Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'mysys' = '%ProgramFiles%\Outlook_Express\SOUNDMAN.EXE'
- %WINDIR%\system.ini
- %WINDIR%\dl_205446.exe
- %WINDIR%\10054.exe
- %ProgramFiles%\outlook_express\soundman.exe
- %ProgramFiles%\outlook_express\httpapi.dll
- %TEMP%\nsf787a.tmp\system.dll
- %WINDIR%\syswow64\com\1.2.8\wndhook.dll
- %WINDIR%\syswow64\com\config.cfg
- %WINDIR%\syswow64\somarshal.dat
- C:\ss2.txt
- %WINDIR%\syswow64\lokdkv.bat
- %WINDIR%\syswow64\klmkzkvxu.bat
- nul
- %TEMP%\nsf787a.tmp\system.dll
- %WINDIR%\dl_205446.exe
- %WINDIR%\syswow64\digzohvtct.bat
- %WINDIR%\syswow64\lokdkv.bat в %WINDIR%\syswow64\digzohvtct.bat
- 'cl.###system.com':80
- http://cl.###system.com/cl.php?fi####################################################################
- DNS ASK ba###com.net.cn
- DNS ASK cl.###system.com
- DNS ASK r.###ntech.com
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\10054.exe'
- '%WINDIR%\dl_205446.exe'
- '%ProgramFiles%\outlook_express\soundman.exe'
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\klmkzkvxu.bat (со скрытым окном)
- '%WINDIR%\syswow64\ping.exe' -n 3 127.0.0.1