Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- [<HKLM>\SYSTEM\ControlSet003\Services\aqjrcy] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\yqjrcyyi] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\aqjrcy] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\aqjrcy] 'Start' = '00000002'
- '%TEMP%\IXP000.TMP\1.exe'
- '<SYSTEM32>\svchost.exe' -k aqjrcy
- NtQueryDirectoryFile, драйвер-обработчик: cskqih.sys
- NtDeviceIoControlFile, драйвер-обработчик: cskqih.sys
- <SYSTEM32>\cskqih.dll
- <DRIVERS>\cskqih.sys
- %TEMP%\IXP000.TMP\1.exe
- <SYSTEM32>\0006c93e.ini
- %TEMP%\IXP000.TMP\1.exe
- '21#.#5.140.179':80
- 21#.#5.140.179/20130627/183401/318265.jsp
- 21#.#5.140.179/20130627/183346/303140.jsp
- 21#.#5.140.179/20130627/183330/286828.jsp
- 21#.#5.140.179/20130627/183415/332500.jsp
- 21#.#5.140.179/20130627/183502/379125.jsp
- 21#.#5.140.179/20130627/183447/363812.jsp
- 21#.#5.140.179/20130627/183431/348187.jsp
- 21#.#5.140.179/20130627/183213/210609.jsp
- 21#.#5.140.179/20130627/183158/195140.jsp
- 21#.#5.140.179/20130627/183142/179578.jsp
- 21#.#5.140.179/20130627/183229/225843.jsp
- 21#.#5.140.179/20130627/183315/271812.jsp
- 21#.#5.140.179/20130627/183259/256734.jsp
- 21#.#5.140.179/20130627/183244/241078.jsp