Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{8B877E7B-1C5E-34F5-F197-CAC5E70855E9}] 'StubPath' = 'msjava32.exe'
- <SYSTEM32>\reg.exe add hklm\SYSTEM\CurrentControlSet\Services\secdrv /v imagepath /t REG_EXPAND_SZ /d system32\DRIVERS\Secdrv.sys /f
- <SYSTEM32>\reg.exe add hklm\SYSTEM\CurrentControlSet\Services\secdrv /v imagepath /t REG_EXPAND_SZ /d \??\"%HOMEPATH%\53297.dat" /f
- %WINDIR%\Installer\b254ee.msi
- <SYSTEM32>\msjava32.exe
- <SYSTEM32>\dllcache\cic23ux.sys
- %HOMEPATH%\53297.tmp
- %HOMEPATH%\Cookies\index16.dat
- %HOMEPATH%\Cookies\index16.dat
- %HOMEPATH%\53297.dat
- '74.##.184.170':80