Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinUp' = '%WINDIR%\WinUp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\WinUp.exe' = '%WINDIR%\WinUp.exe:*:Enabled:Windows Update Center'
- %WINDIR%\WinUp.exe
- %HOMEPATH%\eee\eee.final.scr.2\photo.exe
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %HOMEPATH%\eee\eee.final.scr.2\photo.jpg
- %WINDIR%\WinUp.exe
- %HOMEPATH%\Recent\photo.lnk
- %HOMEPATH%\Recent\eee.final.scr.2.lnk
- %HOMEPATH%\eee\eee.final.scr.2\photo.jpg
- %HOMEPATH%\eee\eee.final.scr.2\eee.gz
- %HOMEPATH%\eee\eee.final.scr.2\photo.exe
- %HOMEPATH%\eee\eee.final.scr.2\config.txt
- 'ez##.#wardspace.com':80
- ez##.#wardspace.com/ip.html
- DNS ASK ez##.#wardspace.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''