Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xo' = '%PROGRAM_FILES%\j.exe'
- '%PROGRAM_FILES%\j.exe'
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations /v ModRiskFileTypes /t REG_SZ /d .exe;.bat;.reg;.vbs /f
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\softindex[1].html
- %PROGRAM_FILES%\sysinfo.ini
- %PROGRAM_FILES%\j.exe
- '61.##0.212.10':8000
- 'www.ip##ck.com':80
- 'localhost':1036
- www.ip##ck.com/softrun/sysinfoIe83.txt
- www.ip##ck.com/softrun/softindex.html
- DNS ASK www.ip##ck.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'