Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TINTSETP' = '<SYSTEM32>\TINTSETP.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- '%TEMP%\IXP000.TMP\360jl.exe'
- '<SYSTEM32>\ftp.exe' -s:ftp.txt
- '<SYSTEM32>\reg.exe' ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v TINTSETP /t REG_SZ /d "<SYSTEM32>\TINTSETP.exe" /f
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 20
- '<SYSTEM32>\findstr.exe' /i "ftp.exe" goto Ky
- '<SYSTEM32>\net.exe' stop sharedaccess
- '<SYSTEM32>\net1.exe' stop sharedaccess
- '<SYSTEM32>\tasklist.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\hmUPY[1]
- %TEMP%\IXP000.TMP\ftp.txt
- %TEMP%\IXP000.TMP\360jl.exe
- %TEMP%\~1.bat
- %TEMP%\~1.bat
- %TEMP%\IXP000.TMP\ftp.txt
- 'localhost':1042
- 'sw##.###tantfreesite.com':21
- 'localhost':1039
- 'go#.gl':80
- go#.gl/hmUPY
- DNS ASK sw##.###tantfreesite.com
- DNS ASK go#.gl
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'IEFrame' WindowName: '(null)'