Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Skype' = '<SYSTEM32>\Skype.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Skype' = '<SYSTEM32>\Skype.exe'
- '%TEMP%\filename2.exe' keyscramblerwiresharkollydbgOutpostNormanAnubisSandboxieThreatSeekitZoneNOD32DefenderVMkaspersky
- '%TEMP%\DmbkAIrmBr.exe' zinoubi12@mail.com zinoubi.00@gmail.com smtp.mail.com zinoubi12@mail.com 76634241 587 chrome,firefox,filezilla,imvu,steam,
- AVP.EXE
- bdagent.exe
- outpost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\google[1]
- %TEMP%\filename2.exe
- %TEMP%\DmbkAIrmBr.exe
- из <Полный путь к вирусу> в <SYSTEM32>\Skype.exe
- '74.##5.232.51':80
- 'localhost':1040
- 'sm##.mail.com':587
- 74.##5.232.51/
- DNS ASK www.google.com
- DNS ASK sm##.mail.com
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'VMDragDetectWndClass' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'