Техническая информация
- [<HKCU>\Software\Microsoft\Internet Account Manager\Accounts]
- %TEMP%\2904AO6U.cmd
- %TEMP%\~x
- %TEMP%\~y
- %TEMP%\2904AO6U.cmd
- 'localhost':1039
- 'ad#####.fastentrega.com':80
- http://ad#####.fastentrega.com/ok.php?a=###################
- DNS ASK ad#####.fastentrega.com
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2904AO6U.cmd" <Полный путь к файлу>"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' "http://ad#####.fastentrega.com/ok.php?a=#####################"
- '<SYSTEM32>\fsutil.exe' file createnew "%TEMP%\tumbs.db" 286"
- '<SYSTEM32>\reg.exe' export HKU %TEMP%\~x
- '<SYSTEM32>\cmd.exe' /S /D /c" type %TEMP%\~x "
- '<SYSTEM32>\find.exe' "Internet Explorer\Main"
- '<SYSTEM32>\cmd.exe' /c type %TEMP%\~y | <SYSTEM32>\find.exe "S-1-5-21"
- '<SYSTEM32>\cmd.exe' /S /D /c" type %TEMP%\~y "
- '<SYSTEM32>\find.exe' "S-1-5-21"