Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'barosearch' = '%ProgramFiles%\barosearch\bsearch.exe'
- '' (загружен из сети Интернет)
- %ProgramFiles%\barosearch\bsearch.exe
- %APPDATA%\erase.bat
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\bsearchsvc[1].exe
- %ProgramFiles%\barosearch\bsearchsvc.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\ver[1].xml
- <Полный путь к файлу>
- 'localhost':1037
- 'lo#.###osearch.co.kr':80
- 'do######.barosearch.co.kr':80
- http://lo#.###osearch.co.kr/bacon2/AppLog.php?a=#########################################################
- http://do######.barosearch.co.kr/bsearch/A55727927/bsearchsvc.exe
- http://do######.barosearch.co.kr/bsearch/A55727927/ver.xml
- DNS ASK lo#.###osearch.co.kr
- DNS ASK do######.barosearch.co.kr
- '%ProgramFiles%\barosearch\bsearch.exe'
- '%ProgramFiles%\barosearch\bsearchsvc.exe' /silent /install
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\erase.bat" "
- '<SYSTEM32>\sc.exe' description BCSvc