Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'EthernetATAPI' = '%TEMP%\kernel.exe'
- '%TEMP%\kernelup.scr'
- '%TEMP%\kernel.exe'
- %TEMP%\cert8.db
- %TEMP%\secmod.db
- %TEMP%\Set.txt
- %TEMP%\kernel.exe
- %TEMP%\kernelup.scr
- %TEMP%\key3.db
- 'ft#.#rivehq.com':21
- DNS ASK ft#.#rivehq.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''