Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'bnet' = '%TEMP%\\System32\bnet.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IOGKKOGKCGOCCOG' = '%APPDATA%\upload.exe'
- %APPDATA%\upload.exe
- %TEMP%\IBSJNWCTTN.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tasks[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\tasks[1].php
- %TEMP%\IBSJNWCTTN.exe
- %APPDATA%\upload.exe
- %APPDATA%\upload.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\tasks[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tasks[1].php
- 'cs#####ipt.no-ip.info':80
- cs#####ipt.no-ip.info/www/bot/tasks.php?ui###################################################
- cs#####ipt.no-ip.info/www/bot/adduser.php?ui###############################################################################################################################################################
- DNS ASK cs#####ipt.no-ip.info
- ClassName: 'Indicator' WindowName: ''