Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfmon' = '%TEMP%\Project1\Project1.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\Project1.exe.lnk
- <SYSTEM32>\attrib.exe +r +h +s "%TEMP%\bootId.ini"
- %TEMP%\Project1\Project1.exe
- %TEMP%\bootId.ini.tmp.part
- %TEMP%\bootId.ini
- %TEMP%\Antпvir.exe
- %TEMP%\Project1.exe
- %TEMP%\system_occupation.dat
- %TEMP%\bootId.ini
- 'localhost':80
- localhost/kasparsky/new_id.php?pa##########################################################################
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''