetDDE
- <SYSTEM32>\cmd.exe /c %WINDIR%\inf\bfdde.bat
- <SYSTEM32>\sc.exe start Evntconnections
- <SYSTEM32>\sc.exe start NetDDE
- <SYSTEM32>\sc.exe description NetDDE "???????????????????????????? (DDE) ?????????"
- <SYSTEM32>\sc.exe create NetDDE BinPath= %WINDIR%\inf\WNET type= own type= interact start= auto DisplayName= "Network DDE"
- <SYSTEM32>\sc.exe stop Evntconnections
- <SYSTEM32>\cmd.exe /c %WINDIR%\inf\bfbf.bat
- <SYSTEM32>\cmd.exe /c <Текущая директория>\tmp.bat
- <SYSTEM32>\sc.exe description Evntconnections "?????????????????????,???????,??????????"
- <SYSTEM32>\sc.exe create Evntconnections BinPath= %WINDIR%\inf\NTService.exe type= own type= interact start= auto DisplayName= "Evnt connections"
- <SYSTEM32>\sc.exe delete Evntconnections
- %WINDIR%\inf\sc.exe
- %WINDIR%\inf\svchost.exe
- %WINDIR%\inf\bfdde.bat
- %WINDIR%\inf\bfbf.bat
- <Текущая директория>\tmp.bat
- <Текущая директория>\NTSVC.ocx
- %WINDIR%\inf\NTSVC.ocx
- %WINDIR%\inf\NTService.exe
- <Текущая директория>\NTSVC.ocx
- из <Полный путь к вирусу> в <Текущая директория>\tmp.exe