Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SystemHost' = '%APPDATA%\svchost.exe'
- '%APPDATA%\jusched.exe'
- '%APPDATA%\svchost.exe'
- <Текущая директория>\MT2Login.ini
- %APPDATA%\svchost.exe
- %APPDATA%\%USERNAME%.0FABFBFF000206D7.ini
- %TEMP%\aut3.tmp
- %APPDATA%\jusched.exe
- %TEMP%\jusched.exe
- %TEMP%\aut1.tmp
- %TEMP%\svchost.exe
- %TEMP%\aut2.tmp
- %APPDATA%\svchost.exe
- %APPDATA%\jusched.exe
- %TEMP%\svchost.exe
- %TEMP%\aut3.tmp
- %TEMP%\jusched.exe
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- 'www.wa###men.cba.pl':80
- www.wa###men.cba.pl/clients/All.txt
- www.wa###men.cba.pl/clients/URNXYMAV.0FABFBFF000206D7.txt
- www.wa###men.cba.pl/index.php
- DNS ASK www.wa###men.cba.pl
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''