Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Inoyikotadoqev' = 'rundll32.exe "%WINDIR%\clh3rxtc.dll",Startup'
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\1131458048] 'Name' = '%TEMP%\5.tmp'
- '%TEMP%\lxfy.exe'
- '%TEMP%\-1998166001'
- '%TEMP%\hhckoyg.exe'
- '%TEMP%\mhshghx.exe'
- '%TEMP%\hgvngcs.exe'
- '%TEMP%\rsftl.exe'
- '%TEMP%\wdux.exe'
- '%TEMP%\xdsf.exe'
- '%TEMP%\jmohv.exe'
- '%TEMP%\gysg.exe'
- '%TEMP%\nsx3.tmp\3E4U - Old.exe'
- '%TEMP%\nsx3.tmp\ic8.exe'
- '%TEMP%\nsx3.tmp\1EuroP.exe'
- '%TEMP%\nsx3.tmp\2IC.exe'
- '%TEMP%\nsx3.tmp\6tbp.exe'
- '%TEMP%\nrlv.exe'
- '%TEMP%\vdcm.exe'
- '%TEMP%\lxfy.exe' (загружен из сети Интернет)
- '%TEMP%\mhshghx.exe' (загружен из сети Интернет)
- '%TEMP%\wdux.exe' (загружен из сети Интернет)
- '%TEMP%\jmohv.exe' (загружен из сети Интернет)
- '%TEMP%\gysg.exe' (загружен из сети Интернет)
- '%TEMP%\hhckoyg.exe' (загружен из сети Интернет)
- '%TEMP%\vdcm.exe' (загружен из сети Интернет)
- '%TEMP%\nrlv.exe' (загружен из сети Интернет)
- '%TEMP%\xdsf.exe' (загружен из сети Интернет)
- '%TEMP%\rsftl.exe' (загружен из сети Интернет)
- '%TEMP%\-1998166001' (загружен из сети Интернет)
- '%TEMP%\hgvngcs.exe' (загружен из сети Интернет)
- '<SYSTEM32>\rundll32.exe' "%WINDIR%\clh3rxtc.dll",iep
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\rundll32.exe' "%WINDIR%\clh3rxtc.dll",Startup
- <SYSTEM32>\svchost.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\spoolsv.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'currentlevel' = '00000000'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\lyyyzdduh[1].php
- %TEMP%\wdux.exe
- %TEMP%\jmohv.exe
- %TEMP%\lxfy.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\sbsfwao[1].php
- %TEMP%\xdsf.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\wjwwnae[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\nnrfjmqeh[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\vvvmmddhvl[1].php
- %TEMP%\rsftl.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\0K836SL8\desktop.ini
- %WINDIR%\aqarofiboqaxu.dll
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WN4HCZWX\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WTUZKPQR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\LDEXP34W\desktop.ini
- %TEMP%\mhshghx.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\hhlycptx[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\kxyyp[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\CAM7MVA9.php
- %TEMP%\Aqz..bat
- %TEMP%\hgvngcs.exe
- %TEMP%\4.tmp
- %TEMP%\nsx3.tmp\6tbp.exe
- %WINDIR%\Temp\6.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\lmzdd[1].php
- %WINDIR%\clh3rxtc.dll
- %TEMP%\nsx3.tmp\ic8.exe
- %TEMP%\nsn2.tmp
- %TEMP%\nsx3.tmp\1EuroP.exe
- %TEMP%\nsx3.tmp\3E4U - Old.exe
- %TEMP%\nsx3.tmp\2IC.exe
- %TEMP%\hhckoyg.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\uhhymdqu[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\vvvjzar[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bosgwxbeff[1].php
- %TEMP%\-1998166001
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ivjwneei[1].php
- %TEMP%\nrlv.exe
- %TEMP%\vdcm.exe
- %TEMP%\gysg.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\scctgxkbb[1].php
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\LDEXP34W\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WTUZKPQR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\0K836SL8\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WN4HCZWX\desktop.ini
- <DRIVERS>\etc\hosts
- %TEMP%\5.tmp
- <SYSTEM32>\svchost.exe
- %WINDIR%\Temp\6.tmp
- %TEMP%\nsx3.tmp\ic8.exe
- %TEMP%\nsx3.tmp\2IC.exe
- %TEMP%\nsx3.tmp\1EuroP.exe
- %TEMP%\nsx3.tmp\6tbp.exe
- %TEMP%\nsx3.tmp\3E4U - Old.exe
- %TEMP%\4.tmp в %TEMP%\5.tmp
- '23######0628.linkbuzz.net':80
- 'li####aphy-type.com':443
- 'ab###ute.com':80
- 'localhost':1040
- ab###ute.com/bdqqu/lyyyzdduh.php?ad####################################
- ab###ute.com/bdqqu/vvvmmddhvl.php?ad####################################
- ab###ute.com/bdqqu/nnrfjmqeh.php?ad####################################
- ab###ute.com/bdqqu/kxyyp.php?ad##################################################################
- ab###ute.com/bdqqu/hhlycptx.php?ad####################################
- ab###ute.com/bdqqu/sbsfwao.php?ad####################################
- ab###ute.com/bdqqu/wjwwnae.php?ad####################################
- ab###ute.com/bdqqu/scctgxkbb.php?ad####################################
- ab###ute.com/bdqqu/ivjwneei.php?ad####################################
- ab###ute.com/bdqqu/lmzdd.php?ad####################################
- ab###ute.com/bdqqu/bosgwxbeff.php?ad####################################
- ab###ute.com/bdqqu/vvvjzar.php?ad####################################
- ab###ute.com/bdqqu/uhhymdqu.php?ad####################################
- DNS ASK 23######0628.linkbuzz.net
- DNS ASK ga###rcle.com
- DNS ASK li####aphy-type.com
- DNS ASK gr####uzzchat.in
- DNS ASK ig.#om.br
- DNS ASK nb#.com
- DNS ASK wi#####iafoundation.org
- DNS ASK ab###ute.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'SystemTray_Main' WindowName: '(null)'
- ClassName: 'CSCHiddenWindow' WindowName: '(null)'