Техническая информация
- [<HKLM>\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] '' = '%APPDATA%\nvg\iexplore.exe'
- Средство контроля пользовательских учетных записей (UAC)
- firefox.exe
- iexplore.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.com;.scr'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bg_fnd[1].gif
- %APPDATA%\nvg\iexplore.exe
- %APPDATA%\CRNJEUFU.jsp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\start[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\top26[1].gif
- %APPDATA%\CRNJEUFU.jsp
- 'so##.#xbusiness.com':80
- 'pr###.##itesecurity.com.br':80
- so##.#xbusiness.com/img/bg/bg_fnd.gif
- so##.#xbusiness.com/img/bg/top26.gif
- pr###.##itesecurity.com.br/soul/start.php
- DNS ASK so##.#xbusiness.com
- DNS ASK www.google.com
- DNS ASK pr###.##itesecurity.com.br
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'