Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Vssoft' = '<SYSTEM32>\devmon.exe'
- скрытых файлов
- <SYSTEM32>\devmon.exe
- <SYSTEM32>\cmd.exe /c <SYSTEM32>\auto.bat
- <SYSTEM32>\netstat.exe -a -n
- NtQuerySystemInformation, драйвер-обработчик: DisplayMgr.sys
- <SYSTEM32>\devmon.exe
- <SYSTEM32>\Mcro\excel.xls_
- <SYSTEM32>\Mcro\excel4.xls_
- <SYSTEM32>\Mcro\winword2.doc
- <SYSTEM32>\Mcro\port.tmp
- <SYSTEM32>\Mcro\20120627_10002_.tmp
- <SYSTEM32>\auto.bat
- <SYSTEM32>\Mcro\winword.doc_
- <SYSTEM32>\Mcro\winword2.doc_
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\checkip.dyndns[1]
- <SYSTEM32>\log.txt
- <SYSTEM32>\devmon.exe
- <DRIVERS>\DisplayMgr.sys
- <SYSTEM32>\Mcro\excel4.xls
- <SYSTEM32>\Mcro\winword.doc
- <SYSTEM32>\Mcro\Info.tmp
- <SYSTEM32>\Mcro\excel.xls
- <SYSTEM32>\Mcro\winword.doc
- <SYSTEM32>\Mcro\port.tmp
- <SYSTEM32>\Mcro\Info.tmp
- <SYSTEM32>\Mcro\winword2.doc_
- <SYSTEM32>\Mcro\winword2.doc
- <SYSTEM32>\Mcro\winword.doc_
- <SYSTEM32>\Mcro\excel.xls
- <SYSTEM32>\Mcro\20120627_10002_.tmp
- <SYSTEM32>\log.txt
- <SYSTEM32>\Mcro\excel4.xls_
- <SYSTEM32>\Mcro\excel4.xls
- <SYSTEM32>\Mcro\excel.xls_
- '67.##5.160.76':465
- 'ch####p.dyndns.org':80
- ch####p.dyndns.org/
- DNS ASK sm##.#ail.yahoo.com
- DNS ASK ch####p.dyndns.org
- ClassName: 'Indicator' WindowName: ''