Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ATI External Event Utility EXE Module' = '<SYSTEM32>\ati2еviw.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{B5F0ED0A-8845-12F0-29D7-43E3930FB558}] 'StubPath' = '<SYSTEM32>\ati2еviw.exe'
- <SYSTEM32>\ctfmon.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\ati2еviw.exe
- '21#.8.106.7':3389
- '21#.#0.75.36':3389
- '21#.#1.62.33':3389
- '94.##1.227.134':22
- '92.##.157.126':3389
- '81.##.117.235':3389