Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'MicrosoftIndex' = '{14b89d16-4730-4c01-b1c9-36610a25ba88}'
- '<SYSTEM32>\regsvr32.exe' /s %TEMP%\windll.dll
- '<SYSTEM32>\ntvdm.exe' -f -i1
- %TEMP%\yahoo-messenger-9.0.0.2160.log
- %TEMP%\windll.dll
- %CommonProgramFiles%\Microsoft\MicrosoftIndex.dll
- %WINDIR%\Temp\scs4.tmp
- %TEMP%\yahoo-messenger-9.0.0.2160.exe
- %TEMP%\nsn2.tmp\NSISdl.dll
- %WINDIR%\Temp\scs3.tmp
- %TEMP%\windll.dll
- %TEMP%\nsn2.tmp\NSISdl.dll
- %WINDIR%\Temp\scs3.tmp
- %WINDIR%\Temp\scs4.tmp
- '20#.#26.167.92':80
- 20#.#26.167.92/tor2_5/trun.php?tn###########################
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-ae0.ae4.380001'
- ClassName: 'MozillaUIWindowClass' WindowName: '(null)'