Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Client Server Runtime Subsystem' = '"%ALLUSERSPROFILE%\Application Data\Windows\csrss.exe"'
- %TEMP%\nsm3.tmp\System.dll
- %ALLUSERSPROFILE%\Application Data\Windows\csrss.exe
- %TEMP%\6893A5D897\state.tmp
- %TEMP%\qiDyNgOmG4HcR4kNgC.niJXZ
- %TEMP%\nsg2.tmp
- %TEMP%\privacy_policy.php
- %TEMP%\PKimage.aspx1402444885.html
- %TEMP%\6893A5D897\state.tmp в %TEMP%\6893A5D897\state
- '19#.#3.244.244':443
- '15#.35.32.5':443
- 'localhost':1039