Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '"%APPDATA%\WinDefender\windefender.exe"'
- '%TEMP%\svchost.exe'
- '%TEMP%\Installer.exe'
- '%TEMP%\svchost32.exe'
- '<SYSTEM32>\regsvr32.exe' /s "%APPDATA%\IE\bho.dll"
- '<SYSTEM32>\regsvr32.exe' /u /s "%APPDATA%\IE\bho.dll"
- '<SYSTEM32>\wscript.exe' "%TEMP%\j.vbs"
- %APPDATA%\firefox@mozilla.com\chrome.manifest
- %APPDATA%\firefox@mozilla.com\install.rdf
- %TEMP%\j.vbs
- %TEMP%\svchost.exe
- %APPDATA%\WinDefender\windefender.exe
- %APPDATA%\IE\bho.dll
- %APPDATA%\IE\settings.dat
- %APPDATA%\firefox@mozilla.com\content\settings.js
- %APPDATA%\firefox@mozilla.com\content\overlay.js
- %APPDATA%\firefox@mozilla.com\content\overlay.xul
- %TEMP%\4.da_
- %TEMP%\5.da_
- %TEMP%\3.da_
- %TEMP%\1.da_
- %TEMP%\2.da_
- %TEMP%\8.da_
- %TEMP%\Installer.exe
- %TEMP%\svchost32.exe
- %TEMP%\6.da_
- %TEMP%\7.da_
- 'ks#####4.kimsufi.com':80
- ks#####4.kimsufi.com/tools/parser.php?us######################################################################################
- DNS ASK ks#####4.kimsufi.com
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'