Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\realteksb.lnk
- <SYSTEM32>\tasks\realtek sound blaster
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\nsw3997.tmp
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\7x7l8420\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\y6t26h1p\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\ctmgxzkx\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\93tvrlmx\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\desktop.ini
- %APPDATA%\realtek sound blaster\realteksb.exe
- %APPDATA%\software\software.exe
- %APPDATA%\software\boat_25.exe
- %APPDATA%\software\pencil_98.exe
- %APPDATA%\fungal\skate_28.exe
- %TEMP%\nsb39b7.tmp\system.dll
- %APPDATA%\microsoft\windows\cookies\low\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\index.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\93tvrlmx\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\ctmgxzkx\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\y6t26h1p\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\7x7l8420\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\desktop.ini
- %TEMP%\nsb39b7.tmp\system.dll
- %APPDATA%\software\pencil_98.exe
- 'te##te.in':443
- DNS ASK te##te.in
- ClassName: '18467-41' WindowName: ''
- '%APPDATA%\fungal\skate_28.exe'
- '%APPDATA%\software\pencil_98.exe'
- '%APPDATA%\software\boat_25.exe'
- '%APPDATA%\realtek sound blaster\realteksb.exe'
- '%WINDIR%\syswow64\cmd.exe' /k ping -n 5 localhost < nul & del /F /Q "%APPDATA%\Software\Pencil_98.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\syswow64\WININET.dll",DispatchAPICall 1
- '%WINDIR%\syswow64\cmd.exe' /k ping -n 5 localhost < nul & del /F /Q "%APPDATA%\Software\Pencil_98.exe"
- '%WINDIR%\syswow64\ping.exe' -n 5 localhost