Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'User Protection' = '"%PROGRAM_FILES%\User Protection\usrprot.exe" -noscan'
- Центр обеспечения безопасности (Security Center)
- <SYSTEM32>\net1.exe stop winmgmt /y
- <SYSTEM32>\net1.exe start winmgmt
- <SYSTEM32>\net1.exe start wscsvc
- <SYSTEM32>\net1.exe stop wscsvc
- <SYSTEM32>\net.exe stop wscsvc
- <SYSTEM32>\net.exe stop winmgmt /y
- <SYSTEM32>\wbem\mofcomp.exe %TEMP%\4otjesjty.mof
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnOnZoneCrossing' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- %TEMP%\tmp1.tmp
- %TEMP%\4otjesjty.mof
- %TEMP%\tmp1.tmp
- 'fi###rnos.org':80
- 'se####tyletters.com':80
- 'se####tytaxes.com':80
- 'el##ind.org':80
- fi###rnos.org/usr/usrr.dat
- fi###rnos.org/usr/usr.dat
- fi###rnos.org/usr/usr_db
- se####tyletters.com/usr/usrr.dat
- se####tyletters.com/usr/usr.dat
- se####tyletters.com/usr/usr_db
- se####tytaxes.com/usr/usrr.dat
- se####tytaxes.com/usr/usr.dat
- se####tytaxes.com/usr/usr_db
- el##ind.org/usr/usrr.dat
- el##ind.org/usr/usr.dat
- el##ind.org/usr/usr_db
- DNS ASK fi###rnos.org
- DNS ASK se####tyletters.com
- DNS ASK se####tytaxes.com
- DNS ASK el##ind.org
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''