Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'CrIris' = '{04acad59-1e3e-4ee3-b8f1-d8771ea7d8ba}'
- %TEMP%\is-DKUQT.tmp\outlook-password-unlocker-3.0.1.4.tmp /SL5="$300DA,655927,53248,%TEMP%\outlook-password-unlocker-3.0.1.4.exe"
- %TEMP%\outlook-password-unlocker-3.0.1.4.exe
- <SYSTEM32>\regsvr32.exe /s "%TEMP%\windll.dll"
- %TEMP%\is-TB1N4.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-TB1N4.tmp\_isetup\_RegDLL.tmp
- %CommonProgramFiles%\CrIris\CrIris.dll
- %TEMP%\windll.dll
- %TEMP%\nst2.tmp\NSISdl.dll
- %TEMP%\outlook-password-unlocker-3.0.1.4.exe
- %TEMP%\outlook-password-unlocker-3.0.1.4.log
- %TEMP%\is-DKUQT.tmp\outlook-password-unlocker-3.0.1.4.tmp
- %TEMP%\nst2.tmp\NSISdl.dll
- %TEMP%\windll.dll
- 'to####tsfiles.net':80
- to####tsfiles.net/zhmchk/zhmchk.php?sf##############################################
- DNS ASK to####tsfiles.net
- '<IP-адрес в локальной сети>':1035
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MozillaUIWindowClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''