Техническая информация
- Средство контроля пользовательских учетных записей (UAC)
- '%WINDIR%\regedit.exe' /s "%APPDATA%\%USERNAME%.reg"
- '<SYSTEM32>\cmd.exe' /c ""C:\parco.bat""
- '<SYSTEM32>\cmd.exe' /c ""C:\credi.bat""
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonBadCertRecving' = '00000000'
- %HOMEPATH%\Internet Explorer.lnk
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %APPDATA%\%USERNAME%.reg
- C:\parco.txt
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- C:\mitos.pac
- C:\lazer.gif
- C:\credi.txt
- <DRIVERS>\etc\lmhosts
- C:\mitos.pac
- <DRIVERS>\etc\lmhosts
- C:\lazer.gif
- %APPDATA%\%USERNAME%.reg
- C:\parco.bat
- C:\credi.bat
- <DRIVERS>\etc\hosts
- <DRIVERS>\etc\lmhosts.sam
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- C:\parco.txt в C:\parco.bat
- C:\credi.txt в C:\credi.bat
- %HOMEPATH%\Start Menu\Programs\Internet Explorer.lnk
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- '21#.#2.83.130':8081
- '21#.#2.83.130':80
- 'localhost':1039
- http://21#.#2.83.130/images/data/readme.txt
- http://21#.#2.83.130/images/data/newconrad.txt
- http://21#.#2.83.130/data/cnrgw.gif
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''