Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '%HOMEPATH%\Local Settings\Hewlett-Packard\app.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '' = '%HOMEPATH%\Local Settings\Microsoft\Windows Live\winhelp.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'appnh' = '%HOMEPATH%\Local Settings\Hewlett-Packard\app.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'NotePad' = '%HOMEPATH%\Local Settings\Microsoft\notepad.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\45541.scr
- %HOMEPATH%\Start Menu\Programs\Startup\34550.exe
- %HOMEPATH%\Start Menu\Programs\Startup\32489.exe
- %HOMEPATH%\Start Menu\Programs\Startup\31096.exe
- %HOMEPATH%\Start Menu\Programs\Startup\27517.exe
- %HOMEPATH%\Start Menu\Programs\Startup\31051.exe
- %HOMEPATH%\Start Menu\Programs\Startup\33533.scr
- %HOMEPATH%\Start Menu\Programs\Startup\34197.scr
- %HOMEPATH%\Start Menu\Programs\Startup\31115.scr
- %HOMEPATH%\Start Menu\Programs\Startup\29709.exe
- %HOMEPATH%\Start Menu\Programs\Startup\15436.exe
- %HOMEPATH%\Start Menu\Programs\Startup\18916.scr
- %HOMEPATH%\Start Menu\Programs\Startup\10296.scr
- %HOMEPATH%\Start Menu\Programs\Startup\<Имя вируса>.exe
- %HOMEPATH%\Start Menu\Programs\Startup\8376.scr
- %HOMEPATH%\Start Menu\Programs\Startup\21409.scr
- %HOMEPATH%\Start Menu\Programs\Startup\23488.scr
- %HOMEPATH%\Start Menu\Programs\Startup\25296.exe
- %HOMEPATH%\Start Menu\Programs\Startup\21461.scr
- %HOMEPATH%\Start Menu\Programs\Startup\23212.scr
- Редактора реестра (RegEdit)
- '%TEMP%\31051.exe'
- '%TEMP%\33533.scr' /S
- '%TEMP%\36742.exe'
- '%TEMP%\31115.scr' /S
- '%TEMP%\29709.exe'
- '%TEMP%\34197.scr' /S
- '%TEMP%\36772.exe'
- '%TEMP%\48452.scr' /S
- '%TEMP%\56762.scr' /S
- '%TEMP%\63680.scr' /S
- '%TEMP%\34713.exe'
- '%TEMP%\43850.scr' /S
- '%TEMP%\50468.scr' /S
- '%TEMP%\34550.exe'
- '%TEMP%\18916.scr' /S
- '%TEMP%\23212.scr' /S
- '%TEMP%\21461.scr' /S
- '%TEMP%\8376.scr' /S
- '%TEMP%\10296.scr' /S
- '%TEMP%\15436.exe'
- '%TEMP%\25296.exe'
- '%TEMP%\32489.exe'
- '%TEMP%\27517.exe'
- '%TEMP%\45541.scr' /S
- '%TEMP%\23488.scr' /S
- '%TEMP%\21409.scr' /S
- '%TEMP%\31096.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[308218]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[306171]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[321328]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[327750]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[322750]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[294750]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[276281]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[274296]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[293125]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[294578]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[293109]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[333203]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[385953]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[380500]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[388218]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[394484]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[389953]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[374421]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[341625]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[338312]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[356812]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[370140]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[360171]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[180687]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[179843]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[192093]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[209734]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[192937]BootLog.cmd" "
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /t Reg_dword /v DisableRegistryTools /f /d 1
- '<SYSTEM32>\schtasks.exe' /create /tn "System Restore" /tr "'%HOMEPATH%\Local Settings\Microsoft\Windows\mspaint.exe'" /sc ONLOGON /ru "CRNJEUFU\%USERNAME%"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "System Restore"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "WindowsExplore"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[169312]BootLog.cmd" "
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsExplore" /tr "'%HOMEPATH%\Local Settings\Microsoft\Windows\Explorer\WmiPrivise.exe'" /sc ONLOGON /ru "CRNJEUFU\%USERNAME%"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[210171]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[260812]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[239390]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[260437]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[263312]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[263671]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[239156]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[214031]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[212156]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[233765]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[235828]BootLog.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Win[234515]BootLog.cmd" "
- %TEMP%\33533.scr
- %TEMP%\Win[333203]BootLog.cmd
- %TEMP%\31051.exe
- %TEMP%\Win[327750]BootLog.cmd
- %TEMP%\36772.exe
- %TEMP%\Win[341625]BootLog.cmd
- %TEMP%\36742.exe
- %TEMP%\Win[338312]BootLog.cmd
- %TEMP%\Win[322750]BootLog.cmd
- %TEMP%\31115.scr
- %TEMP%\Win[306171]BootLog.cmd
- %TEMP%\Win[294750]BootLog.cmd
- %TEMP%\34550.exe
- %TEMP%\34197.scr
- %TEMP%\Win[321328]BootLog.cmd
- %TEMP%\Win[308218]BootLog.cmd
- %TEMP%\29709.exe
- %TEMP%\34713.exe
- %TEMP%\Win[389953]BootLog.cmd
- %TEMP%\Win[394484]BootLog.cmd
- %TEMP%\56762.scr
- %TEMP%\Win[388218]BootLog.cmd
- %TEMP%\71955.scr
- %TEMP%\Win[405328]BootLog.cmd
- %TEMP%\63680.scr
- %TEMP%\Win[398609]BootLog.cmd
- %TEMP%\Win[385953]BootLog.cmd
- %TEMP%\Win[360171]BootLog.cmd
- %TEMP%\50468.scr
- %TEMP%\43850.scr
- %TEMP%\Win[356812]BootLog.cmd
- %TEMP%\Win[374421]BootLog.cmd
- %TEMP%\Win[380500]BootLog.cmd
- %TEMP%\48452.scr
- %TEMP%\Win[370140]BootLog.cmd
- %TEMP%\Win[294578]BootLog.cmd
- %TEMP%\Win[212156]BootLog.cmd
- %TEMP%\23212.scr
- %TEMP%\Win[209734]BootLog.cmd
- %TEMP%\Win[210171]BootLog.cmd
- %TEMP%\25296.exe
- %TEMP%\Win[233765]BootLog.cmd
- %TEMP%\21461.scr
- %TEMP%\Win[214031]BootLog.cmd
- %TEMP%\18916.scr
- %TEMP%\Win[179843]BootLog.cmd
- %TEMP%\Win[180687]BootLog.cmd
- %TEMP%\Win[169312]BootLog.cmd
- %TEMP%\8376.scr
- %TEMP%\Win[192937]BootLog.cmd
- %TEMP%\15436.exe
- %TEMP%\10296.scr
- %TEMP%\Win[192093]BootLog.cmd
- %TEMP%\Win[234515]BootLog.cmd
- %TEMP%\32489.exe
- %TEMP%\Win[274296]BootLog.cmd
- %TEMP%\Win[263671]BootLog.cmd
- %TEMP%\27517.exe
- %TEMP%\Win[293109]BootLog.cmd
- %TEMP%\Win[293125]BootLog.cmd
- %TEMP%\Win[276281]BootLog.cmd
- %TEMP%\45541.scr
- %TEMP%\Win[263312]BootLog.cmd
- %TEMP%\23488.scr
- %TEMP%\Win[239156]BootLog.cmd
- %TEMP%\Win[235828]BootLog.cmd
- %TEMP%\21409.scr
- %TEMP%\Win[260437]BootLog.cmd
- %TEMP%\Win[260812]BootLog.cmd
- %TEMP%\Win[239390]BootLog.cmd
- %TEMP%\31096.exe
- 'sa##e11.org':80
- sa##e11.org/INSANE/insane/QueryCommand.php?HW##############################################################
- DNS ASK sa##e11.org