Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ZUBIAOGWD98ABASD98H' = '%TEMP%\ZIOGA8D9BAD9GADH98D\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ZUBIAOGWD98ABASD98H' = '\ZIOGA8D9BAD9GADH98D\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'dTk22K' = '%HOMEPATH%\gDl99D\winlogon.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %TEMP%\ZIOGA8D9BAD9GADH98D\svchost.exe
- %APPDATA%\Imminent\Logs\22-04-2014
- %APPDATA%\Imminent\Path.dat
- C:\ZIOGA8D9BAD9GADH98D\svchost.exe
- %TEMP%\aut1.tmp
- %HOMEPATH%\fYy11H.YO2
- %HOMEPATH%\iKa37U.txt
- %HOMEPATH%\iKa37U.txt
- %HOMEPATH%\fYy11H.YO2
- %TEMP%\aut1.tmp
- 'im######monitor.zapto.org':9003
- DNS ASK im######monitor.zapto.org
- ClassName: 'Indicator' WindowName: '(null)'