Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Alg' = 'C:\alg.exe'
- <SYSTEM32>\dllcache\beep.sys файлом <SYSTEM32>\dllcache\beep.sys.new
- <DRIVERS>\beep.sys файлом <DRIVERS>\beep.sys.new
- C:\alg.exe
- %ALLUSERSPROFILE%\Documents\My Videos\PulgConfig.log
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\st59[1].gif
- %WINDIR%\VC.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\daohao[1].gif
- C:\alg.exe
- <Текущая директория>\hello_tt.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\1[1].php
- %ALLUSERSPROFILE%\Documents\My Videos\PulgFile.log
- %ALLUSERSPROFILE%\Documents\My Videos\PulgConfig.log
- %ALLUSERSPROFILE%\Documents\My Videos\Vanlsp.tmp
- %WINDIR%\VC.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\st59[1].gif
- <Текущая директория>\hello_tt.sys
- <SYSTEM32>\dllcache\beep.sys.new в <SYSTEM32>\dllcache\beep.sys
- C:\alg.exe в %ALLUSERSPROFILE%\Documents\My Videos\Vanlsp.tmp
- 'pc##.9966.org':80
- 'localhost':80
- 'localhost':1036
- localhost/daohao.gif
- pc##.9966.org/st59.gif
- localhost/1.php?us##############################################################################################################
- DNS ASK pc##.9966.org