Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HDVXII' = '<SYSTEM32>\UPDATERWIN.EXE'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ROTECTIONX' = '<SYSTEM32>\Taskcall.EXE'
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\rundll32.exe' shell32.dll,Control_RunDLL <SYSTEM32>\BMX.cpl
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v EnableLUA /t REG_DWORD /d 0 /f
- <LS_APPDATA>\HJI8.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\DDD4045[1].zip
- 'www.4s##red.com':80
- www.4s##red.com/download/xr_kqahi/DDD4045.zip
- DNS ASK www.4s##red.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'