Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost.exe' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- '%TEMP%\FB_7.tmp.exe'
- '%TEMP%\FB_6.tmp.exe'
- '%TEMP%\FB_9.tmp.exe'
- '%TEMP%\FB_8.tmp.exe'
- '%TEMP%\FB_5.tmp.exe'
- '%TEMP%\FB_2.tmp.exe'
- '%TEMP%\FB_1.tmp.exe'
- '%TEMP%\FB_4.tmp.exe'
- '%TEMP%\FB_3.tmp.exe'
- '<SYSTEM32>\cmd.exe' /c del %TEMP%\FB_3TM~1.EXE >> NUL
- '<SYSTEM32>\net1.exe' stop MpsSvc
- '%APPDATA%\svchost.exe'
- '%APPDATA%\Ubovn\dyir.exe'
- '%APPDATA%\Windows Update.exe'
- '<SYSTEM32>\cmd.exe' /c echo on error resume next:CreateObject("WScript.Shell").Run "%TEMP%\IXP000.TMP\@.cmd",1: >"%HOMEPATH%\Start Menu\Programs\Startup\x.vbs"
- '%TEMP%\IXP000.TMP\@.cmd'
- '<SYSTEM32>\cmd.exe' net stop MpsSvc
- '<SYSTEM32>\net.exe' stop MpsSvc
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- <SYSTEM32>\cmd.exe
- [<HKCU>\Software\VanDyke\SecureFX]
- [<HKCU>\Software\FTP Explorer\Profiles]
- [<HKCU>\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224]
- [<HKLM>\Software\NCH Software\ClassicFTP\FTPAccounts]
- [<HKCU>\Software\ExpanDrive\Sessions]
- [<HKCU>\Software\Cryer\WebSitePublisher]
- [<HKCU>\Software\FTPWare\COREFTP\Sites]
- [<HKLM>\Software\TurboFTP]
- [<HKCU>\Software\TurboFTP]
- [<HKCU>\Software\BPFTP]
- [<HKCU>\Software\CoffeeCup Software\Internet\Profiles]
- [<HKCU>\Software\Sota\FFFTP\Options]
- [<HKCU>\Software\Sota\FFFTP]
- [<HKCU>\Software\South River Technologies\WebDrive\Connections]
- [<HKLM>\Software\Martin Prikryl]
- [<HKCU>\Software\Martin Prikryl]
- [<HKCU>\Software\FlashPeak\BlazeFtp\Settings]
- [<HKCU>\Software\Microsoft\Internet Explorer\IntelliForms\Storage2]
- [<HKLM>\Software\South River Technologies\WebDrive\Connections]
- [<HKLM>\Software\SoftX.org\FTPClient\Sites]
- [<HKLM>\SOFTWARE\NCH Software\Fling\Accounts]
- [<HKCU>\SOFTWARE\NCH Software\Fling\Accounts]
- [<HKCU>\Software\NCH Software\ClassicFTP\FTPAccounts]
- [<HKCU>\Software\SoftX.org\FTPClient\Sites]
- [<HKLM>\Software\FTPClient\Sites]
- [<HKCU>\Software\FTPClient\Sites]
- [<HKCU>\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar]
- [<HKCU>\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar]
- [<HKLM>\Software\Ghisler\Total Commander]
- [<HKCU>\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar]
- [<HKCU>\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar]
- [<HKCU>\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar]
- [<HKCU>\Software\Ghisler\Total Commander]
- [<HKCU>\Software\Far2\SavedDialogHistory\FTPHost]
- [<HKCU>\Software\Far\SavedDialogHistory\FTPHost]
- [<HKCU>\Software\Far Manager\Plugins\FTP\Hosts]
- [<HKLM>\Software\Ghisler\Windows Commander]
- [<HKCU>\Software\Ghisler\Windows Commander]
- [<HKCU>\Software\Far Manager\SavedDialogHistory\FTPHost]
- [<HKCU>\Software\BPFTP\Bullet Proof FTP\Main]
- [<HKLM>\Software\FileZilla Client]
- [<HKLM>\Software\FileZilla]
- [<HKCU>\Software\BulletProof Software\BulletProof FTP Client\Options]
- [<HKCU>\Software\BPFTP\Bullet Proof FTP\Options]
- [<HKCU>\Software\BulletProof Software\BulletProof FTP Client\Main]
- [<HKCU>\Software\FileZilla Client]
- [<HKCU>\Software\FlashFXP]
- [<HKCU>\Software\FlashFXP\3]
- [<HKCU>\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar]
- [<HKCU>\Software\FileZilla]
- [<HKLM>\Software\FlashFXP]
- [<HKLM>\Software\FlashFXP\3]
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1A10' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1A03' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1A02' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A10' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1A06' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonBadCertRecving' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A05' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1A05' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1406' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1406' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1406' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1609' = '00000000'
- %TEMP%\FB_7.tmp.exe
- %TEMP%\FB_8.tmp.exe
- %TEMP%\FB_5.tmp.exe
- %TEMP%\FB_6.tmp.exe
- %TEMP%\SysInfo.txt
- %APPDATA%\Ubovn\dyir.exe
- %APPDATA%\23EF5514-3059-436F-A4A7-4CEFAAB20EB1\run.dat
- %APPDATA%\Windows Update.exe
- %TEMP%\FB_9.tmp.exe
- <LS_APPDATA>\CSIDL_
- <LS_APPDATA>\CSIDL_X
- %TEMP%\IXP000.TMP\@.cmd
- %TEMP%\IXP000.TMP\@.cm_
- %TEMP%\FB_1.tmp.exe
- %TEMP%\FB_4.tmp.exe
- %APPDATA%\svchost.exe
- %TEMP%\FB_2.tmp.exe
- %TEMP%\FB_3.tmp.exe
- %TEMP%\IXP000.TMP\@.cmd
- <LS_APPDATA>\CSIDL_X
- <LS_APPDATA>\CSIDL_
- %TEMP%\IXP000.TMP\@.cmd
- %TEMP%\IXP000.TMP\@.cm_
- %TEMP%\FB_3.tmp.exe
- 'ch####p.dyndns.org':80
- 'www.kr###online.com':80
- '18#.#14.55.23':1030
- 'bl####ills.ddns.net':1030
- 'wp#d':80
- http://ch####p.dyndns.org/
- http://11#.#11.111.2/wpad.dat via wp#d
- http://www.kr###online.com/wp-admin/css/Panel/gate.php
- DNS ASK www.kr###online.com
- DNS ASK up.###-point.com
- DNS ASK ch####p.dyndns.org
- DNS ASK bl####ills.ddns.net
- DNS ASK wp#d
- ClassName: 'Progman' WindowName: ''