Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%HOMEPATH%\syselp.exe'
- '%HOMEPATH%\syslt.exe'
- '%TEMP%\crc32e.exe'
- %HOMEPATH%\naslcl32.dll
- %HOMEPATH%\syselp.exe
- %TEMP%\naslcl32.dll
- %TEMP%\nosst.dat
- %TEMP%\sysmon.ocx
- %HOMEPATH%\syslt.dat
- <SYSTEM32>\naslcl32.dll
- %HOMEPATH%\syselp.dat
- %HOMEPATH%\syslt.exe
- %HOMEPATH%\sysltst.dat
- %TEMP%\zdt.dll
- %TEMP%\tcpsvcs.exe
- %TEMP%\tzchange.exe
- %TEMP%\nos.exe
- %TEMP%\crc32e.exe
- %TEMP%\elp.exe
- %TEMP%\wshatm.dll
- %TEMP%\wshbth.dll
- %TEMP%\wsecedit.dll
- %TEMP%\sqlwoa.dll
- %TEMP%\tprdpw32.dll
- %TEMP%\elp.exe
- %TEMP%\nos.exe
- 'aa#####smzt.no-ip.info':2455
- DNS ASK aa#####smzt.no-ip.info
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'