Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Download Manager2' = '%HOMEPATH%\Downloads\crss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Document Explorer2' = '%HOMEPATH%\Documents\crss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Profile Manager2' = '%HOMEPATH%\crss.exe'
- %HOMEPATH%\crss.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\purebot2.sytes[1]
- %HOMEPATH%\crss.exe
- %HOMEPATH%\crss.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\purebot2.sytes[1]
- %HOMEPATH%\crss.exe
- 'pu####t2.sytes.net':80
- pu####t2.sytes.net/
- DNS ASK pu####t2.sytes.net
- ClassName: 'Indicator' WindowName: ''