Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winrar' = '%WINDIR%\svchoste.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Warrior' = '%WINDIR%\cscdll.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'msdtcy' = '<SYSTEM32>\msdtcy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\msdtcy.exe "<Полный путь к вирусу>"
- <SYSTEM32>\cmd.exe /c <SYSTEM32>\regedit.bat
- %WINDIR%\svchoste.exe
- <SYSTEM32>\regedit.bat
- %WINDIR%\cscdll.exe
- <SYSTEM32>\msdtcy.exe
- <SYSTEM32>\msdtcye.exe
- <SYSTEM32>\regedit.bat
- ClassName: 'Shell_TrayWnd' WindowName: ''