Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'avgnte' = '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\avgnte.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'avgnte' = '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\avgnte.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\avgnte.exe
- '%TEMP%\icsesfeet.exe' <PATH_SAMPLE>.doc
- %WINDIR%\syswow64\cleanmgr.exe
- %TEMP%\icsesfeet.exe
- %TEMP%\nearenty_56d54e8d98daf.gif
- %APPDATA%\microsoft\windows\start menu\programs\startup\avgnte.exe
- <PATH_SAMPLE>.doc
- http://re#####acjahektor.pl/javascript/libs/jcrop/demos/alarm.php
- http://le####arowicz.pl/images/galleries/4/534574_530340216995974_1334360344_n_5444dc1bcf90a.jpg
- DNS ASK re#####acjahektor.pl
- DNS ASK le####arowicz.pl
- '%APPDATA%\microsoft\windows\start menu\programs\startup\avgnte.exe'
- '%WINDIR%\syswow64\cmd.exe' /c "%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\avgnte.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\mstsc.exe' "%TEMP%\icsesfeet.exe" <PATH_SAMPLE>.doc
- '%WINDIR%\syswow64\cmd.exe' /c "%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\avgnte.exe"
- '%WINDIR%\syswow64\cleanmgr.exe' "%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\avgnte.exe"