Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows NT Login Application' = '%APPDATA%\winlogons.exe'
- %APPDATA%\bits2\unzip.exe (загружен из сети Интернет) %APPDATA%\bits2\file.zip -d %APPDATA%\bits2
- %APPDATA%\winlogons.exe
- <SYSTEM32>\wscript.exe "%APPDATA%\bits2\windows.vbs"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\unzip[1].exe
- %APPDATA%\bits2\unzip.exe
- %APPDATA%\bits2\windows.vbs
- %APPDATA%\winlogons.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\file[1].zip
- %APPDATA%\bits2\file.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\unzip[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\file[1].zip
- 'st###works.com':80
- 'www.mo####anblade.com':80
- 'gi##ub.com':443
- st###works.com/dev/unzip.exe
- www.mo####anblade.com/ftp/pics/articles/file.zip
- DNS ASK st###works.com
- DNS ASK www.mo####anblade.com
- DNS ASK gi##ub.com
- ClassName: 'Indicator' WindowName: ''