Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '%HOMEPATH%\6e0111de\csrss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Critical' = '%HOMEPATH%\8bed001e0bcd1\rundll32.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows' = '%HOMEPATH%\smss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System' = '%HOMEPATH%\001e0bcd1\lsass.exe'
- %HOMEPATH%\6e0111de\csrss.exe
- %HOMEPATH%\8bed001e0bcd1\rundll32.exe
- %HOMEPATH%\001e0bcd1\lsass.exe
- %HOMEPATH%\smss.exe
- 'www.so####tos.com.es':80
- 'ma######lito.wordpress.com':80
- www.so####tos.com.es/cuenta.php
- ma######lito.wordpress.com/
- DNS ASK www.so####tos.com.es
- DNS ASK ma######lito.wordpress.com
- ClassName: 'Indicator' WindowName: ''