Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'SystemService' = '%TEMP%\gbot\svchost.exe'
- '%TEMP%\gbot\svchost.exe'
- '%TEMP%\1.7.0.exe'
- '%TEMP%\gbuilder.exe'
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run /V "SystemService" /D "%TEMP%\gbot\svchost.exe" /F
- %TEMP%\bc
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\getcmd[1].php
- %TEMP%\gbot\svchost.exe
- %TEMP%\gbuilder.exe
- %TEMP%\1.7.0.exe
- %TEMP%\bc
- 'so####y.meximas.com':80
- so####y.meximas.com/botnet(kkd)/getcmd.php?ui###############
- DNS ASK so####y.meximas.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'