Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'startkey' = '<SYSTEM32>\server.exe'
- %WINDIR%\explorer.exe
- %HOMEPATH%\desktop\lisp_success.doc
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %TEMP%\0.exe
- %TEMP%\1.exe
- %WINDIR%\syswow64\plugin1.dat
- %WINDIR%\syswow64\server.exe
- %APPDATA%\addons.dat
- '%TEMP%\0.exe'
- '%TEMP%\1.exe'