Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SusClientId' = '000003B391933250.exe'
- Диспетчера задач (Taskmgr)
- Редактора реестра (RegEdit)
- Центр обеспечения безопасности (Security Center)
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.com;.cmd;'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
- [<HKCU>\Software\Microsoft\Internet Explorer\Download] 'CheckExeSignatures' = 'no'
- [<HKCU>\Software\Microsoft\Internet Explorer\Download] 'RunInvalidSignatures' = '00000001'
- <SYSTEM32>\000003B391933250.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\expressos[1].cfg
- <SYSTEM32>\expressos.cfg
- <SYSTEM32>\vermelho.sys
- <SYSTEM32>\borlndmm.dll
- 'we######magila.no-ip.org':661
- 'co#######caobbb.webcindario.com':80
- 'localhost':1036
- co#######caobbb.webcindario.com/expressos.cfg
- DNS ASK co#######caobbb.webcindario.com
- DNS ASK we######magila.no-ip.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TfBeholder' WindowName: ''