Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'braviax' = '<SYSTEM32>\braviax.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'braviax' = '<SYSTEM32>\braviax.exe'
- <DRIVERS>\beep.sys
- <SYSTEM32>\dllcache\beep.sys
- <SYSTEM32>\logonui.exe /status /shutdown
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\10250350[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\10250350[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\10250350[1]
- <SYSTEM32>\wisdstr.exe
- <SYSTEM32>\braviax.exe
- <SYSTEM32>\dllcache\figaro.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\10250350[1]
- 've#####noskilotas.com':80
- 'op####duchiosa.com':80
- 'sm####onovkajio.com':80
- 'localhost':1036
- 'tu####avigators.com':80
- ve#####noskilotas.com/10250350
- op####duchiosa.com/10250350
- tu####avigators.com/10250350
- sm####onovkajio.com/10250350
- DNS ASK ve#####noskilotas.com
- DNS ASK op####duchiosa.com
- DNS ASK tu####avigators.com
- DNS ASK sm####onovkajio.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'StatusWindowClass' WindowName: ''
- ClassName: 'Indicator' WindowName: ''