Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'office xpКдИл·Ё,І»Ч°їЙДЬОЮ·ЁК№УГКдИл·Ё' = '%PROGRAM_FILES%\ctfmon.vbs'
- <SYSTEM32>\regini.exe %TEMP%\653570350745560.ini
- <SYSTEM32>\wscript.exe %TEMP%\qbgwxowa.vbs
- %HOMEPATH%\Favorites\ѕ«ІКРЎУОП·.url
- %HOMEPATH%\Favorites\МФ±¦НшЅсИХґтХЫМШјЫЗш.url
- %HOMEPATH%\Favorites\ѕ«ІКµзУ°.url
- %HOMEPATH%\Favorites\РФјјЗЙ.url
- %HOMEPATH%\Favorites\ЙПНшµјєЅ.url
- %PROGRAM_FILES%\Internet Explorer\IEXP1ORE.EXE
- %TEMP%\653570350745560.ini
- %TEMP%\qbgwxowa.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ie[1].ico
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\IEXP1ORE[1].EXE
- <SYSTEM32>\ie.ico
- '65######0745560.19881.info':80
- 'localhost':1035
- 65######0745560.19881.info/go/IEXP1ORE.EXE
- 65######0745560.19881.info/go/ie.ico
- DNS ASK 65######0745560.19881.info