Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'CTFM0N' = '%WINDIR%\system\SVCH0ST.exe'
- '%WINDIR%\system\SVCHOST.exe'
- '%TEMP%\dpwskck1.exe'
- '%WINDIR%\regedit.exe' /s 3.reg
- '%WINDIR%\regedit.exe' /s 2.reg
- '%WINDIR%\regedit.exe' /s 1.reg
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
- %WINDIR%\system\SVCHOST.exe
- %TEMP%\dpwskck1.exe
- %WINDIR%\system\MSINET.OCX
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\time[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\in-6diq[1].html
- %HOMEPATH%\Start Menu\Жф¶Ї Internet Explorer дЇААЖч.url
- %HOMEPATH%\Favorites\НшЦ·Ц®јТ.url
- %TEMP%\1.reg
- %TEMP%\3.reg
- %TEMP%\2.reg
- 'www.55##.com':80
- 'localhost':1036
- www.55##.com/1/time.html
- www.55##.com/1/in-6diq.html
- DNS ASK www.55##.com
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'