Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'hNjHcHiDoIp29100' = '%ALLUSERSPROFILE%\Application Data\hNjHcHiDoIp29100\hNjHcHiDoIp29100.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Inoyikotadoqev' = 'rundll32.exe "%WINDIR%\crunsf.dll",Startup'
- '%ALLUSERSPROFILE%\Application Data\hNjHcHiDoIp29100\hNjHcHiDoIp29100.exe' "<LS_APPDATA>\162829.exe"
- '<LS_APPDATA>\162829.exe'
- '<LS_APPDATA>\162828.exe'
- '<SYSTEM32>\rundll32.exe' "%WINDIR%\crunsf.dll",iep
- '<SYSTEM32>\rundll32.exe' "%WINDIR%\crunsf.dll",Startup
- %ALLUSERSPROFILE%\Application Data\hNjHcHiDoIp29100\hNjHcHiDoIp29100
- %ALLUSERSPROFILE%\Application Data\hNjHcHiDoIp29100\hNjHcHiDoIp29100.exe
- %TEMP%\a8B5E.tmp
- %WINDIR%\ufabosuyegan.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\CAPWSJH1.php
- <LS_APPDATA>\162829.exe
- <LS_APPDATA>\162828.exe
- %WINDIR%\crunsf.dll
- <LS_APPDATA>\162829
- <LS_APPDATA>\162829.exe
- <LS_APPDATA>\162829
- 'localhost':1039
- '19#####d1200.wordxs.net':80
- '19#.#8.113.214':80
- '69.##.195.77':80
- 19#.#8.113.214/lurl.php?af#########
- DNS ASK 19#####d1200.wordxs.net
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'