Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'windefender' = '<LS_APPDATA>\temdefender\windefender.exe'
- '' (загружен из сети Интернет)
- <LS_APPDATA>\temdefender\windefender.exe
- 'localhost':1040
- 'localhost':1042
- 'go###e.com.br':80
- 'ek###neness.org':80
- http://www.go###e.com.br/ via go###e.com.br
- http://www.ek###neness.org/site/qwsazxswedc.ds via ek###neness.org
- DNS ASK www.go###e.com.br
- DNS ASK www.ek###neness.org
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<LS_APPDATA>\temdefender\windefender.exe'
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome