Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Il31b4Q645n5pEk' = '%APPDATA%\Il31b4Q645n5pEk.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000000'
- <SYSTEM32>\cmd.exe
- %TEMP%\ihdxd.vbs
- %APPDATA%\il31b4q645n5pek.exe
- %TEMP%\java.exe
- %APPDATA%\fw.bat
- http://bi#.ly/15eoJAx
- DNS ASK bi#.ly
- DNS ASK bi##y.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\iHDXd.vbs"
- '%APPDATA%\il31b4q645n5pek.exe'
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\fw.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoControlPanel /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\fw.bat" "