Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Web Event Logger' = '{79FEACFF-FFCE-815E-A900-316290B5B738}'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfmon.exe' = '<SYSTEM32>\ctfmon.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1601' = '00000000'
- <SYSTEM32>\jnobmpbb.exe
- <SYSTEM32>\hlmckeqn.dll
- <SYSTEM32>\surf.dat
- %TEMP%\kdojpbpk.htm
- %TEMP%\kibcoabd.htm
- %TEMP%\bjjpgmdj.htm
- %TEMP%\kibcoabd.htm
- %TEMP%\kdojpbpk.htm
- http://ga##prom.ru/index.htm
- http://ga##prom.ru/disabled/style.css
- http://ga##prom.ru/disabled/modernizr.js
- http://ga##prom.ru/disabled/html5shiv.js
- http://ga##prom.ru/disabled/i/_/b-header-parking__content-logo.png
- http://ga##prom.ru/disabled/i/_/b-menu-external__logo_style_regru.png
- http://ga##prom.ru/disabled/i/_/b-http-status_icon_stop.png
- http://ga##prom.ru/disabled/script.js
- http://ga##prom.ru/disabled/english.js
- http://www.re##ine.ru/index.php
- DNS ASK ki###-bank.ru
- DNS ASK re##ine.ru
- DNS ASK ga##prom.ru
- DNS ASK co##.jquery.com
- ClassName: 'IEFrame' WindowName: 'MicroSoft-Corp2 - Microsoft Internet Explorer'
- ClassName: 'IEFrame' WindowName: 'MicroSoft-Corp1 - Microsoft Internet Explorer'
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: 'MicroSoft-Corp3 - Microsoft Internet Explorer'
- '<SYSTEM32>\jnobmpbb.exe'
- '<SYSTEM32>\jnobmpbb.exe' ' (with hidden window)
- '%ProgramFiles%\internet explorer\iexplore.exe' %TEMP%\kibcoabd.htm
- '%ProgramFiles%\internet explorer\iexplore.exe' %TEMP%\kdojpbpk.htm
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles%\Microsoft Office\Office12\GrooveUtil.DLL",GetResourceModulePath g6BojgnB7kM4VJ3x/i0Sl93nk84Oc6Ut
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles%\Microsoft Office\Office12\GrooveUtil.DLL",GetResourceModulePath IlLnyRalPXeNKwbzaR/IK1bY1AHhXqx2
- '<SYSTEM32>\ctfmon.exe'
- '%ProgramFiles%\internet explorer\iexplore.exe' %TEMP%\bjjpgmdj.htm
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles%\Microsoft Office\Office12\GrooveUtil.DLL",GetResourceModulePath suE72VfsJqifxKMJwRtglbSufiqJi6tq