Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BPL00050000040Cl' = 'C:\Intel\LCD\Disc\Brt_Cable.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'OPC0050265d4c' = 'C:\Intel\LCD\Disc\Brt_Cable.exe'
- %WINDIR%\explorer.exe
- Brt_Cable.exe
- %APPDATA%\Microsoft\Windows\Templates\IO\xStorages.LZH
- C:\Intel\LCD\Disc\Brt_Cable.exe
- %APPDATA%\Microsoft\Windows\Templates\IO\xStorages.001
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\cv[1].zip
- %APPDATA%\Microsoft\Windows\Templates\IO\xStorages.GZ
- %APPDATA%\Microsoft\Windows\Templates\IO\xStorages.LZH
- C:\Intel\LCD\Disc\Brt_Cable.exe
- %APPDATA%\Microsoft\Windows\Templates\IO\xStorages.001
- <Полный путь к файлу>
- %APPDATA%\Microsoft\Windows\Templates\IO\xStorages.LZH
- %APPDATA%\Microsoft\Windows\Templates\IO\xStorages.LZH
- 'localhost':1038
- 'do#####ewide.weebly.com':80
- http://do#####ewide.weebly.com/uploads/1/1/8/3/118351659/cv.zip
- DNS ASK do#####ewide.weebly.com
- '<Полный путь к файлу>'
- 'C:\Intel\LCD\Disc\Brt_Cable.exe'
- '<SYSTEM32>\svchost.exe'
- '%WINDIR%\explorer.exe'