Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'fire' = '<ANALYSE_DIR>.bat'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'windows' = 'C:\Arquivos de programas\Mozilla Firefox\fire.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '%USERNAME%' = '<Полный путь к вирусу>'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'fire3' = '%ProgramFiles%\Mozilla Firefox\fire.exe'
- iexplore.exe
- firefox.exe
- opera.exe
- chrome.exe
- safari.exe
- %WINDIR%\arquivo.txt
- %WINDIR%\arquivo.bak
- <ANALYSE_DIR>.bat
- %WINDIR%\iniciar.txt
- %ProgramFiles%\Mozilla Firefox\fire.exe
- 'ba#####avisa.ueuo.com':80
- http://ba#####avisa.ueuo.com/aviso.php
- DNS ASK ba#####avisa.ueuo.com
- ClassName: '' WindowName: 'Gerenciador de Tarefas do Windows'
- ClassName: 'Indicator' WindowName: ''