Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Dump' = '%PROGRAM_FILES%\Dump\Dump.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\UnzipService] 'ImagePath' = 'System32\Mseus.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\UnzipService] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Mseu] 'Start' = '00000002'
- %TEMP%\Regini.exe
- %TEMP%\mseus.ini
- <SYSTEM32>\mseus.exe
- %TEMP%\Instdrv.exe
- <SYSTEM32>\ainf.inf
- <SYSTEM32>\tokset.dll
- %TEMP%\Mseu.ini
- %PROGRAM_FILES%\Dump\Dump.exe
- <DRIVERS>\Mstart.sys
- %TEMP%\Dump.ini
- <DRIVERS>\Mseu.sys
- %TEMP%\Regini.exe
- %TEMP%\mseus.ini
- %TEMP%\Instdrv.exe
- %TEMP%\Mseu.ini
- %TEMP%\Regini.exe
- %TEMP%\Dump.ini
- ClassName: 'Shell_TrayWnd' WindowName: ''