Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Instalador do ActiveX' = '%TEMP%\AxInstSV.exe'
- %TEMP%\AxInstSV.exe
- %TEMP%\~1.bat
- <LS_APPDATA>\dw.exe
- %TEMP%\~1.bat
- 'localhost':1039
- 're#####.soccer-total.com':80
- http://re#####.soccer-total.com/ads.php?a=#########################
- DNS ASK re#####.soccer-total.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '%TEMP%\AxInstSV.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\~1.bat "%TEMP%\AxInstSV.exe"
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\find.exe' "VMware"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' "http://re#####.soccer-total.com/ads.php?a=###########################"
- '<SYSTEM32>\findstr.exe' "www.li####efensiva.org" <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /S /D /c" echo y"
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run" /v "Instalador do ActiveX" /t REG_SZ /d "%TEMP%\AxInstSV.exe"