Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Alg' = 'C:\alg.exe'
- C:\alg.exe
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.11##.com/?13# /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.11##.com/?13# /f
- <SYSTEM32>\cmd.exe /c %WINDIR%\IE.Bat
- %WINDIR%\tj.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Post[1].Asp
- %WINDIR%\IE.Bat
- %WINDIR%\bj.txt
- %ALLUSERSPROFILE%\Documents\My Videos\PulgFile.log
- %TEMP%\Temp\НЁУГ.exe
- %TEMP%\Temp\82.exe
- C:\alg.exe
- <Текущая директория>\hello_tt.sys
- %ALLUSERSPROFILE%\Documents\My Videos\Vanzod.tmp
- <Текущая директория>\hello_tt.sys
- 'localhost':1043
- '61.##7.116.84':2011
- '12#.#sx50.info':8080
- 'localhost':1035
- '12#.#sx50.info':80
- 12#.#sx50.info/82/Post.Asp?us##########################################################################################################
- DNS ASK 12#.#sx50.info
- '<IP-адрес в локальной сети>':1036
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''