Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MSUtil' = '"%HOMEPATH%\My Documents\SQL Server Document\avu.exe" -a'
- скрытых файлов
- %HOMEPATH%\My Documents\SQL Server Document\avu.exe -op
- %HOMEPATH%\My Documents\SQL Server Document\avu.exe
- %HOMEPATH%\My Documents\SQL Server Document\avb.dll
- %HOMEPATH%\My Documents\SQL Server Document\setfile.zip
- %HOMEPATH%\My Documents\SQL Server Document\avod.exe
- %HOMEPATH%\My Documents\SQL Server Document\setfile.zip
- 'aa#####2.pnsweb.net.cn':80
- aa#####2.pnsweb.net.cn/ls_install.asp?ma#########################
- DNS ASK aa#####2.pnsweb.net.cn
- '<IP-адрес в локальной сети>':1035
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: 'FolderView'
- ClassName: 'WorkerW' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''