Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'jrun32' = '%APPDATA%\AppData\jrun32.exe -notray'
- '%APPDATA%\AppData\jrun32.exe' -notray
- '%APPDATA%\AppData\jrun32.exe'
- '%TEMP%\Installer.exe'
- '%TEMP%\RedBotPro.exe'
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v jrun32 /t REG_SZ /d "%APPDATA%\AppData\jrun32.exe -notray" /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\KDSCKTPK.bat" "
- '<SYSTEM32>\ipconfig.exe'
- <SYSTEM32>\ipconfig.exe
- %APPDATA%\AppData\jrun32.exe
- %TEMP%\KDSCKTPK.bat
- %TEMP%\RedBotPro.exe
- %TEMP%\Installer.exe
- %TEMP%\~DF2F1F.tmp
- %TEMP%\~DF70F3.tmp
- 'le##rix.org':80
- le##rix.org/tools/parser.php?us######################################################################################
- DNS ASK le##rix.org
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'