Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'w_distrib.exe' = '%WINDIR%\w_distrib.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\w_distrib.exe' = '%WINDIR%\w_distrib.exe:*:Enabled:w_distrib.exe'
- Средство контроля пользовательских учетных записей (UAC)
- '%WINDIR%\w_distrib.exe'
- '<SYSTEM32>\taskkill.exe' /f /fi "IMAGENAME eq <Имя вируса>.exe"
- '<SYSTEM32>\netstat.exe' -ano
- '<SYSTEM32>\chcp.com' 1251
- '<SYSTEM32>\netsh.exe' firewall set opmode mode=disable
- '<SYSTEM32>\cmd.exe' /c ""<Текущая директория>\$$336699.bat""
- %TEMP%\d_ver
- %TEMP%\txt_server_list
- %WINDIR%\w_distrib.exe
- <Текущая директория>\$$336699.bat
- '61.##7.67.249':80
- 61.##7.67.249/txt/txt_server_list
- DNS ASK fr###pac.net
- DNS ASK su####arsinfo.net
- DNS ASK yandex.ru
- DNS ASK bm####rwindows.com
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'MS_WINHELP' WindowName: '(null)'