Техническая информация
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] 'Debugger' = 'SoundMan.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\helpsvc] 'Start' = '00000002'
- <SYSTEM32>\crwww.exe
- <SYSTEM32>\SoundMan.exe
- <SYSTEM32>\crwww.exe (загружен из сети Интернет)
- <SYSTEM32>\grpconv.exe -o
- <SYSTEM32>\net1.exe user new1 12369
- <SYSTEM32>\net1.exe user new1 /active:yes
- <SYSTEM32>\net1.exe localgroup %USERNAME%s new1 /add
- <SYSTEM32>\ping.exe 127.1 -n 5
- <SYSTEM32>\runonce.exe -r
- <SYSTEM32>\net.exe stop wscsvc
- <SYSTEM32>\cacls.exe %systemroot%\system32\cmd.exe /e /t /g everyone:F
- <SYSTEM32>\net1.exe stop wscsvc
- <SYSTEM32>\rundll32.exe setupapi,InstallHinfSection DefaultInstall 128 %WINDIR%\1.inf
- <SYSTEM32>\net1.exe user new1 12369 /add
- 360tray.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\crt[1].jpg
- %WINDIR%\1.inf
- <Текущая директория>\1.bat
- <SYSTEM32>\crwww.exe
- <SYSTEM32>\ineters.exe
- <SYSTEM32>\SoundMan.exe
- <SYSTEM32>\tthh11.ini
- <SYSTEM32>\notepde.exe
- <SYSTEM32>\notepde.exe
- <SYSTEM32>\ineters.exe
- <SYSTEM32>\SoundMan.exe
- %WINDIR%\1.inf
- '21#.#3.161.159':80
- 'localhost':1035
- 21#.#3.161.159/tthh11/crt.jpg