Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Update Background Intelligent Transfer Service' = '<LS_APPDATA>\HUR\[system process]svc.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<LS_APPDATA>\HUR\[system process]svc.exe' = '<LS_APPDATA>\HUR\[system ...
- '<LS_APPDATA>\HUR\win360tray.exe'
- '<LS_APPDATA>\HUR\[system process]svc.exe'
- '<LS_APPDATA>\HUR\win360tray.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "<LS_APPDATA>\HUR\[system process]svc.exe" "Update Background Intelligent Transfer Service" ENABLE
- '<LS_APPDATA>\HUR\[system process]svc.exe'
- [system process]svc.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\cat[1].php
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\e[1].php
- <LS_APPDATA>\HUR\[system process]svc.exe
- <LS_APPDATA>\HUR\win360tray.exe
- 'ip####chforum.biz':80
- 'ca###odtop.biz':80
- http://ip####chforum.biz/e.php
- http://ca###odtop.biz/cat.php
- DNS ASK ip####chforum.biz
- DNS ASK ca###odtop.biz