Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Norton System ' = '<SYSTEM32>\imgrt.scr'
- <SYSTEM32>\imgrt.scr (загружен из сети Интернет)
- <SYSTEM32>\cmd.exe /c "%TEMP%\EZC1.bat"
- %TEMP%\EZC1.bat
- <SYSTEM32>\imgrt.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\carta[1].exe
- 'localhost':1037
- 'www.fi####gratis.com.br':80
- 'localhost':1034
- 'ba######k.webcindario.com':80
- www.fi####gratis.com.br/
- ba######k.webcindario.com/carta.exe
- DNS ASK www.fi####gratis.com.br
- DNS ASK ba######k.webcindario.com
- '<IP-адрес в локальной сети>':1035
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''