Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LastEnum' = 'RunDll32.exe "%APPDATA%\apisvcd.dll",Start'
- '%TEMP%\ose000000.exe' "<Полный путь к вирусу>"
- '<SYSTEM32>\rundll32.exe' "%APPDATA%\apisvcd.dll",Start ""
- '%APPDATA%\winUproll.exe' ""
- %TEMP%\ose000000.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\search[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\search[1].htm
- %APPDATA%\winUproll.exe
- %TEMP%\EU_Eastern_Europe_agenda_BA_3_Nov_2015.pdf
- %APPDATA%\apisvcd.dll
- %APPDATA%\winUproll.exe
- '10#.#71.117.216':80
- http://10#.#71.117.216/search.php
- ClassName: 'Indicator' WindowName: ''