Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Skype Portable' = '%HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\SkypePortable_.exe'
- '%HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\Death.exe'
- '%HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\SkypePortable_.exe'
- %HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\Death.exe
- %HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\pthread.dll
- %HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\reaper.conf
- %HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\curl.dll
- %HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\SkypePortable_.exe
- %HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\bitcoin.conf
- %HOMEPATH%\My Documents\My Pictures\Desktop Backgrounds\bitcoin-reaper.cl
- 'ga###leaks.com':80
- 'wp#d':80
- ga###leaks.com/b.txt
- wp#d/wpad.dat
- DNS ASK ga###leaks.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'