Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Yahoo Messengger' = '<SYSTEM32>\SSVICHOSST.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe SSVICHOSST.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\IEXPLORE.EXE
- %HOMEPATH%\Start Menu\Programs\Startup\x4x.exe
- %HOMEPATH%\Start Menu\Programs\Startup\1.scr
- %HOMEPATH%\Start Menu\Programs\Startup\x4x.exe
- %TEMP%\kaoauvw
- %TEMP%\aut3.tmp
- %WINDIR%\SSVICHOSST.exe
- <SYSTEM32>\SSVICHOSST.exe
- %TEMP%\enqofin
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\1[1].scr
- <SYSTEM32>\SSVICHOSST.exe
- %TEMP%\aut3.tmp
- %TEMP%\kaoauvw
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\enqofin
- 'www.ki###arch.info':80
- www.ki###arch.info/1.scr
- DNS ASK www.ki###arch.info
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Indicator' WindowName: ''