Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'cyadicon' = '%PROGRAM_FILES%\cyadicon\cyadicon.exe'
- %PROGRAM_FILES%\cyadicon\cyadicon.exe
- %PROGRAM_FILES%\cyadicon\cyinsproc.exe <Полный путь к вирусу>;
- <SYSTEM32>\cmd.exe /c c:\DelUS.bat
- %TEMP%\nsz2.tmp\System.dll
- %PROGRAM_FILES%\cyadicon\cyconfig.ini
- C:\DelUS.bat
- %PROGRAM_FILES%\cyadicon\uninstall.exe
- %PROGRAM_FILES%\cyadicon\cyadicon.exe
- %PROGRAM_FILES%\cyadicon\cyremoveproc.exe
- %PROGRAM_FILES%\cyadicon\cyinsproc.exe
- %PROGRAM_FILES%\cyadicon\cyinsproc.exe
- %TEMP%\nsz2.tmp\System.dll
- 'en#.#yad.co.kr':80
- 'lo#.#yad.co.kr':80
- en#.#yad.co.kr/index2.php?co#########################################
- lo#.#yad.co.kr/su.php?co#############################################
- DNS ASK en#.#yad.co.kr
- DNS ASK lo#.#yad.co.kr