Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '±Ј»¤' = '%WINDIR%\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '±Ј»¤їуКЇ' = '%WINDIR%\Miner.exe'
- '%WINDIR%\3306.exe'
- '%WINDIR%\svchost.exe'
- '%WINDIR%\3306.exe' (загружен из сети Интернет)
- '%WINDIR%\svchost.exe' (загружен из сети Интернет)
- %WINDIR%\a790299.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\a790299[1].zip
- %WINDIR%\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\yqdd[1].exe
- %WINDIR%\3306.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\3306[1].exe
- %WINDIR%\1.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\1[1].zip
- 'yk.##pddos.com':80
- yk.##pddos.com/a790299.zip
- yk.##pddos.com/yqdd.exe
- yk.##pddos.com/3306.exe
- yk.##pddos.com/1.zip
- DNS ASK yk.##pddos.com
- ClassName: 'SysPager' WindowName: '(null)'
- ClassName: 'ToolbarWindow32' WindowName: '(null)'
- ClassName: 'QVODNETOREMAINWND' WindowName: '????????????'
- ClassName: 'TrayNotifyWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'Miner.exe'
- ClassName: '(null)' WindowName: 'MinerWatch.exe'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'