Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Adobe_Update.exe' = '%APPDATA%\Adobe_Update.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\Adobe_Update.exe.lnk
- '%APPDATA%\Taskmgr.exe' -o http://Qn#########34@eu1.triplemining.com:8344 -g no -t 2 -T 55
- '%APPDATA%\Taskmgr.exe' -o http://Qn#########34@eu1.triplemining.com:8344 -g yes -I -10 -t 2 -T 55
- '%APPDATA%\Adobe_Update.exe'
- ClassName: 'OLLYDBG' WindowName: '(null)'
- %TEMP%\evb4.tmp
- %TEMP%\evb3.tmp
- %TEMP%\evb6.tmp
- %TEMP%\evb5.tmp
- %APPDATA%\Adobe_Update.exe
- %APPDATA%\Taskmgr.exe
- %TEMP%\evb2.tmp
- %TEMP%\evb1.tmp
- 'eu#.###plemining.com':8344
- DNS ASK eu#.###plemining.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'