Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\Isas.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winnt' = '%WINDIR%\winnt.exe'
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\net1.exe' Stop SharedAccess
- '<SYSTEM32>\net.exe' Stop SharedAccess
- <SYSTEM32>\Isas.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\system[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\system[1].php
- <SYSTEM32>\MS Silverlight.exe
- %TEMP%\aut1.tmp
- %TEMP%\fcbgozp
- %WINDIR%\winnt.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\system[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\system[1].php
- %TEMP%\aut1.tmp
- %TEMP%\fcbgozp
- 'sy####.123laptop.net':80
- sy####.123laptop.net/system.php?ve#####
- DNS ASK sy####.123laptop.net