Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfmon.exe' = '<SYSTEM32>\ctfmon.exe'
- '%TEMP%\~nsu.tmp\Au_.exe' /S _?=%TEMP%\
- '%TEMP%\uninst.exe' /S
- '%WINDIR%\regedit.exe' /s run.reg
- '<SYSTEM32>\regsvr32.exe' /u /s igfxpph.dll
- '<SYSTEM32>\regsvr32.exe' /u /s nvcpl.dll
- %HOMEPATH%\Favorites\ц·ІИнјюХѕ.url
- %TEMP%\nsp3.tmp\UserInfo.dll
- %TEMP%\nsp3.tmp\System.dll
- %HOMEPATH%\Favorites\РВАЛ.url
- %HOMEPATH%\Favorites\УЕїбНш.url
- %HOMEPATH%\Favorites\ЦР№ШґеФЪПЯ .url
- <SYSTEM32>\run.reg
- %TEMP%\nst5.tmp
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsc7.tmp
- <DRIVERS>\rtkhdaud.dat
- %TEMP%\temp.ini
- %TEMP%\uninst.exe
- %HOMEPATH%\Favorites\ПµНіґуНжјТ.url
- %HOMEPATH%\Favorites\Google.url
- %HOMEPATH%\Favorites\°Щ¶И.url
- %HOMEPATH%\Favorites\°Щ¶ИТ»ПВЈ¬ДгѕНЦЄµА.url
- %TEMP%\nsf2.tmp
- <SYSTEM32>\oeminfo.ini
- <SYSTEM32>\oemlogo.bmp
- %HOMEPATH%\Favorites\ВМЙ«Инјю.url
- %HOMEPATH%\Favorites\Ммј«Нш.url
- %HOMEPATH%\Favorites\НшХѕЦ®јТ.url
- %HOMEPATH%\Favorites\НшЦ·µјєЅ.url
- %HOMEPATH%\Favorites\Зэ¶ЇЦ®јТ.url
- %HOMEPATH%\Favorites\ЛДјѕУйАЦВЫМі.url
- %HOMEPATH%\Favorites\ЛСєь.url
- %TEMP%\uninst.exe
- %TEMP%\temp.ini
- %TEMP%\nsp3.tmp\UserInfo.dll
- <SYSTEM32>\run.reg
- %TEMP%\nsp3.tmp\System.dll
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''