Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'E01AE2BB-4C89-4AB1-A221-824E81DF2C87' = '%APPDATA%\{E01AE2BB-4C89-4AB1-A221-824E81DF2C87}\Msascue.exe'
- '%APPDATA%\{E01AE2BB-4C89-4AB1-A221-824E81DF2C87}\Msascue.exe'
- '%TEMP%\becky-1.4.exe'
- '%TEMP%\idman612.exe'
- %APPDATA%\{E01AE2BB-4C89-4AB1-A221-824E81DF2C87}\Msascue.exe
- %TEMP%\becky-1.4.exe
- %TEMP%\idman612.exe
- 'be###.zerem.info':80
- 'wp#d':80
- wp#d/wpad.dat
- be###.zerem.info/bky/add-log
- be###.zerem.info/bky/get-inst
- DNS ASK be###.zerem.info
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'