Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'wincl' = '%APPDATA%\WinMav\winmav.exe'
- '%APPDATA%\WinMav\winmav.exe'
- %APPDATA%\WinMav\winmav.exe
- %APPDATA%\__check__8232.xyz
- %APPDATA%\__check__8232.xyz
- 'ig#####tromedico.com':80
- 'www.ha####illver.co.uk':80
- 'www.wo####smeding.nl':80
- 'www.vi####rdwest.org.nz':80
- 'www.vi####missions.org':80
- http://ig#####tromedico.com/
- http://www.ha####illver.co.uk/
- http://www.wo####smeding.nl/
- http://www.vi####rdwest.org.nz/
- http://www.vi####missions.org/
- DNS ASK ig#####tromedico.com
- DNS ASK www.ha####illver.co.uk
- DNS ASK www.wo####smeding.nl
- DNS ASK www.vi####rdwest.org.nz
- DNS ASK www.vi####missions.org
- ClassName: 'Indicator' WindowName: ''