Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'aura' = '%WINDIR%\aura.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\r_server] 'Start' = '00000002'
- <LS_APPDATA>\ip.exe
- %WINDIR%\msdtc.exe /service /start /silence /install /silence
- <LS_APPDATA>\zaero.exe
- <SYSTEM32>\reg.exe add "hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v aura /d "%WINDIR%\aura.exe" /f
- <SYSTEM32>\reg.exe import "<LS_APPDATA>\radmin.reg"
- [<HKCU>\Software\ORL\WinVNC3]
- [<HKLM>\SOFTWARE\ORL\WinVNC3]
- %WINDIR%\msdtc.exe
- %TEMP%\ipgeobase.exe
- %TEMP%\cidr_ru_master_index.db
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\48625[1].gif
- %WINDIR%\aura.exe
- %WINDIR%\AdmDll.dll
- <LS_APPDATA>\ip.exe
- <LS_APPDATA>\AdmDll.dll
- <LS_APPDATA>\msdtc.exe
- %TEMP%\~1.bat
- <LS_APPDATA>\start_rom.exe
- <LS_APPDATA>\zaero.exe
- <LS_APPDATA>\radmin.reg
- %TEMP%\~1.bat
- <LS_APPDATA>\zaero.exe
- <LS_APPDATA>\start_rom.exe
- <LS_APPDATA>\ip.exe
- <LS_APPDATA>\radmin.reg
- %TEMP%\~1.bat
- <LS_APPDATA>\msdtc.exe
- <LS_APPDATA>\AdmDll.dll
- '2i#.ru':80
- 2i#.ru/member_photo/48625.gif
- DNS ASK 2i#.ru
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''