Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{C4W5YE0V-EH24-V36W-5XOM-0516IBFKFC7A}] 'StubPath' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCU' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKLMd' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCUd' = ''
- %HOMEPATH%\Start Menu\Programs\Startup\update.exe
- '%HOMEPATH%\Start Menu\Programs\Startup\update.exe'
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\notepad.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\notepad.exe
- %PROGRAM_FILES%\update\Update.exe
- 'fo####iu.zapto.org':82
- DNS ASK fo####iu.zapto.org
- ClassName: 'Indicator' WindowName: '(null)'