Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Cache' = '%ALLUSERSPROFILE%\Package\lua.exe %ALLUSERSPROFILE%\Package\lua.dll'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Check' = '%ALLUSERSPROFILE%\adb.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = ''
- '<SYSTEM32>\msiexec.exe' /q /i %ALLUSERSPROFILE%\i.msi
- %ALLUSERSPROFILE%\i.msi
- %ALLUSERSPROFILE%\package\mime\core.dll
- %ALLUSERSPROFILE%\package\socket\core.dll
- %ALLUSERSPROFILE%\package\lua\socket\http.lua
- %ALLUSERSPROFILE%\package\lua\ltn12.lua
- %ALLUSERSPROFILE%\package\lua.dll
- %ALLUSERSPROFILE%\package\lua.exe
- %ALLUSERSPROFILE%\package\lua5.1.dll
- %ALLUSERSPROFILE%\package\lua\mime.lua
- %ALLUSERSPROFILE%\package\run.vbs
- %ALLUSERSPROFILE%\package\lua\socket.lua
- %ALLUSERSPROFILE%\package\lua\socket\url.lua
- %ALLUSERSPROFILE%\package\hvd
- http://86.##5.252.45/108.msi
- /lsD1DdhMttgc23/page.php?id################## via 18#.#43.214.108
- '%ALLUSERSPROFILE%\package\lua.exe' %ALLUSERSPROFILE%\Package\lua.dll"
- '%WINDIR%\syswow64\cscript.exe' "%ALLUSERSPROFILE%\\Package\run.vbs" //e:vbscript //B //NOLOGO