Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'JavaFlash' = '%TEMP%\iexplorer.exe'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' "http://adobe.shockwavesfx.com/successful.php3"
- %TEMP%\file_id.diz
- %TEMP%\find.exe
- %TEMP%\player.exe
- %WINDIR%\temp\a00898.bat
- %TEMP%\iexplorer.dll
- %WINDIR%\temp\a00898.bat
- %WINDIR%\temp\a00898.bat
- DNS ASK pr###.#hockwavesfx.com
- DNS ASK ad###.#hockwavesfx.com
- DNS ASK ve######2.shockwavesfx.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%TEMP%\player.exe'
- '%TEMP%\find.exe' "TTL"
- '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\Temp\a00898.bat" "%TEMP%\player.exe" " (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' add "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" /v JavaFlash /t REG_SZ /d "%TEMP%\iexplorer.exe"
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\ping.exe proxy.shockwavesfx.com -n 1 -l 1 | find.exe "TTL"
- '%WINDIR%\syswow64\ping.exe' proxy.shockwavesfx.com -n 1 -l 1
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\ping.exe verifica2.shockwavesfx.com -n 1 -l 1 | find.exe "TTL"
- '%WINDIR%\syswow64\ping.exe' verifica2.shockwavesfx.com -n 1 -l 1