Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Processus hote pour les services Windows' = '\sys32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Processus hote pour les services Windows' = '%APPDATA%\sys32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'n92A47iG' = '%HOMEPATH%\g95Z27uQ\svchost.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- C:\sys32\svchost.exe
- %APPDATA%\imlgs\31-03-2014
- %APPDATA%\install.imp
- %APPDATA%\sys32\svchost.exe
- %HOMEPATH%\m26I80kQ.QX7
- %TEMP%\aut1.tmp
- %HOMEPATH%\d28O68bB.txt
- C:\<Имя вируса>.exe
- %HOMEPATH%\d28O68bB.txt
- %HOMEPATH%\m26I80kQ.QX7
- %TEMP%\aut1.tmp
- 'ki######urgy22.no-ip.biz':4547
- DNS ASK ki######urgy22.no-ip.biz
- ClassName: 'Indicator' WindowName: '(null)'