Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'cimone' = 'C:\comine.exe'
- 'C:\toskngr.exe'
- '%PROGRAM_FILES%\Catolag.exe'
- '%PROGRAM_FILES%\do706.exe'
- '<SYSTEM32>\cmd.exe' /c "%PROGRAM_FILES%\Boot.bat"
- 360tray.exe
- C:\text.txt
- C:\toskngr.exe
- %PROGRAM_FILES%\Boot.bat
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %PROGRAM_FILES%\Catolag.exe
- %TEMP%\FP1.tmp
- %PROGRAM_FILES%\do706.exe
- C:\toskngr.exe
- %TEMP%\FP1.tmp
- 'localhost':1037
- DNS ASK ud#.#job123.com
- 'ud#.#job123.com':31801
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'Progman' WindowName: ''