Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCU' = ''
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}] 'StubPath' = '<SYSTEM32>\install\server.exe Restart'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKLM' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'јјјCCCCЅјјјњјјјй7PЏ|йФMщьјШCЊШ5њC№4ZьјЏ|жееШ5¬ФDщьјUЄnCCWDб7|?‘4ZьјЅпклЅИюьјTЩrCC7D7{TBCCЏJ0Zьј77лё7ЁTXhCCъ?ё?BЩЙV7{TФrCCгвзй7PЏ|йФ,ъьјШCЊШ5њC№њTьјЙ™Tьј7©мюьјTзUCC0ZьјЩјјј7©Ё¬ьјTbCCЏ|жееШ5¬Ф+ъьјUЛmCCWDб1ьј?‘њTьјЅпклн5Ё7L7zT jCC7D7c?GЅА™6шўCЂаИёЂ“ЙЁ7ём7s—w1пЅ7zTudCCW№ч9gЙgжгвз,й7P?xP5щ@7щ@TѓdCCЏ|йФ’ыьјШCЊШ5њ1йP7щ@TvXCC5щL5йHЏ|жееШ5¬Ф‰ыьј1щ@T/oCCUelCCWL7щL7йH7Yб,й7Pнпкл7F5щ@7щ@TXkCCЏ|йФ ыьјШCЊШ5њ7щ@TZiCC7L9JВ™Ѕјјј7щ@і ш¤CмTбSCCм1щ@T¬dCCж4и¤CятЙ\7{7й@TЙoCCЏ|жееШ5¬Ф' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'јјјCCCCЅјјјњјјјй7PЏ|йФMщьјШCЊШ5њC№4ZьјЏ|жееШ5¬ФDщьјUЄnCCWDб7|?‘4ZьјЅпклЅИюьјTЩrCC7D7{TBCCЏJ0Zьј77лё7ЁTXhCCъ?ё?BЩЙV7{TФrCCгвзй7PЏ|йФ,ъьјШCЊШ5њC№њTьјЙ™Tьј7©мюьјTзUCC0ZьјЩјјј7©Ё¬ьјTbCCЏ|жееШ5¬Ф+ъьјUЛmCCWDб1ьј?‘њTьјЅпклн5Ё7L7zT jCC7D7c?GЅА™6шўCЂаИёЂ“ЙЁ7ём7s—w1пЅ7zTudCCW№ч9gЙgжгвз,й7P?xP5щ@7щ@TѓdCCЏ|йФ’ыьјШCЊШ5њ1йP7щ@TvXCC5щL5йHЏ|жееШ5¬Ф‰ыьј1щ@T/oCCUelCCWL7щL7йH7Yб,й7Pнпкл7F5щ@7щ@TXkCCЏ|йФ ыьјШCЊШ5њ7щ@TZiCC7L9JВ™Ѕјјј7щ@і ш¤CмTбSCCм1щ@T¬dCCж4и¤CятЙ\7{7й@TЙoCCЏ|жееШ5¬Ф' = ''
- %TEMP%\XX--XX--XX.txt
- <SYSTEM32>\install\server.exe
- <SYSTEM32>\PerfStringBackup.TMP
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'