Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Полный путь к вирусу>' = '<Полный путь к вирусу>:*:Enabled:іИЧУдЇААЖч'
- <SYSTEM32>\sc.exe config UI0Detect start= disabled
- <SYSTEM32>\sc.exe stop UI0Detect
- <SYSTEM32>\cmd.exe /c %TEMP%\_tmp9.bat
- %ALLUSERSPROFILE%\Application Data\chengziie\popset.ini
- %HOMEPATH%\AppData\LocalLow\KfeExplorer\Cache\TypedURLs.dat
- %HOMEPATH%\AppData\LocalLow\KfeExplorer\Cache\SearchUrls.dat
- %TEMP%\_tmp9.bat
- 'cj#.##engziie.com':8900
- 'localhost':1044
- 'www.ba##u.com':80
- DNS ASK cl#####t.chengziie.com
- DNS ASK ad###.chengziie.com
- DNS ASK cl#####x.chengziie.com
- DNS ASK cl#####.chengziie.com
- DNS ASK cl###.chengziie.com
- DNS ASK cj#.##engziie.com
- DNS ASK www.ba##u.com
- DNS ASK cl####.chengziie.com
- 'cj#.##engziie.com':8899
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''