Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GoogleRuntimeUpdate' = '%TEMP%\GoogleRuntimeUpdate.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleRuntimeUpdate' = '%TEMP%\GoogleRuntimeUpdate.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%TEMP%\tmp1.tmp.exe";"%WINDIR%\Explorer.exe"'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%TEMP%\tmp2.tmp.exe";"%TEMP%\tmp1.tmp.exe";"%WINDIR%\Explorer.exe"'
- '%TEMP%\tmp2.tmp.exe' /pq
- '%TEMP%\tmp2.tmp.exe' /px
- '%APPDATA%\8106362249725717961213570167.exe'
- '%TEMP%\tmp1.tmp.exe' /pq
- '%TEMP%\tmp1.tmp.exe' /px
- '%TEMP%\GoogleRuntimeUpdate.exe'
- '%APPDATA%\8106362249725717961213570167.exe' (загружен из сети Интернет)
- %TEMP%\tmp2.tmp.exe
- %APPDATA%\8106362249725717961213570167.exe
- %TEMP%\tmp1.tmp.exe
- %TEMP%\GoogleRuntimeUpdate.exe
- %TEMP%\GoogleRuntimeUpdate.exe
- 'dl.##opbox.com':80
- 'fl####rc.sytes.net':6667
- '15#.49.0.0':8080
- 'wp#d':80
- dl.##opbox.com/FileToDownload.exe
- wp#d/wpad.dat
- DNS ASK fl####rc.sytes.net
- DNS ASK dl.##opbox.com
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'