Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lupq.exe' = '"%APPDATA%\lupq.exe"'
- %WINDIR%\Tasks\fbagent.job
- %TEMP%\ 1snt.exe
- %TEMP%\ snt.exe
- iexplore.exe
- firefox.exe
- chrome.exe
- %APPDATA%\lupq.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\setup[1].php
- %TEMP%\2.tmp
- %TEMP%\4.tmp
- %TEMP%\3.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\setup[1].php
- %TEMP%\ 1snt.exe
- %TEMP%\ snt.exe
- %APPDATA%\inj.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\setup[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\setup[1].php
- 'st##001.com':80
- st##001.com/1/setup.php?ac############################################
- st##001.com/1/setup.php?ac##################################################
- st##001.com/1/setup.php?ac#################################################
- st##001.com/1/setup.php?ac########################################################
- DNS ASK st##001.com
- '<IP-адрес в локальной сети>':1040
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''