Техническая информация
- %TEMP%\їЁНЫТБНёКУ.exe
- %TEMP%\їЁНЫТБНёКУ9.706.exe
- C:\їЁНЫТБНёКУ.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.ti##sin.cc
- <SYSTEM32>\wscript.exe "C:\kwy.vbs"
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '0'
- %TEMP%\їЁНЫТБНёКУ.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Version[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\tiansin[1]
- C:\їЁНЫТБНёКУ.exe
- C:\kwy.vbs
- %TEMP%\їЁНЫТБНёКУ9.706.exe
- <DRIVERS>\etc\hosts
- 'localhost':1039
- 'www.ti##sin.cc':80
- 'localhost':1036
- 'do##.#iansin.com':80
- www.ti##sin.cc/
- do##.#iansin.com/Version.txt
- DNS ASK www.ti##sin.cc
- DNS ASK do##.#iansin.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''