Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Service Process' = '<SYSTEM32>\config\service.exe'
- <SYSTEM32>\config\service.exe
- [<HKLM>\SOFTWARE\Miranda]
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trillian]
- [<HKCU>\Software\Far\Plugins\FTP\Hosts]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\connect[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\getftp[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\getemails[1].php
- <SYSTEM32>\config\service.exe
- <SYSTEM32>\options.dll
- <SYSTEM32>\ielog.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\connect[1].php
- 'www.st###-panel.com':80
- www.st###-panel.com/getemails.php?em#####
- www.st###-panel.com/getftp.php?pa###
- www.st###-panel.com/connect.php?ut#################################################################################
- DNS ASK www.st###-panel.com
- '<IP-адрес в локальной сети>':1036