Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Power' = 'rundll32.exe <SYSTEM32>\alxklt.dll,Start'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Galaxy' = 'rundll32.exe <SYSTEM32>\ppgaxea.dll,Su'
- '%TEMP%\RarSFX0\Gapr11.exe'
- <SYSTEM32>\alxklt.dll
- %TEMP%\sns.txt
- <SYSTEM32>\setuts_hr.log
- %TEMP%\sos.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\sos[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sns[1].txt
- %TEMP%\RarSFX0\alxklt.dll
- %TEMP%\RarSFX0\ppgaxea.dll
- %TEMP%\RarSFX0\Gapr11.exe
- <SYSTEM32>\apputs_ga.log
- <SYSTEM32>\ppgaxea.dll
- %TEMP%\RarSFX0\Gapr11.exe
- %TEMP%\RarSFX0\alxklt.dll
- %TEMP%\RarSFX0\ppgaxea.dll
- 'www.cc##nfo.net':80
- 'localhost':1035
- www.cc##nfo.net/download/sos.txt
- www.cc##nfo.net/download/sns.txt
- DNS ASK www.cc##nfo.net
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'