Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'analisis' = '%APPDATA%\analisis.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\usuarios[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\infectados[1].php
- %APPDATA%\analisis.exe
- '24.#7.1.142':80
- 'localhost':1036
- 'www.wa###mijnip.nl':80
- 24.#7.1.142/administrator/components/com_checkin/mlt/users/usuarios.php
- 24.#7.1.142/administrator/components/com_checkin/mlt//images/web.txt
- 24.#7.1.142/administrator/components/com_checkin/mlt//images/config.txt
- www.wa###mijnip.nl/
- 24.#7.1.142/administrator/components/com_checkin/mlt//images/titulo.txt
- 24.#7.1.142/administrator/components/com_checkin/mlt/users/infectados.php
- DNS ASK www.wa###mijnip.nl
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''