Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ez88' = '%APPDATA%\lnhz9.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Sxikihuvuw' = 'rundll32.exe "%WINDIR%\cascl32.dll",Startup'
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\311923824] 'Name' = '"%TEMP%\5.tmp"'
- %APPDATA%\lnhz9.exe
- "%TEMP%\dpfom.exe" (загружен из сети Интернет)
- "%TEMP%\wutei.exe" (загружен из сети Интернет)
- "%TEMP%\vsjmv.exe" (загружен из сети Интернет)
- "%TEMP%\gripwn.exe" (загружен из сети Интернет)
- "%TEMP%\xadxfbn.exe" (загружен из сети Интернет)
- "%TEMP%\gdqt.exe" (загружен из сети Интернет)
- <SYSTEM32>\net1.exe stop "Security Center"
- <SYSTEM32>\sc.exe config SharedAccess start= DISABLED
- <SYSTEM32>\net1.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\rundll32.exe setupapi,InstallHinfSection DefaultInstall 128 %APPDATA%\mdinstall.inf
- <SYSTEM32>\rundll32.exe "%WINDIR%\cascl32.dll",iep
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\rundll32.exe "%WINDIR%\cascl32.dll",Startup
- <SYSTEM32>\net.exe stop "Security Center"
- <SYSTEM32>\net.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\sc.exe config wscsvc start= DISABLED
- <SYSTEM32>\spoolsv.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A10' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{AEBA21FA-782A-4A90-978D-B72164C80120}' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{A8A88C49-5EB2-4990-A1A2-0876022C854F}' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'currentlevel' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\osmhbjeyw[1].php
- %TEMP%\wutei.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\waemxrzu[1].php
- %APPDATA%\lnhz9.exe
- %TEMP%\gdqt.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\hhojrlgrzg[1].php
- %TEMP%\vsjmv.exe
- %TEMP%\dpfom.exe
- %APPDATA%\mdinstall.inf
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\bbweytelg[1].php
- %TEMP%\axmgx.exe
- %APPDATA%\MouseDriver.bat
- %TEMP%\Rlb..bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\ermgbv[1].php
- %TEMP%\rant.exe
- %TEMP%\nsk3.tmp\3IC.exe
- %TEMP%\nsk3.tmp\4IR.exe
- %TEMP%\nsk3.tmp\5tbp.exe
- %TEMP%\nsk3.tmp\2gansta.exe
- %TEMP%\nsj2.tmp
- %TEMP%\nsk3.tmp\Hxkds.exe
- %TEMP%\nsk3.tmp\1EuroP.exe
- %TEMP%\4.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\pfwicxeqx[1].php
- %TEMP%\gripwn.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\evpxfz[1].php
- %TEMP%\xadxfbn.exe
- %WINDIR%\cascl32.dll
- %WINDIR%\Temp\6.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\qqlsqy[1].php
- %APPDATA%\MouseDriver.bat
- %TEMP%\5.tmp
- %TEMP%\nsk3.tmp\Hxkds.exe
- %WINDIR%\Temp\6.tmp
- <DRIVERS>\etc\hosts
- %TEMP%\nsk3.tmp\5tbp.exe
- %TEMP%\nsk3.tmp\2gansta.exe
- %TEMP%\nsk3.tmp\1EuroP.exe
- %TEMP%\nsk3.tmp\4IR.exe
- %TEMP%\nsk3.tmp\3IC.exe
- 'aa###ker.com':80
- 'ri###hoot.in':80
- aa###ker.com/orltke/ermgbv.php?ad################################
- aa###ker.com/orltke/waemxrzu.php?ad################################
- aa###ker.com/orltke/cqksml.php?ad################################
- aa###ker.com/orltke/bbweytelg.php?ad################################
- aa###ker.com/orltke/osmhbjeyw.php?ad################################
- aa###ker.com/orltke/pfwicxeqx.php?ad################################
- aa###ker.com/orltke/qqlsqy.php?ad################################
- aa###ker.com/orltke/hhojrlgrzg.php?ad################################
- aa###ker.com/orltke/evpxfz.php?ad################################
- ri###hoot.in/?in##############################################################################################################
- DNS ASK ri###hoot.in
- DNS ASK aa###ker.com
- DNS ASK go##le.ae
- DNS ASK ik##.com
- DNS ASK si###ell.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'CSCHiddenWindow' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''