Техническая информация
- '%WINDIR%\regedit.exe' /s "config.reg"
- '%APPDATA%\CCleaner\CCleaner.exe'
- '%APPDATA%\4\ooo.exe'
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\4\start (4).bat" "
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %APPDATA%\4\ppp.mp4
- [<HKCU>\SOFTWARE\FileZilla Client]
- [<HKCU>\Software\RIT\The Bat!]
- [<HKCU>\Software\Headlight\GetRight]
- [<HKLM>\SOFTWARE\FileZilla Client]
- %APPDATA%\CCleaner\CCleaner.exe
- %TEMP%\AGI2.tmp
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cookies.sqlite-shm
- %APPDATA%\CCleaner\video.mp4
- %APPDATA%\4\start (4).bat
- %APPDATA%\4\ppp.mp4
- %TEMP%\AGI1.tmp
- %APPDATA%\4\ooo.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cookies.sqlite-shm
- %TEMP%\AGI2.tmp
- %TEMP%\AGI1.tmp
- 'www.pi###orm.com':443
- DNS ASK www.pi###orm.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''