Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Hostprozess fur Windows-Dienste' = '%APPDATA%\Microsoft\svchost.exe'
- '%TEMP%\SVCHOST_UPDATE.exe'
- '%APPDATA%\Microsoft\svchost.exe'
- '%TEMP%\PSC.sfx.exe' -ponline123 -d%HOMEPATH%\Local Settings\Temp
- '%TEMP%\PaySafe Card Codegenerator.exe'
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 20000
- '<SYSTEM32>\wscript.exe' "%TEMP%\new.vbs"
- %APPDATA%\Microsoft\svchost.exe
- %TEMP%\dw.log
- %TEMP%\3E83E.dmp
- %TEMP%\SVCHOST_UPDATE.exe
- %TEMP%\PSC.sfx.exe
- %TEMP%\new.vbs
- %TEMP%\PaySafe Card Codegenerator.exe
- %APPDATA%\Microsoft\svchost.exe
- %TEMP%\SVCHOST_UPDATE.exe
- 'si####new.funpic.de':80
- 'wp#d':80
- si####new.funpic.de/image.jpeg
- wp#d/wpad.dat
- DNS ASK si####new.funpic.de
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'