Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WindowsDown] 'Start' = '00000002'
- '<SYSTEM32>\3.exe'
- '<SYSTEM32>\servet.exe'
- '<SYSTEM32>\3.exe' (загружен из сети Интернет)
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\Deledomn.bat
- <SYSTEM32>\3.exe
- C:\AutoRun.inf
- C:\servet.exe
- <SYSTEM32>\servet.exe
- <SYSTEM32>\Deledomn.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\3[1].exe
- C:\servet.exe
- C:\AutoRun.inf
- <SYSTEM32>\servet.exe
- 'www.se##elv.org':80
- 'localhost':1037
- www.se##elv.org/js/3.exe
- DNS ASK www.se##elv.org
- ClassName: '#32770' WindowName: 'IE????????'
- ClassName: '#32770' WindowName: '???????????????????? - IE??????'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '#32770' WindowName: 'IE ????????'