Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'SecurityWIN64' = 'Wscript.exe "%APPDATA%\windows.vbs"'
- '<SYSTEM32>\ping.exe' -n 1 www.se####tydnss.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windows.vbs"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\comphp[1].php
- %ALLUSERSPROFILE%\ppctrl.dat
- %ALLUSERSPROFILE%\user.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\a[1].php
- %TEMP%\2018.tmp
- %APPDATA%\windows.vbs
- %ALLUSERSPROFILE%\pckt.tmp
- %ALLUSERSPROFILE%\0
- %ALLUSERSPROFILE%\MZђ
- %TEMP%\3217.tmp
- %ALLUSERSPROFILE%\ppctrl.dat
- %APPDATA%\windows.vbs
- %TEMP%\2018.tmp
- %TEMP%\3217.tmp
- '79.##.179.237':80
- 'localhost':1039
- 'www.se####tydnss.com':80
- 79.##.179.237/wp-content/plugins/dhcp/comphp.php?ti#######################################
- www.se####tydnss.com/bit/a.php?a=#####
- www.se####tydnss.com/bisupdpck.txt
- www.se####tydnss.com/bisdtpck.txt
- DNS ASK www.se####tydnss.com