Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RtHDVCpI' = '%APPDATA%\Realtek\Audio\HDA\RtHDVCpI.exe'
- '%TEMP%\88475882532.exe'
- '%APPDATA%\Realtek\Audio\HDA\RtHDVCpI.exe'
- '%TEMP%\88475882532.exe' (загружен из сети Интернет)
- %APPDATA%\Microsoft\Internet Explorer\UserData\Low\Temporary files\LSTCache.txt
- %HOMEPATH%\Desktop\My Shared Folder\MZђ.exe
- %HOMEPATH%\Desktop\My Shared Folder\$.exe
- %APPDATA%\Realtek\Audio\HDA\RtHDVCpI.exe
- %APPDATA%\Microsoft\Internet Explorer\UserData\Low\Temporary files\User Cache.ini
- %TEMP%\88475882532.exe
- 'se###.w4yserver.at':80
- 'ga###ait.com':80
- ga###ait.com/wp-content/plugins/wereviews/modules/libs/midia/ETX/FLPGGS
- se###.w4yserver.at/upload/media/88425882532
- DNS ASK se###.w4yserver.at
- DNS ASK ga###ait.com
- ClassName: 'Indicator' WindowName: '(null)'