Техническая информация
- '<LS_APPDATA>\{KY7SRUR3-SAVS-AUXW-G29X-EMUDU6QW1WA8}\ss659zuui.exe'
- '<LS_APPDATA>\{KY7SRUR3-SAVS-AUXW-G29X-EMUDU6QW1WA8}\5s6guy01k365.exe'
- '<LS_APPDATA>\{KY7SRUR3-SAVS-AUXW-G29X-EMUDU6QW1WA8}\ss659zuui.exe' (загружен из сети Интернет)
- '<LS_APPDATA>\{KY7SRUR3-SAVS-AUXW-G29X-EMUDU6QW1WA8}\5s6guy01k365.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\Tlooks[1].swf
- <LS_APPDATA>\{KY7SRUR3-SAVS-AUXW-G29X-EMUDU6QW1WA8}\ss659zuui.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Clientts[1].swf
- <LS_APPDATA>\{KY7SRUR3-SAVS-AUXW-G29X-EMUDU6QW1WA8}\5s6guy01k365.exe
- 'ru####-pos005.com':80
- ru####-pos005.com/framework/php/adm/Clientts.swf
- ru####-pos005.com/framework/php/adm/Tlooks.swf
- DNS ASK ru####-pos005.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TMyUpForm' WindowName: ''