Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\Userinit.exe,%APPDATA%\lsass.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Windows Media Player update.exe
- %HOMEPATH%\Start Menu\Programs\Startup\Windows Media Player update.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Media Player update] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\lsass.exe' = '%TEMP%\lsass.exe:*:Enabled:Windows Media Player update'
- '%TEMP%\lsass.exe' /Autoit3ExecuteScript %TEMP%\procwatch.tmp
- '%TEMP%\lsass.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\lsass.exe" "Windows Media Player update" ENABLE
- %APPDATA%\lsass.exe
- %TEMP%\procwatch.tmp
- %TEMP%\lsass.exe
- %APPDATA%\lsass.exe
- 'ai###erry.com':80
- ai###erry.com/mboard-R/msg/msg/reg.php?Vm###########################################################################################################################################################################
- DNS ASK ai###erry.com
- ClassName: 'Shell_TrayWnd' WindowName: ''