Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sysconf32' = '%WINDIR%\sysconf32.vbs'
- %WINDIR%\sysconf32.vbs
- %TEMP%\javadeployreg.log
- 'so#m.cz':80
- 'so#m.cz':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- http://www.so#m.cz/projects/webdoor/enter.php?cl###############
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgSig3kDTLEjcPoIdj6WnO%2FrmQ%3D%3D
- 'so#m.cz':443
- DNS ASK so#m.cz
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%WINDIR%\sysconf32.vbs"
- '<SYSTEM32>\wscript.exe' "%WINDIR%\sysconf32.vbs"' (со скрытым окном)
- '%ProgramFiles%\internet explorer\iexplore.exe' -Embedding