Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'CatalogMonitor' = '"%ALLUSERSPROFILE%\Microsoft AData\catmon.exe" /h'
- %ALLUSERSPROFILE%\Microsoft AData\setup.exe /p
- %ALLUSERSPROFILE%\Microsoft AData\setup.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\setup[1].php
- %ALLUSERSPROFILE%\Microsoft AData\setup.exe
- %ALLUSERSPROFILE%\Microsoft AData\catmon.exe
- %ALLUSERSPROFILE%\Microsoft AData\t.sid
- 'go###tprt3.com':80
- 'ge###rtprt3.com':80
- go###tprt3.com/install/?tr############
- ge###rtprt3.com/smrtprt/setup.php?tr############
- DNS ASK go###tprt3.com
- DNS ASK ge###rtprt3.com