Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Intel Pro Motherboard' = '%LOCALAPPDATA%\Intel Pro\inetl_pro_wireless.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Intel Pro Motherboard' = '%LOCALAPPDATA%\Intel Pro\inetl_pro_wireless.exe'
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- %LOCALAPPDATA%\intel pro\inetl_pro_wireless.exe
- unc\aduiyrzwer\users\winadmin-setup.exe
- '19#.#07.16.103':80
- http://www.wh###smyip.com/automation/n09230945.asp
- http://ip###odb.com/ip_query.php
- DNS ASK wh###smyip.com
- DNS ASK ip###odb.com
- '%LOCALAPPDATA%\intel pro\inetl_pro_wireless.exe'
- '%WINDIR%\syswow64\netsh.exe' Advfirewall set Currentprofile State off