Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Gorn' = '%ProgramFiles(x86)%\Gorn\Gorn\crypt.exe'
- [HKLM\System\CurrentControlSet\Services\Dhcp] 'Start' = '00000002'
- crypt.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %ProgramFiles(x86)%\gorn\gorn\neznoesvidanie.vbs
- %ProgramFiles(x86)%\gorn\gorn\prostoigra.bat
- %ProgramFiles(x86)%\gorn\gorn\2.txt
- %ProgramFiles(x86)%\gorn\gorn\1.txt
- %ProgramFiles(x86)%\gorn\gorn\crypt.exe
- %ProgramFiles(x86)%\gorn\gorn\dns_bablo.vbs
- %ProgramFiles(x86)%\gorn\gorn\uninstall.exe
- %ProgramFiles(x86)%\gorn\gorn\uninstall.ini
- %APPDATA%\mongos.yt
- %TEMP%\nskef8d.tmp\mongos.dll
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\nskef8d.tmp\mongos.dll
- '10#.#1.183.181':80
- DNS ASK se######.googlesearchreport.com
- DNS ASK se#######.googlesearchreport.com
- '%WINDIR%\syswow64\wscript.exe' "%ProgramFiles(x86)%\Gorn\Gorn\neznoesvidanie.vbs"
- '%ProgramFiles(x86)%\gorn\gorn\crypt.exe'
- '%WINDIR%\syswow64\wscript.exe' "%ProgramFiles(x86)%\Gorn\Gorn\dns_bablo.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c ""%ProgramFiles(x86)%\Gorn\Gorn\prostoigra.bat" " (со скрытым окном)