Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Net LoGIN Sharing] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Net LoGIN Sharing] 'ImagePath' = 'C:\Documents and Settings\Default User\Application Data\ok.exe'
- 'Net LoGIN Sharing' C:\Documents and Settings\Default User\Application Data\ok.exe
- C:\documents and settings\default user\application data\ok.exe
- %WINDIR%\delete.bat
- C:\documents and settings\default user\application data\ok.exe
- 'kt###0.3322.org':2343
- DNS ASK kt###0.3322.org
- 'C:\documents and settings\default user\application data\ok.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\Delete.bat' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\Delete.bat