Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TSystem.exe' = '<LS_APPDATA>\Noroeste\TSystem.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GraphicsIntel.exe' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinServices.exe' = ''
- firefox.exe
- <LS_APPDATA>\Noroeste\TSystem.exe
- 'www.c-##ke.com':80
- 'www.dy###ling.com':80
- www.c-##ke.com/contenidos/prod_cult/escuelas/ct/media/
- www.c-##ke.com/contenidos/prod_cult/escuelas/ct/media/ltado-xiu.php
- www.dy###ling.com/2009/ltado-xiu.php
- DNS ASK www.c-##ke.com
- DNS ASK www.dy###ling.com
- '<IP-адрес в локальной сети>':1037
- ClassName: 'Indicator' WindowName: ''