Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '<DRIVERS>\winlogon.exe'
- Диспетчера задач (Taskmgr)
- Редактора реестра (RegEdit)
- Средство контроля пользовательских учетных записей (UAC)
- <DRIVERS>\winlogon.exe
- <DRIVERS>\nod32.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\register[1].php
- %TEMP%\sfx.ini
- <DRIVERS>\winlogon.exe
- %TEMP%\sfx.ini
- 'st####idgeart.com':80
- 'localhost':1043
- 'co####dadjumper.org':80
- '19#.#1.194.27':80
- 'wp#d':80
- 'www.co####dadjumper.org':80
- 'we####dmetal.com':80
- 19#.#1.194.27/appserv/noticias/htdacces
- st####idgeart.com/http.config
- co####dadjumper.org/Online/register.php?ma###################################################################
- wp#d/wpad.dat
- www.co####dadjumper.org/cliente/usuario.php
- we####dmetal.com/http.config
- DNS ASK st####idgeart.com
- DNS ASK co####dadjumper.org
- DNS ASK we####dmetal.com
- DNS ASK wp#d
- DNS ASK www.co####dadjumper.org
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''