Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ctpop' = '%PROGRAM_FILES%\ctpop\ctpop.exe'
- %PROGRAM_FILES%\ctpop\setupex.exe
- %PROGRAM_FILES%\ctpop\ctpop.exe
- <SYSTEM32>\cmd.exe /c \DelUS.bat
- %TEMP%\nsl4.tmp\NSISdl.dll
- C:\DelUS.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ctpep[1].xml
- %TEMP%\dataup.exe
- %TEMP%\nsm2.tmp\SelfDelete.dll
- %PROGRAM_FILES%\ctpop\setupex.exe
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- %PROGRAM_FILES%\ctpop\uninst.exe
- %PROGRAM_FILES%\ctpop\ctpop.exe
- %TEMP%\nsm2.tmp\SelfDelete.dll
- 'yo####04.cafe24.com':80
- 'localhost':1037
- '1.##4.83.91':80
- yo####04.cafe24.com/log/?mo###########################################
- yo####04.cafe24.com/log/ctpep.xml
- 1.##4.83.91/files/dataup.dat
- DNS ASK yo####04.cafe24.com