Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aspnet_states] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\DSLserverorm] 'Start' = '00000002'
- '%TEMP%\100.exe'
- '<SYSTEM32>\qqiuqi.exe'
- '%TEMP%\vip.exe'
- '<SYSTEM32>\hujzuk.exe'
- '<SYSTEM32>\taskkill.exe' /f /t /im <Имя вируса>.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\\up.bat
- <SYSTEM32>\qqiuqi.exe
- %TEMP%\up.bat
- <SYSTEM32>\hujzuk.exe
- %TEMP%\vip.exe
- %TEMP%\100.exe
- %TEMP%\100.exe в %TEMP%\SOFTWARE.LOG
- 'ap#.#oho1z.com':80
- 'ge###.api520.com':1001
- 'cc.##i520.com':1002
- ap#.#oho1z.com/baohe/wb/update.txt
- DNS ASK ap#.#oho1z.com
- DNS ASK ge###.api520.com
- DNS ASK cc.##i520.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''