Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = '<SYSTEM32>\userinit.exe,C:\DOCUME~1\%USERNAME%\LOCALS~1\Temp\DCSCMIN\fMDCa.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'java7' = '%TEMP%\DCSCMIN\fMDCa.exe'
- '%TEMP%\DCSCMIN\fMDCa.exe'
- fMDCa.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\proxy1[1].vbs
- %TEMP%\DCSCMIN\fMDCa.exe
- 'localhost':1043
- 'of#######0microsoft.linkpc.net':1411
- 'localhost':1040
- 'cd#.##sya.web.tr':80
- http://cd#.##sya.web.tr/N5vbJe/proxy1.vbs
- DNS ASK of#######0microsoft.linkpc.net
- DNS ASK cd#.##sya.web.tr