Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = 'ABC.exe'
- %WINDIR%\regedit.exe
- <SYSTEM32>\cmd.exe /c %WINDIR%\17mt.bat
- <SYSTEM32>\wscript.exe "<Текущая директория>\tem.vbs"
- C:\17mt.ico
- %WINDIR%\reg.reg
- %WINDIR%\17mt.bat
- <Текущая директория>\Hook.dll
- <SYSTEM32>\1.ime
- <Текущая директория>\tem.vbs
- <SYSTEM32>\activeds.tlb
- <SYSTEM32>\actxprxy.dll
- <SYSTEM32>\admparse.dll
- <SYSTEM32>\activeds.dll
- <SYSTEM32>\acctres.dll
- <SYSTEM32>\acledit.dll
- <SYSTEM32>\aclui.dll
- 'localhost':1034
- DNS ASK www.ba##u.com
- '<IP-адрес в локальной сети>':1035
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'CicLoaderWndClass' WindowName: ''
- ClassName: '' WindowName: 'Microsoft Internet Explorer'
- ClassName: 'Progman' WindowName: ''