Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System' = 'C:\systemlogon.exe'
- '<SYSTEM32>\cmd.exe' /c (echo Table ARP & arp -a & echo ====================== & ipconfig /all & echo ====================== & net user) > %WINDIR%\Temp\sysmac.sys
- '<SYSTEM32>\attrib.exe' +h +s C:\systemlogon.exe
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\arp.exe' -a
- '<SYSTEM32>\cmd.exe' /c attrib +h +s C:\systemlogon.exe
- '<SYSTEM32>\cmd.exe' /c "<Текущая директория>\cv.doc"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v System /d C:\systemlogon.exe /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v System /d C:\systemlogon.exe /f
- [<HKCU>\Software\Microsoft\Internet Account Manager]
- [<HKCU>\Software\Microsoft\Internet Account Manager\Accounts]
- %WINDIR%\Temp\temp3.jpg
- %WINDIR%\Temp\image2.jpg
- %WINDIR%\Temp\temp2.jpg
- %WINDIR%\Temp\image4.jpg
- %WINDIR%\Temp\temp4.jpg
- %WINDIR%\Temp\image3.jpg
- %WINDIR%\Temp\win.txt
- %WINDIR%\Temp\wnsck.dll
- C:\systemlogon.exe
- %WINDIR%\Temp\image1.jpg
- %WINDIR%\Temp\temp1.jpg
- %WINDIR%\Temp\sysmac.sys
- C:\systemlogon.exe
- %WINDIR%\Temp\image2.jpg
- %WINDIR%\Temp\image3.jpg
- %WINDIR%\Temp\temp4.jpg
- %WINDIR%\Temp\image1.jpg
- %WINDIR%\Temp\temp1.jpg
- %WINDIR%\Temp\temp2.jpg
- %WINDIR%\Temp\temp3.jpg
- 'sm##.gmail.com':25
- DNS ASK sm##.gmail.com