Техническая информация
- [<HKLM>\Software\Classes\PROTOCOLS\Filter\text/html] 'CLSID' = '{E92D7312-DE97-4B0B-A7DF-F5ED54B09DC7}'
- [<HKLM>\Software\Classes\PROTOCOLS\Filter\text/plain] 'CLSID' = '{E92D7312-DE97-4B0B-A7DF-F5ED54B09DC7}'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'sp' = 'rundll32 %TEMP%\se.dll,DllInstall'
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\syswow64\ifag.dll
- %TEMP%\se.dll
- %WINDIR%\syswow64\ifag.dll
- %WINDIR%\syswow64\ifag.dll в %WINDIR%\syswow64\fomgcbaa.tmp
- '82.##9.166.69':80
- '82.##9.166.67':80
- DNS ASK di###tx.ak47.be
- DNS ASK on###e.refer.cn
- DNS ASK gl####.look-up.tv
- DNS ASK xm#.###dows-data.info
- ClassName: 'HH Parent' WindowName: ''
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\se.dll,DllInstall' (со скрытым окном)
- '%WINDIR%\syswow64\explorer.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\se.dll,DllInstall
- '%WINDIR%\syswow64\explorer.exe'