Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\gvtobstauwkqdr] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\gvtobstauwkqdr] 'ImagePath' = 'system32\drivers\qjjrkg.sys'
- '<SYSTEM32>\cmd.exe' /c del <Полный путь к вирусу> >> NUL
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\getcfg[1].htm
- <DRIVERS>\qjjrkg.sys
- <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\getcfg[1].htm
- <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\getcfg[1].htm
- '<L###LNET>.88.1':80
- '<L####NET>.254.1':80
- http://19#.#68.88.1/~projects/bkrnl/getcfg.php via <L###LNET>.88.1
- http://19#.#68.254.1/~projects/bkrnl/getcfg.php via <L####NET>.254.1