Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'nes' = 'C:\temp\nes.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'fea' = 'C:\temp\fea.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'reco' = 'C:\temp\reco.vbs'
- '%WINDIR%\syswow64\taskkill.exe' /im wscript.exe /f
- C:\temp\loginicio.log
- C:\temp\fea.vbs
- C:\temp\nes.vbs
- C:\temp\reco.vbs
- C:\temp\fea.bat
- C:\temp\cmc.bat
- C:\temp\logencendido.log
- C:\temp\el-baile-del-troleo-version-club-penguin1.mp4
- C:\temp\fea.vbs
- C:\temp\nes.vbs
- C:\temp\reco.vbs
- C:\temp\fea.bat
- C:\temp\cmc.bat
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK cd#.##scordapp.com
- DNS ASK microsoft.com
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "C:\temp\fea.vbs"
- '%WINDIR%\syswow64\wscript.exe' "C:\temp\nes.vbs"
- '%WINDIR%\syswow64\wscript.exe' "C:\temp\reco.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\temp\fea.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\temp\cmc.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\temp\fea.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\temp\cmc.bat" "