Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Google Updater 2.0' = '%ALLUSERSPROFILE%\Google Updater 2.0\qa1ii73ki.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Google Updater 2.0' = '"%ALLUSERSPROFILE%\Google Updater 2.0\qa1ii73ki.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe] 'Debugger' = 'rbhkyhudq.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Google Updater 2.0' = '"%ALLUSERSPROFILE%\Google Updater 2.0\qa1ii73ki.exe"'
- [<HKLM>\System\CurrentControlSet\Services\SSDPSRV] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- '' (загружен из сети Интернет)
- '%APPDATA%\vbc.exe'
- %WINDIR%\syswow64\explorer.exe
- <SYSTEM32>\dwm.exe
- %WINDIR%\explorer.exe
- iexplore.exe
- firefox.exe
- winword.exe
- Процесс firefox.exe, модуль dnsapi.dll
- Процесс iexplore.exe, модуль dnsapi.dll
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %WINDIR%\syswow64\cmd.exe
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: 'TIdaWindow', WindowName: ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'
- %APPDATA%\vbc.exe
- %TEMP%\joe\sun\spyware\pagepanemaster.xml
- %TEMP%\joe\sun\spyware\webdevwebserver.exe
- %TEMP%\joe\sun\spyware\oleobject.xml
- %TEMP%\joe\sun\spyware\sbssystemdata.dll
- %TEMP%\privacy\x-sqlite3.xml
- %TEMP%\contact-form\org.gnome.totem.gschema.xml
- %TEMP%\contact-form\pgort80.dll
- %TEMP%\plate\voip\x-cdrdao-toc.xml
- %TEMP%\contact-form\edbgjitui.dll
- %TEMP%\contact-form\xorg.xml
- %APPDATA%\booking\efforts\sav\19.opends60.dll
- %TEMP%\goods_script\the\bboard\etpprojui.dll
- %TEMP%\goods_script\the\bboard\x-lrzip.xml
- %TEMP%\goods_script\the\bboard\ieexecremote.dll
- %TEMP%\joe\sun\spyware\mscorcfg.xml
- %TEMP%\joe\sun\spyware\8.opends60.dll
- %TEMP%\joe\sun\spyware\wbemdc.dll
- %TEMP%\joe\sun\spyware\rcxditui.dll
- %TEMP%\joe\sun\spyware\mc.exe
- %TEMP%\joe\sun\spyware\regsvcs.exe
- %TEMP%\plate\voip\documentation.xml
- %TEMP%\plate\voip\wfeventlog.xml
- %TEMP%\plate\voip\model13.xml
- %TEMP%\contact-form\.xml
- %TEMP%\plate\voip\vnd.comicbook+zip.xml
- %TEMP%\plate\voip\microsoftvsdesignerui.dll
- %TEMP%\plate\voip\edbgtl.dll
- %TEMP%\plate\voip\msenc71ui.dll
- %TEMP%\plate\voip\mips-o32-linux.xml
- %TEMP%\plate\voip\cstldui.dll
- %TEMP%\nsb8bac.tmp
- %TEMP%\amahrealgar
- %TEMP%\encoreslipway.dll
- %WINDIR%\syswow64\cmd.exe в %ALLUSERSPROFILE%\google updater 2.0\qa1ii73ki.exe
- 'si###atics.ga':80
- http://si###atics.ga/~zadmin/div/me.exe
- http://si###atics.ga/~zadmin/lk/wid/logout.php?id########
- DNS ASK si###atics.ga
- ClassName: '' WindowName: 'GMER'
- ClassName: '' WindowName: 'Monitoring - API Monitor v2 32-bit'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\rundll32.exe' EncoreSlipway,Breathing
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\explorer.exe'