Техническая информация
- [<HKCU>\software\microsoft\windows\currentversion\run\] 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...
- [<HKCU>\software\microsoft\windows\currentversion\run\] 'svchost' = 'regsvr32 /s "C:\Temp:0014A978.dat"'
- [<HKLM>\software\microsoft\windows\currentversion\run\] 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...
- [<HKLM>\software\microsoft\windows\currentversion\run\] 'svchost' = 'regsvr32 /s "C:\Temp:0014A978.dat"'
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\syswow64\explorer.exe
- C:\temp:rnd.dat
- 'google.com':80
- '85.##.19.211':80
- http://www.google.com/search?q=######
- DNS ASK google.com
- '%WINDIR%\syswow64\explorer.exe'