Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\svchost.com'
- <SYSTEM32>\ftp.exe -v -s:<SYSTEM32>\Internet.txt 91.203.4.51
- <SYSTEM32>\wscript.exe "%TEMP%\mes.js"
- %WINDIR%\regedit.exe /s <SYSTEM32>\vsrs.reg
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\LimpidSpy1.bat""
- <SYSTEM32>\xcopy.exe /H /Y *.exe <SYSTEM32>\svchost.com
- <SYSTEM32>\Test.txt
- <SYSTEM32>\Internet.txt
- %TEMP%\mes.js
- %TEMP%\1.tmp\LimpidSpy1.bat
- <SYSTEM32>\svchost.com
- <SYSTEM32>\vsrs.reg
- <SYSTEM32>\Test.txt
- %TEMP%\1.tmp\LimpidSpy1.bat
- <SYSTEM32>\vsrs.reg
- <SYSTEM32>\Internet.txt
- 'localhost':1039
- 'localhost':1037
- '91.#03.4.51':21
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''