Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'conime.exe' = ''
- %WINDIR%\Temp\conime.exe
- %WINDIR%\regedit.exe /s %WINDIR%\temp\k.reg
- %WINDIR%\Temp\k.reg
- %WINDIR%\Temp\conime.exe
- %WINDIR%\Temp\k.reg
- 'pa####001.myfw.us':80
- 'pa###.myfw.us':80
- '18#.#2.212.133':80
- pa####001.myfw.us/ru/%43%4e%6d/art/porth.asp
- pa###.myfw.us/ru/%43%4e%6d/art/porth.asp
- 18#.#2.212.133/ru/li/htp.asp
- DNS ASK pa####001.myfw.us
- DNS ASK pa###.myfw.us
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''