Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Spooler SubSystem App' = '%PROGRAM_FILES%\Windows Media Player\spoolsv.exe'
- '<SYSTEM32>\net1.exe' stop WinDefend
- '<SYSTEM32>\sc.exe' delete WinDefend
- '<SYSTEM32>\net.exe' stop WinDefend
- %PROGRAM_FILES%\Windows Media Player\RCX3.tmp
- %PROGRAM_FILES%\Windows Media Player\RCX4.tmp
- %PROGRAM_FILES%\Windows Media Player\RCX2.tmp
- %PROGRAM_FILES%\Windows Media Player\spoolsv.exe
- %PROGRAM_FILES%\Windows Media Player\RCX1.tmp
- %PROGRAM_FILES%\Windows Media Player\spoolsv.exe
- %PROGRAM_FILES%\Windows Media Player\RCX3.tmp в %PROGRAM_FILES%\Windows Media Player\spoolsv.exe
- %PROGRAM_FILES%\Windows Media Player\RCX4.tmp в %PROGRAM_FILES%\Windows Media Player\spoolsv.exe
- %PROGRAM_FILES%\Windows Media Player\RCX1.tmp в %PROGRAM_FILES%\Windows Media Player\spoolsv.exe
- %PROGRAM_FILES%\Windows Media Player\RCX2.tmp в %PROGRAM_FILES%\Windows Media Player\spoolsv.exe
- 'so###de.com.br':80
- http://so###de.com.br/wp-content/plugins/addthis/count2/count.php?ve#######
- DNS ASK so###de.com.br