Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WAUSDIS] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\winlogon.exe' = '<SYSTEM32>\winlogon.exewinlogon.exe:*:Enabled:Windows Automatic Update Secure Download and Installation Service'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\wausdis.exe' = '<SYSTEM32>\wausdis.exe:*:Enabled:Windows Automatic Update Secure Download and Installation Service'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\wausdis.exe' = '<SYSTEM32>\wausdis.exe<SYSTEM32>\wausdis.exe:*:Enabled:Windows Automatic Update Secure Download and Installation Service'
- '<SYSTEM32>\wausdis.exe'
- '<SYSTEM32>\wausdis.exe' "<Полный путь к вирусу>"
- <SYSTEM32>\winlogon.exe
- %WINDIR%\Temp\WAUSDIS_000.tmp
- <SYSTEM32>\wausdis.exe
- %WINDIR%\Temp\WAUSDIS_000.tmp
- <SYSTEM32>\wausdis.exe
- 'g7##.###smcgillicuddy.com':5945
- 'localhost':5495
- DNS ASK g7##.###smcgillicuddy.com
- '23#.#55.255.250':1900