Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Scan' = '<SYSTEM32>\Scan.exe'
- <SYSTEM32>\Scan.exe
- <SYSTEM32>\wscript.exe "<SYSTEM32>\Change.vbs"
- <SYSTEM32>\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\216e3aee165[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\216e3aee165[1].exe
- <SYSTEM32>\Scan.exe
- <SYSTEM32>\Change.vbs
- <SYSTEM32>\Scan.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\216e3aee165[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\216e3aee165[1].exe
- 'localhost':1058
- 'localhost':1060
- 'localhost':1056
- 'localhost':1053
- 'localhost':1054
- 'localhost':1067
- 'localhost':1069
- 'localhost':1065
- 'localhost':1061
- 'localhost':1063
- 'localhost':1041
- 'localhost':1042
- 'localhost':1039
- 'localhost':1036
- 'www.ks###mar.com':80
- 'localhost':1049
- 'localhost':1051
- 'localhost':1047
- 'localhost':1044
- 'localhost':1046
- www.ks###mar.com/up/uploads/files/216e3aee165.exe
- DNS ASK www.ks###mar.com
- ClassName: 'Indicator' WindowName: ''