Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Web Event Logger' = '{79FEACFF-FFCE-815E-A900-316290B5B738}'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1601' = '00000000'
- <SYSTEM32>\nmibel32.exe
- <SYSTEM32>\bhoico32.dll
- <SYSTEM32>\surf.dat
- %TEMP%\bqbcjokn.htm
- %TEMP%\bcmbbfmh.htm
- ClassName: 'IEFrame' WindowName: 'MicroSoft-Corp1 - Microsoft Internet Explorer'
- ClassName: 'IEFrame' WindowName: 'MicroSoft-Corp2 - Microsoft Internet Explorer'
- ClassName: '' WindowName: ''
- '<SYSTEM32>\nmibel32.exe'
- '<SYSTEM32>\nmibel32.exe' ' (со скрытым окном)
- '%ProgramFiles%\internet explorer\iexplore.exe' %TEMP%\bcmbbfmh.htm
- '%ProgramFiles%\internet explorer\iexplore.exe' %TEMP%\bqbcjokn.htm
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles%\Microsoft Office\Office12\GrooveUtil.DLL",GetResourceModulePath OGda08i8HqD0HQDI3mmG8Cuno1nMCwaG
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles%\Microsoft Office\Office12\GrooveUtil.DLL",GetResourceModulePath hhm4Vp2gn3pnUTCv/2QVfxNs0Ff1SM/b