Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftWinUpdate' = '%APPDATA%\spoolsv.exe'
- '%TEMP%\service'
- '%TEMP%\jqs'
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v MicrosoftWinUpdate /d %APPDATA%\spoolsv.exe /f
- '%TEMP%\services'
- %TEMP%\service
- %APPDATA%\driver\videovrx.vxd
- %TEMP%\jqs
- %APPDATA%\driver\service.drv
- %APPDATA%\spoolsv.exe
- %APPDATA%\driver\avsdrvdvx6.dll
- %TEMP%\services
- %TEMP%\service
- %TEMP%\service в <Текущая директория>\
- 'go###e.com.br':80
- 'www.sh###mper.org':80
- http://www.sh###mper.org/esperanca.gif
- http://go###e.com.br/index.html
- http://www.sh###mper.org/sair_do_brefo/acesso.php
- DNS ASK go###e.com.br
- DNS ASK www.sh###mper.org
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: 'windgroup'
- ClassName: '' WindowName: 'R'
- ClassName: 'Shell_TrayWnd' WindowName: ''