[<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'И¤НжУОП·' = '<Drive name for removable media>:\И¤НжУОП·\17wan.exe'
Creates the following files on removable media:
<Drive name for removable media>:\И¤НжУОП·\offline.html
<Drive name for removable media>:\И¤НжУОП·\offlinel.html
<Drive name for removable media>:\И¤НжУОП·\logo.ico
<Drive name for removable media>:\И¤НжУОП·\minibrowser.exe
<Drive name for removable media>:\И¤НжУОП·\И¤НжНш.lnk
<Drive name for removable media>:\И¤НжУОП·\images\loading.gif
<Drive name for removable media>:\И¤НжУОП·\images\platformbg.jpg
<Drive name for removable media>:\И¤НжУОП·\images\bg.jpg
<Drive name for removable media>:\И¤НжУОП·\images\loading-s.gif
<Drive name for removable media>:\И¤НжУОП·\hosts
<Drive name for removable media>:\И¤НжУОП·\DownLoad.dll
<Drive name for removable media>:\И¤НжУОП·\Mfc71.dll
<Drive name for removable media>:\И¤НжУОП·\17Wan.exe
<Drive name for removable media>:\И¤НжУОП·\ComService.dll
<Drive name for removable media>:\И¤НжУОП·\Msvcp71.dll
<Drive name for removable media>:\И¤НжУОП·\SkinControls.dll
<Drive name for removable media>:\И¤НжУОП·\SocketModule.dll
<Drive name for removable media>:\И¤НжУОП·\Msvcr71.dll
<Drive name for removable media>:\И¤НжУОП·\QvodSetupPlus3.exe
Malicious functions:
To bypass firewall, removes or modifies the following registry keys:
[<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Drive name for removable media>:\И¤НжУОП·\QvodSetupPlus3.exe' = '<Drive name for removable media>:\И¤НжУОП·\QvodSetupPlus3.exe:*:Enabled:QVOD'
Creates and executes the following:
<Drive name for removable media>:\И¤НжУОП·\QvodSetupPlus3.exe
<Drive name for removable media>:\И¤НжУОП·\minibrowser.exe
Modifies file system :
Creates the following files:
%HOMEPATH%\Desktop\И¤НжНш.lnk
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\minibrowser[1].php
Если Вы продолжите использование данного сайта, это означает, что Вы даете согласие на использование нами Cookie-файлов и иных технологий по сбору статистических сведений о посетителях. Подробнее