Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Proxy' = '%APPDATA%\Proxy.exe'
- Диспетчера задач (Taskmgr)
- '%WINDIR%\regedit.exe' /s C:\Comando.Reg
- '<SYSTEM32>\cmd.exe' /c C:\Proxy.Bat
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyOverride' = 'local'
- [<HKLM>\SYSTEM\ControlSet001\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = 'http://198.24.179.110/script.pac'
- C:\Comando.Reg
- C:\Flash.bat
- C:\Proxy.Bat
- %TEMP%\enviadedemail.tmp
- %APPDATA%\Proxy.exe
- C:\Chrome.bat
- C:\FF.bat
- C:\IE.bat
- C:\Safari.bat
- C:\Opera.bat
- %APPDATA%\Proxy.exe
- C:\Flash.bat
- C:\Opera.bat
- C:\Proxy.Bat
- C:\Safari.bat
- C:\FF.bat
- C:\Comando.Reg
- C:\IE.bat
- C:\Chrome.bat
- 'ne####e.1eko.com':80
- http://ne####e.1eko.com/contador.php?us###############
- DNS ASK ne####e.1eko.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Indicator' WindowName: ''