Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\prvdisk] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\igfxcSvrup] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\PolicyAgent] 'Start' = '00000002'
- '%PROGRAM_FILES%\eccbdwdlz\mrjhvbr.exe' -p Pass1 -r Pass1 -f 125.39.100.74+0 -n PASS -x
- '%TEMP%\nsd2.tmp\ns10.tmp' mrjhvbr.exe -p Pass2 -r Pass2 -f 220.181.126.15+0 -n PASS -x
- '%TEMP%\nsd2.tmp\nsF.tmp' mrjhvbr.exe -p Pass1 -r Pass1 -f 125.39.100.74+0 -n PASS -x
- '%CommonProgramFiles%\Intel\igfxsvrc.exe'
- '%TEMP%\nscA.tmp\nsE.tmp' sc create prvdisk binpath= <SYSTEM32>\PrvMon\prvdisk.sys type= kernel start= system group= Base tag= yes
- '%PROGRAM_FILES%\eccbdwdlz\un0426234006816.exe'
- '%TEMP%\~nsu.tmp\Au_.exe' _?=%PROGRAM_FILES%\eccbdwdlz\
- '%PROGRAM_FILES%\eccbdwdlz\mrjhvbr.exe' -p Pass3 -r Pass3 -f 220.181.126.7+0 -n PASS -x
- '%PROGRAM_FILES%\eccbdwdlz\mrjhvbr.exe' -p Pass2 -r Pass2 -f 220.181.126.15+0 -n PASS -x
- '%TEMP%\nsd2.tmp\ns11.tmp' mrjhvbr.exe -p Pass3 -r Pass3 -f 220.181.126.7+0 -n PASS -x
- '%TEMP%\nscA.tmp\nsD.tmp' sc start igfxcSvrup
- '%TEMP%\nsd2.tmp\ns5.tmp' regedit /s info.reg
- '%TEMP%\nsd2.tmp\ns6.tmp' sc stop PolicyAgent
- '%PROGRAM_FILES%\eccbdwdlz\mrjhvbr.exe' -file wrz2pn.txt
- '%TEMP%\nsd2.tmp\ns3.tmp' sc start PolicyAgent
- '%TEMP%\nsd2.tmp\ns4.tmp' "mrjhvbr.exe" -file wrz2pn.txt
- '%TEMP%\nscA.tmp\nsB.tmp' sc create igfxcSvrup binpath= "%CommonProgramFiles%\Intel\igfxsvrc.exe" type= share start= auto displayname= "Wignx Web Cache Services"
- '%TEMP%\nscA.tmp\nsC.tmp' sc description igfxcSvrup "К№УГWeb CahceјјКхМṩЅшРР»ҐБЄНшдЇААФ¤¶БјУЛЩ·юОсЎЈИз№ыНЈЦ№ёГ·юОсЈ¬ФтјЖЛг»ъЅ«І»ѕЯ±ёХвР©јјКхМṩµДјУЛЩ№¦ДЬЎЈ"
- '%PROGRAM_FILES%\eccbdwdlz\mysetup.exe'
- '%TEMP%\nsd2.tmp\ns7.tmp' sc start PolicyAgent
- '%TEMP%\nsd2.tmp\ns8.tmp' sc config PolicyAgent start= auto
- '<SYSTEM32>\sc.exe' start igfxcSvrup
- '<SYSTEM32>\sc.exe' description igfxcSvrup "К№УГWeb CahceјјКхМṩЅшРР»ҐБЄНшдЇААФ¤¶БјУЛЩ·юОсЎЈИз№ыНЈЦ№ёГ·юОсЈ¬ФтјЖЛг»ъЅ«І»ѕЯ±ёХвР©јјКхМṩµДјУЛЩ№¦ДЬЎЈ"
- '<SYSTEM32>\wscript.exe' "%CommonProgramFiles%\Intel\note.vbs"
- '<SYSTEM32>\sc.exe' create prvdisk binpath= <SYSTEM32>\PrvMon\prvdisk.sys type= kernel start= system group= Base tag= yes
- '<SYSTEM32>\sc.exe' create igfxcSvrup binpath= "%CommonProgramFiles%\Intel\igfxsvrc.exe" type= share start= auto displayname= "Wignx Web Cache Services"
- '%WINDIR%\regedit.exe' /s info.reg
- '<SYSTEM32>\sc.exe' start PolicyAgent
- '<SYSTEM32>\sc.exe' config PolicyAgent start= auto
- '<SYSTEM32>\sc.exe' stop PolicyAgent
- %TEMP%\nscA.tmp\AccessControl.dll
- %CommonProgramFiles%\Intel\config-n.xml
- %CommonProgramFiles%\Intel\config-s.xml
- %TEMP%\nscA.tmp\nsB.tmp
- %TEMP%\nscA.tmp\nsExec.dll
- %TEMP%\nscA.tmp\System.dll
- %CommonProgramFiles%\Intel\vison.txt
- %CommonProgramFiles%\Intel\note.txt
- %CommonProgramFiles%\Intel\ypac.txt
- %CommonProgramFiles%\Intel\prvdisk.sys
- %CommonProgramFiles%\Intel\suject.db
- %CommonProgramFiles%\Intel\igfxsvrc.exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\ol[1].asp
- %TEMP%\nsd2.tmp\nsF.tmp
- %CommonProgramFiles%\Intel\note.vbs
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsd2.tmp\ns11.tmp
- %TEMP%\nsd2.tmp\ns10.tmp
- %CommonProgramFiles%\Intel\pro.txt
- %TEMP%\nscA.tmp\nsD.tmp
- %TEMP%\nscA.tmp\nsC.tmp
- %TEMP%\nscA.tmp\nsE.tmp
- <SYSTEM32>\PrvMon\prvdisk.sys
- %WINDIR%\tudouva.pac
- %CommonProgramFiles%\Intel\sqlite3.dll
- %TEMP%\nsd2.tmp\InetLoad.dll
- %TEMP%\nsd2.tmp\nsRandom.dll
- %PROGRAM_FILES%\eccbdwdlz\un0426234006816.exe
- <Текущая директория>\op.ini
- %TEMP%\nsd2.tmp\nsplugin.dll
- %TEMP%\nsd2.tmp\Internet.dll
- %PROGRAM_FILES%\eccbdwdlz\reginfo.xml
- %PROGRAM_FILES%\eccbdwdlz\s0001.xml
- %PROGRAM_FILES%\eccbdwdlz\menu.xml
- %PROGRAM_FILES%\eccbdwdlz\temp0426234006816.ini
- %TEMP%\nsd2.tmp\System.dll
- %PROGRAM_FILES%\eccbdwdlz\ser000.xml
- %TEMP%\nsd2.tmp\ns6.tmp
- %TEMP%\nsd2.tmp\ns5.tmp
- %PROGRAM_FILES%\eccbdwdlz\info.reg
- %PROGRAM_FILES%\eccbdwdlz\mysetup.exe
- %TEMP%\nsd2.tmp\ns8.tmp
- %TEMP%\nsd2.tmp\ns7.tmp
- %PROGRAM_FILES%\eccbdwdlz\wrz2pn.txt
- <Текущая директория>\tx.ini
- %PROGRAM_FILES%\eccbdwdlz\mrjhvbr.exe
- %TEMP%\nsd2.tmp\ns4.tmp
- %TEMP%\nsd2.tmp\ns3.tmp
- %TEMP%\nsd2.tmp\nsExec.dll
- <Текущая директория>\tx.ini
- %PROGRAM_FILES%\eccbdwdlz\mrjhvbr.exe
- %TEMP%\nsd2.tmp\InetLoad.dll
- <Текущая директория>\op.ini
- %TEMP%\nsd2.tmp\ns11.tmp
- %PROGRAM_FILES%\eccbdwdlz\info.reg
- %PROGRAM_FILES%\eccbdwdlz\reginfo.xml
- %TEMP%\nsd2.tmp\ns10.tmp
- %TEMP%\nsd2.tmp\nsF.tmp
- %PROGRAM_FILES%\eccbdwdlz\un0426234006816.exe
- %CommonProgramFiles%\Intel\note.vbs
- %PROGRAM_FILES%\eccbdwdlz\wrz2pn.txt
- %PROGRAM_FILES%\eccbdwdlz\temp0426234006816.ini
- %TEMP%\nsd2.tmp\System.dll
- %TEMP%\nsd2.tmp\nsExec.dll
- %TEMP%\nsd2.tmp\Internet.dll
- %TEMP%\nsd2.tmp\nsRandom.dll
- %TEMP%\nsd2.tmp\nsplugin.dll
- %TEMP%\nscA.tmp\nsB.tmp
- %TEMP%\nsd2.tmp\ns8.tmp
- %TEMP%\nscA.tmp\nsD.tmp
- %TEMP%\nscA.tmp\nsC.tmp
- %TEMP%\nsd2.tmp\ns7.tmp
- %TEMP%\nsd2.tmp\ns4.tmp
- %TEMP%\nsd2.tmp\ns3.tmp
- %TEMP%\nsd2.tmp\ns6.tmp
- %TEMP%\nsd2.tmp\ns5.tmp
- %PROGRAM_FILES%\eccbdwdlz\ser000.xml
- %PROGRAM_FILES%\eccbdwdlz\mysetup.exe
- %PROGRAM_FILES%\eccbdwdlz\menu.xml
- %PROGRAM_FILES%\eccbdwdlz\s0001.xml
- %TEMP%\nscA.tmp\System.dll
- %CommonProgramFiles%\Intel\prvdisk.sys
- %TEMP%\nscA.tmp\nsE.tmp
- %TEMP%\nscA.tmp\nsExec.dll
- %TEMP%\nscA.tmp\AccessControl.dll
- 'localhost':1042
- 'tj.##nzhuan.co':80
- 'm.###nong.com':888
- tj.##nzhuan.co/ol.asp?c=###########################
- tj.##nzhuan.co/svr.asp?c=########################################
- DNS ASK tj.##nzhuan.co
- DNS ASK m.###nong.com
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'