Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '%APPDATA%\csrss.exe'
- '%APPDATA%\csrss.exe'
- '%TEMP%\Updater.exe'
- '%TEMP%\Updater.exe' (загружен из сети Интернет)
- %APPDATA%\csrss.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\Updater[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\index[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Updater[1].exe
- %TEMP%\Updater.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Updater[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\index[1].php
- %TEMP%\~DFCDC0.tmp
- %TEMP%\~DF5E70.tmp
- 'localhost':1039
- 'ra##.net':80
- 'localhost':1036
- ra##.net/log/index.php?is#####################################################################################################
- ra##.net/Updater.exe
- DNS ASK ra##.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''