Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sim1' = '%WINDIR%\com1.exe'
- <SYSTEM32>\cmd.exe /c %WINDIR%\del.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\setup_iesearchtoolbar[1].exe
- %WINDIR%\del.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\programs[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sim1.hurricangroup[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\installed[1].php
- 'to####rpartner.com':80
- 'si##.##rricangroup.com':80
- to####rpartner.com/programs.txt
- to####rpartner.com/setup_iesearchtoolbar.exe
- si##.##rricangroup.com/
- to####rpartner.com/installed.php?wm######
- DNS ASK to####rpartner.com
- DNS ASK si##.##rricangroup.com