Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WinMediaCenter] 'Start' = '00000002'
- '%TEMP%\NSE2.exe'
- '%WINDIR%\sleep.exe' 7
- '<SYSTEM32>\attrib.exe' -h "%TEMP%\NSE2.exe"
- '<SYSTEM32>\attrib.exe' -s "del /Q /a "s"\*.*
- '<SYSTEM32>\svchost.exe' -k wupagent
- '<SYSTEM32>\cmd.exe' /c %TEMP%\\Deleteme.bat
- %TEMP%\Deleteme.bat
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\rconn[1].jpg
- %WINDIR%\Temp\cat.jpg
- <SYSTEM32>\wupdagnt.dll
- %TEMP%\<Имя вируса>
- %TEMP%\NSD1.tmp
- %TEMP%\NSE2.tmp
- %TEMP%\NSE2.exe
- %TEMP%\NSD1.tmp
- %TEMP%\NSE2.tmp в %TEMP%\NSE2.exe
- '22#.#49.223.209':80
- 'localhost':1037
- 22#.#49.223.209/rconn.jpg
- ClassName: '(null)' WindowName: 'hwp_exec'