Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'JavaUpdate' = '%WINDIR%\system\JavaServer.exe'
- '<SYSTEM32>\Powder.exe'
- '<SYSTEM32>\SQL.exe'
- '<SYSTEM32>\cmd.exe' /c ""<SYSTEM32>\start.bat" "
- <SYSTEM32>\JavaServerUpdate.exe
- %WINDIR%\system\JavaServer.exe
- <SYSTEM32>\powder.pref
- <SYSTEM32>\Powder.exe
- <SYSTEM32>\SQL.exe
- <SYSTEM32>\start.bat
- 'da#####der.web44.net':80
- 'po###rtoy.co.uk':80
- po###rtoy.co.uk/Update.api?Ac#################
- da#####der.web44.net/iplog.php
- DNS ASK da#####der.web44.net
- DNS ASK www.ru
- DNS ASK po###rtoy.co.uk
- 'www.ru':0
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'