Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'hiya' = '%WINDIR%\Security.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'linux-is-gay' = '%WINDIR%\lastdefense.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AV' = '<SYSTEM32>\AV.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mike4hermione' = '<SYSTEM32>\nortonsgay.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Hermione.bat
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\rifk.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\win32.bat
- ClassName: 'MSBLWindowClass' WindowName: '(null)'
- %WINDIR%\lastdefense.exe
- %ALLUSERSPROFILE%\Desktop\hiya.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\amberstorm[1]
- <SYSTEM32>\AV.exe
- <SYSTEM32>\nortonsgay.exe
- %WINDIR%\Security.exe
- 'www.am###storm.com':80
- 'localhost':1036
- www.am###storm.com/
- DNS ASK www.am###storm.com
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'IMWindowClass' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'