Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Audio HD Driver' = '%TEMP%\spolsvrr.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Audio HD Driver' = '%TEMP%\spolsvrr.exe'
- скрытых файлов
- %WINDIR%\twunk_32.exe
- %TEMP%\spolsvrr.exe
- %APPDATA%\spolsvrr.exe
- %TEMP%\delete.bat
- %TEMP%\user2.txt
- %APPDATA%\userlog.dat
- %TEMP%\user7
- %TEMP%\user8
- %TEMP%\twain.log
- %TEMP%\spolsvrr.exe
- %APPDATA%\spolsvrr.exe
- %APPDATA%\userlog.dat
- %TEMP%\user2.txt
- %TEMP%\user8
- %TEMP%\user7
- %TEMP%\user8
- %TEMP%\user7
- '10#.#0.222.209':6881
- http://www.ga###123.biz.nf/sqlite3.dll
- DNS ASK ga###123.biz.nf
- DNS ASK bu####xxx.no-ip.org
- DNS ASK bu####xxx.no-ip.biz
- '%WINDIR%\twunk_32.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\delete.bat""
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe'