Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AntiVirus' = '<SYSTEM32>\systemdrivers\balle.bat'
- '<SYSTEM32>\cmd.exe' /K balle.bat
- '<SYSTEM32>\shutdown.exe' -r -t 10 -f -c "YOU DID JUST DOWNLOADED A VIRUS!! HAHAHAH!!!"
- '<SYSTEM32>\shutdown.exe' -r -t 15 -f -c "HAHAHAHAHAHAHAHAHHAHAHAHA YOU ARE A IDIOT ! YOU DOWNLOADED A 'EVIL' VIRUS !"
- '<SYSTEM32>\cmd.exe' /K spreadIT.bat
- '<SYSTEM32>\cmd.exe' /c ""<SYSTEM32>\systemdrivers\start.bat" "
- '<SYSTEM32>\reg.exe' add hkey_current_user\software\microsoft\windows\currentversion\run /v AntiVirus /t reg_sz /d <SYSTEM32>\systemdrivers\balle.bat /f
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- <SYSTEM32>\systemdrivers\ImFlower.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\walder[1].php
- <SYSTEM32>\systemdrivers\start.bat
- <SYSTEM32>\systemdrivers\spreadIT.bat
- <SYSTEM32>\systemdrivers\balle.bat
- 'me####s.lycos.co.uk':80
- 'localhost':1039
- http://me####s.lycos.co.uk/crazylan/gbtest/walder.php
- DNS ASK me####s.lycos.co.uk
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: ''