Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '12_dist34' = '%WINDIR%\ttqevidmrgwb.exe'
- '%WINDIR%\ttqevidmrgwb.exe'
- '<SYSTEM32>\cmd.exe' /c DEL <Полный путь к вирусу>
- <SYSTEM32>\cmd.exe
- ecmd.exe
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\Recovery+gtwrn.png
- <Текущая директория>\Recovery+gtwrn.html
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\Recovery+gtwrn.html
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\Recovery+gtwrn.txt
- %HOMEPATH%\My Documents\recover_file_pnqdeojxy.txt
- %WINDIR%\ttqevidmrgwb.exe
- <Текущая директория>\Recovery+gtwrn.txt
- <Текущая директория>\Recovery+gtwrn.png
- %WINDIR%\ttqevidmrgwb.exe
- 'cs###dro.org':80
- 'je##t.ac.in':80
- http://cs###dro.org/images/icons/mzsys.php
- http://je##t.ac.in/webcontrol/images/mzsys.php
- DNS ASK cs###dro.org
- DNS ASK je##t.ac.in
- ClassName: 'Indicator' WindowName: ''