Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'netx' = '%WINDIR%\svx.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'netc' = '%WINDIR%\svc.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'odbny' = '%WINDIR%\odbn.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'netw' = '%WINDIR%\svw.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'lsass' = '%WINDIR%\lsass.exe'
- %TEMP%\teste1_p.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\navcancl[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\info_48[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\errorpagetemplate[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\errorpagestrings[1]
- <SYSTEM32>\spool\prtprocs\x64\b06a.tmp
- %TEMP%\q1.exe
- %TEMP%\avto2.exe
- %TEMP%\avto1.exe
- %TEMP%\avto.exe
- %TEMP%\1262241479.exe
- %TEMP%\6_ldry3.exe
- %TEMP%\5_odbn.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\dnserrordiagoff_weboc[1]
- %TEMP%\4_pinnew.exe
- %WINDIR%\svx.exe
- %WINDIR%\svc.exe
- %WINDIR%\odbn.exe
- %WINDIR%\svw.exe
- %WINDIR%\lsass.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\bullet[2]
- <SYSTEM32>\spool\prtprocs\x64\b06a.tmp
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\navcancl[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\info_48[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\bullet[1]
- %TEMP%\1262241479.exe в %TEMP%\bf3a.tmp
- %LOCALAPPDATA%\Microsoft\Windows\<INETFILES>\Content.IE5\0U8LPYU9\ErrorPageTemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\errorpagestrings[1]
- %LOCALAPPDATA%\Microsoft\Windows\<INETFILES>\Content.IE5\CAASBYCL\errorPageStrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\httperrorpagesscripts[1]
- 'au####loaders.net':80
- 'd1#######stzrp.cloudfront.net':80
- 'iy##z.com':80
- 'i1.###-image.com':80
- 'i4.###-image.com':80
- 'i2.###-image.com':80
- 'i3.###-image.com':80
- 'tr###blo.com':80
- http://d1#######stzrp.cloudfront.net/scripts/js3.js
- http://i4.###-image.com/__media__/pics/12471/libg.png
- http://i2.###-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot?
- http://i2.###-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot?
- http://i2.###-image.com/__media__/js/min.js?v2##
- http://i2.###-image.com/__media__/pics/12471/bodybg.png
- http://i2.###-image.com/__media__/pics/12471/search-icon.png
- http://i2.###-image.com/__media__/pics/12471/kwbg.jpg
- http://i2.###-image.com/__media__/pics/12471/libg.png
- http://i2.###-image.com/__media__/pics/12471/arrow.png
- http://i3.###-image.com/__media__/pics/12471/arrow.png
- http://i3.###-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot?
- http://i3.###-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot?
- http://i3.###-image.com/__media__/js/min.js?v2##
- http://i3.###-image.com/__media__/pics/12471/bodybg.png
- http://i3.###-image.com/__media__/pics/12471/search-icon.png
- http://i3.###-image.com/__media__/pics/12471/kwbg.jpg
- http://i3.###-image.com/__media__/pics/12471/libg.png
- http://i3.###-image.com/__media__/pics/12471/logo.png
- http://i4.###-image.com/__media__/pics/12471/logo.png
- http://i2.###-image.com/__media__/pics/12471/logo.png
- http://i4.###-image.com/__media__/pics/12471/arrow.png
- http://i1.###-image.com/__media__/pics/12471/search-icon.png
- http://au####loaders.net/track.php?do############################################################################################################################################################...
- http://au####loaders.net/mass/tds2.php
- http://iy##z.com/?dn################################
- http://iy##z.com/px.js?ch##
- http://i1.###-image.com/__media__/js/min.js?v2##
- http://i1.###-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot?
- http://i1.###-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot?
- http://i1.###-image.com/__media__/pics/12471/bodybg.png
- http://i1.###-image.com/__media__/pics/12471/kwbg.jpg
- http://i4.###-image.com/__media__/pics/12471/search-icon.png
- http://i1.###-image.com/__media__/pics/12471/libg.png
- http://i1.###-image.com/__media__/pics/12471/logo.png
- http://i1.###-image.com/__media__/pics/12471/arrow.png
- http://iy##z.com/Photo_Recovery_Tool.cfm?do######################################################################################################################################################...
- http://i4.###-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot?
- http://i4.###-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot?
- http://i4.###-image.com/__media__/js/min.js?v2##
- http://i4.###-image.com/__media__/pics/12471/bodybg.png
- http://i4.###-image.com/__media__/pics/12471/kwbg.jpg
- http://tr###blo.com/estplanete.php
- DNS ASK d4###8675.cn
- DNS ASK sa###ngins.net
- DNS ASK au####loaders.net
- DNS ASK d1#######stzrp.cloudfront.net
- DNS ASK iy##z.com
- DNS ASK i1.###-image.com
- DNS ASK se###pworld.net
- DNS ASK i4.###-image.com
- DNS ASK i2.###-image.com
- DNS ASK i3.###-image.com
- DNS ASK gr####nstant.net
- DNS ASK tr###blo.com
- DNS ASK be###ebtop.net
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\teste1_p.exe'
- '%TEMP%\q1.exe'
- '%TEMP%\avto2.exe'
- '%TEMP%\avto1.exe'
- '%TEMP%\avto.exe'
- '%TEMP%\1262241479.exe'
- '%TEMP%\6_ldry3.exe'
- '%TEMP%\5_odbn.exe'
- '%TEMP%\4_pinnew.exe'