Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'outlookmail.exe' = 'C:\ProgramData\Adobe\Bin\outlookmail.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ExpIorer.exe' = 'C:\ProgramData\Adobe\Bin\ExpIorer.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'winnit.exe' = 'C:\ProgramData\Adobe\Bin\winnit.exe'
- '<SYSTEM32>\notepad.exe'
- <SYSTEM32>\notepad.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\ext[1].mp3
- C:\ProgramData\Adobe\Bin\ExpIorer.exe
- C:\ProgramData\Adobe\Bin\outlookmail.exe
- C:\ProgramData\Adobe\Bin\win.jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\1kjulai[1]
- %TEMP%\file
- %TEMP%\aut1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\altie[1].mp3
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rmt[1].mp3
- C:\ProgramData\Adobe\Bin\winnit.exe
- C:\ProgramData\Adobe\Bin\outlookmail.exe
- C:\ProgramData\Adobe\Bin\ExpIorer.exe
- C:\ProgramData\Adobe\Bin\winnit.exe
- %TEMP%\aut1.tmp
- 'bi#.ly':80
- '37.##7.35.223':80
- 37.##7.35.223/downloadjune/ext.mp3
- bi#.ly/1kjulai
- 37.##7.35.223/downloadjune/altie.mp3
- 37.##7.35.223/downloadjune/rmt.mp3
- DNS ASK bi#.ly
- ClassName: 'Indicator' WindowName: '(null)'