Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'DWQueuedReporting' = '"%CommonProgramFiles%\Microsoft Shared\DW\dwtrig20.exe" -t'
- [<HKLM>\SYSTEM\ControlSet001\Services\strsvc] 'ImagePath' = '%ProgramFiles%\Internet Explorer\SIGNUP\data\strsvc.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\strsvc] 'Start' = '00000002'
- %WINDIR%\pchealth\ERRORREP\QSIGNOFF\4245D.cab
- %WINDIR%\pchealth\ERRORREP\QSIGNOFF\4245D.txt
- %WINDIR%\pchealth\ERRORREP\QSIGNOFF\dwq.snt
- %WINDIR%\Temp\3BDA4.tmp
- %ProgramFiles%\Internet Explorer\SIGNUP\data\strsvc.exe
- %WINDIR%\Temp\dw.log
- %WINDIR%\Temp\3AEEE.dmp
- %WINDIR%\Temp\3AEEE.dmp
- %WINDIR%\Temp\3BDA4.tmp
- 'cc####.#00webhostapp.com':80
- 'wp#d':80
- http://cc####.#00webhostapp.com/s.php
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK cc####.#00webhostapp.com
- DNS ASK wp#d
- '%ProgramFiles%\Internet Explorer\SIGNUP\data\strsvc.exe'
- '<SYSTEM32>\sc.exe' start strsvc
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1228
- '<SYSTEM32>\sc.exe' create strsvc binPath= "%ProgramFiles%\Internet Explorer\SIGNUP\data\strsvc.exe" DisplayName= "Windows STR Service" start= auto
- '<SYSTEM32>\cmd.exe' /C ping localhost -n 4 > nul & sc create strsvc binPath= "%ProgramFiles%\Internet Explorer\SIGNUP\data\strsvc.exe" DisplayName= "Windows STR Service" start= auto & ping localhost -n 4 > nul & s...
- '<SYSTEM32>\ping.exe' localhost -n 4