Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aps] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\aps] 'ImagePath' = '<DRIVERS>\aps.sys'
- <SYSTEM32>\cmd.exe /c <Текущая директория>\229680~1.BAT
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.microsoft.com
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\JwhEHs92H[1]
- <Текущая директория>\2296801295.bat
- %TEMP%\106984
- %APPDATA%\rnf
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\JwhEHs92H[1]
- <Текущая директория>\2296801295.bat
- 'localhost':1041
- '20#.#6.232.182':80
- 'localhost':1043
- 'localhost':1040
- 'localhost':1036
- 'ii####llll.co.in':80
- 'ii###lllll.in':80
- 20#.#6.232.182/
- ii###lllll.in/JwhEHs92H
- ii####llll.co.in/JwhEHs92H
- DNS ASK www.microsoft.com
- DNS ASK c5#######198byx5oi2.from-az.net
- DNS ASK ii###lllll.in
- DNS ASK ii####llll.co.in
- '<IP-адрес в локальной сети>':1037
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''