Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\HpM3Util.exe
- %HOMEPATH%\Start Menu\Programs\Startup\EFS0.TMP
- <Полный путь к вирусу>
- '<SYSTEM32>\services.exe'
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e1deea19bf379aa57dfec4733c9b7312_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Microsoft\SystemCertificates\My\Certificates\609A9FA2EBBF66A7BB06F1413F76451B5617D04F
- C:\System Volume Information\EFS0.LOG
- %APPDATA%\verison.dll
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\247c4f1e-7af5-4036-8b49-9e2dab19c73c
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- C:\System Volume Information\EFS0.LOG
- %HOMEPATH%\Start Menu\Programs\Startup\EFS0.TMP
- 'uo#####sciscqaiu.org':80
- '74.##5.232.51':80
- 74.##5.232.51/
- uo#####sciscqaiu.org/
- DNS ASK uo#####sciscqaiu.org
- DNS ASK www.google.com