Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Lcwgwr' = '%APPDATA%\Microsoft\Windows\Lcwgwr.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows System Installer' = '%APPDATA%\WindowsUpdate\System.exe'
- '<SYSTEM32>\mspaint.exe'
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\mspaint.exe
- %APPDATA%\Microsoft\Windows\Lcwgwr.exe
- %TEMP%\winupdata
- %APPDATA%\v07
- %APPDATA%\WindowsUpdate\System.exe
- 's.###spgpzz.ru':3721
- 'ap#.##pmania.com':80
- http://ap#.##pmania.com/
- DNS ASK s.###gbprgo.ru
- DNS ASK s.###zjaijy.ru
- DNS ASK ap#.##pmania.com
- DNS ASK s.###spgpzz.ru