Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\System\jvtune.exe' = '%WINDIR%\System\jvtune.exe:*:Enabled:KL'
- %WINDIR%\system\jvtune.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\1[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\1[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\1[1].php
- %WINDIR%\system\jvtune.exe
- %WINDIR%\system\ddid
- %WINDIR%\system\ddid
- %WINDIR%\system\jvtune.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\1[1].php
- 'bo###ss88.co.de':80
- 'x1#.co.de':80
- bo###ss88.co.de/1/1.php?ui##################
- x1#.co.de/1/1.php?ui##################
- DNS ASK bo###ss88.co.de
- DNS ASK x1#.co.de