Техническая информация
- <SYSTEM32>\ntvdm.exe -f -i1
- <SYSTEM32>\ntvdm.exe -f -i3
- <SYSTEM32>\ntvdm.exe -f -i2
- <SYSTEM32>\cmd.exe /c ""%TEMP%\upyyx.bat" "
- <SYSTEM32>\taskkill.exe /F /IM <Полный путь к вирусу>
- %TEMP%\dw.log
- %WINDIR%\Temp\scs4.tmp
- %WINDIR%\Temp\scs5.tmp
- %TEMP%\2AEA5.dmp
- %WINDIR%\Temp\scs6.tmp
- %WINDIR%\Temp\scs3.tmp
- %APPDATA%\tiger.exe
- %TEMP%\upyyx.bat
- %APPDATA%\KhRsRaPjWDqH.exe
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs4.tmp
- %WINDIR%\Temp\scs5.tmp
- %WINDIR%\Temp\scs6.tmp
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs3.tmp
- %WINDIR%\Temp\scs2.tmp
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-a4c.a50.3a0002'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-9e0.9f0.390005'
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-9e8.9ec.380002'