Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\svwhcrga.lnk
- <SYSTEM32>\tasks\opera scheduled autoupdate 1044487932
- %APPDATA%\microsoft\windows\svwhcrga\rbetrceg.exe
- %APPDATA%\microsoft\windows\svwhcrga\rbetrceg.exe
- 'ms###csi.com':80
- 'ba##ide.in':80
- 'se##.com':443
- http://www.ms###csi.com/ncsi.txt
- http://ba##ide.in/mlp/
- 'se##.com':443
- DNS ASK ba##ide.in
- DNS ASK se##.com
- '%APPDATA%\microsoft\windows\svwhcrga\rbetrceg.exe'
- '<SYSTEM32>\cmd.exe' /c start "" "%APPDATA%\Microsoft\Windows\svwhcrga\rbetrceg.exe"' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {C1D8A6F1-C607-4978-A114-935E148F204D} S-1-5-21-1238866942-1249195528-555854008-1000:hjtwmprqhsg\user:Interactive:[1]
- '<SYSTEM32>\cmd.exe' /c start "" "%APPDATA%\Microsoft\Windows\svwhcrga\rbetrceg.exe"