Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'srv-2016' = '%APPDATA%\vmdlrsy.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'srv-2016' = '%APPDATA%\vmdlrsy.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\help_recover_instructions+wry.png
- '%APPDATA%\vmdlrsy.exe'
- '<SYSTEM32>\cmd.exe' /c DEL <Полный путь к вирусу>
- <SYSTEM32>\cmd.exe
- ecmd.exe
- C:\Documents and Settings\Default User\Local Settings\History\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\History\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\History\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Temp\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Temp\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Temp\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Cookies\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Cookies\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Favorites\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Favorites\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Favorites\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Cookies\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\SendTo\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\SendTo\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Start Menu\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Start Menu\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Templates\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Templates\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Templates\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Start Menu\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Start Menu\Programs\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Start Menu\Programs\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\My Documents\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\My Documents\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Recent\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\PrintHood\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Recent\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\SendTo\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Recent\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\PrintHood\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\NetHood\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\My Documents\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\NetHood\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\PrintHood\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\NetHood\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\DRM\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\DRM\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Videos\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Pictures\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Pictures\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Videos\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Videos\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\DRM\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Favorites\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Favorites\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Favorites\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\help_recover_instructions+wry.png
- %HOMEPATH%\My Documents\recover_file_bhvnwsxqh.txt
- %APPDATA%\vmdlrsy.exe
- <Текущая директория>\help_recover_instructions+wry.png
- <Текущая директория>\help_recover_instructions+wry.html
- <Текущая директория>\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Music\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Music\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Music\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\help_recover_instructions+wry.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\help_recover_instructions+wry.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\help_recover_instructions+wry.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Templates\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Templates\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Templates\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\help_recover_instructions+wry.html
- %ALLUSERSPROFILE%\Start Menu\Programs\help_recover_instructions+wry.txt
- %ALLUSERSPROFILE%\Start Menu\help_recover_instructions+wry.png
- %ALLUSERSPROFILE%\Start Menu\Programs\help_recover_instructions+wry.html
- 'we#######wooddentaloffice.com':80
- 'su#####itimmerkezi.com':80
- 'pr#####mmobiliers.org':80
- 'we###dco.com':80
- 'ta##iva.org':80
- http://we#######wooddentaloffice.com/mssys.php
- http://su#####itimmerkezi.com/administrator/components/com_akeeba/akeeba/engines/proc/mzsystem.php
- http://pr#####mmobiliers.org/dbconnect.php
- http://we###dco.com/components/com_users/views/remind/tmpl/dbconnect.php
- http://ta##iva.org/installation1/view/database/dbconnect.php
- DNS ASK we#######wooddentaloffice.com
- DNS ASK su#####itimmerkezi.com
- DNS ASK pr#####mmobiliers.org
- DNS ASK we###dco.com
- DNS ASK ta##iva.org
- ClassName: 'Indicator' WindowName: ''