Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'KB0948' = '%WINDIR%\svchost.exe'
- %WINDIR%\svchost.exe
- <SYSTEM32>\cmd.exe /c "%TEMP%\regsvr32.bat"
- %TEMP%\regsvr32.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\sendcommand[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\sendcommand[1].asp
- %WINDIR%\debug.txt
- %TEMP%\0874rctemp.tmp
- %WINDIR%\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\google[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\sendcommand[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\sendcommand[1].asp
- '<IP-адрес в локальной сети>':80
- '74.##5.232.51':80
- <IP-адрес в локальной сети>/RCWServer/sendcommand.asp?DA###################################
- 74.##5.232.51/
- DNS ASK www.google.com
- ClassName: 'Indicator' WindowName: ''