Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'winchk' = '%ALLUSERSPROFILE%\Application Data\WebTemp\winchk.exe'
- Библиотека-обработчик для всех процессов: %ALLUSERSPROFILE%\Application Data\WebTemp\cssys.dll
- %ALLUSERSPROFILE%\application data\netext\udat.dat
- %ALLUSERSPROFILE%\application data\webtemp\winchk.exe
- %ALLUSERSPROFILE%\application data\webtemp\cssys.dll
- %ALLUSERSPROFILE%\application data\webtemp\iusys.dll
- %ALLUSERSPROFILE%\application data\netext\user\uman.dat
- %ALLUSERSPROFILE%\application data\netext\user\action.log
- %ALLUSERSPROFILE%\application data\netext\user\sysinfo.log
- %ALLUSERSPROFILE%\application data\webtemp\winchk.exe
- %ALLUSERSPROFILE%\application data\webtemp\cssys.dll
- %ALLUSERSPROFILE%\application data\webtemp\iusys.dll
- DNS ASK re###espy.com
- ClassName: 'RSClass' WindowName: 'RS'
- ClassName: 'SpyClass' WindowName: 'RemoteSpy'
- ClassName: '#32770' WindowName: ''
- '%ALLUSERSPROFILE%\application data\webtemp\winchk.exe'