Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '<SYSTEM32>\kernel32.exe'
- <LS_APPDATA>\Xenocode\Sandbox\(c) 1998-2008 Yahoo! Inc. All rights reserved.\5.6.100.28\2013.03.30T13.40\Native\STUBEXE\@SYSTEM@\RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 2
- <LS_APPDATA>\Xenocode\Sandbox\(c) 1998-2008 Yahoo! Inc. All rights reserved.\5.6.100.28\2013.03.30T13.40\Native\STUBEXE\@SYSTEM@\kernel32.exe
- <LS_APPDATA>\Xenocode\Sandbox\(c) 1998-2008 Yahoo! Inc. All rights reserved.\5.6.100.28\2013.03.30T13.40\Native\STUBEXE\@SYSTEM@\RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 1
- <LS_APPDATA>\Xenocode\Sandbox\(c) 1998-2008 Yahoo! Inc. All rights reserved.\5.6.100.28\2013.03.30T13.40\Virtual\STUBEXE\@APPDIR@\setup.exe
- <LS_APPDATA>\Xenocode\Sandbox\(c) 1998-2008 Yahoo! Inc. All rights reserved.\5.6.100.28\2013.03.30T13.40\Native\STUBEXE\@SYSTEM@\RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 8
- Библиотека-обработчик для процесса 'kernel32.exe': <SYSTEM32>\kernel32.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '1'
- <SYSTEM32>\kernel32.exe
- %TEMP%\CRNJEUFU - 10-23-2012-1.16.26-AM.gif
- 'sm##.gmail.com':587
- DNS ASK sm##.gmail.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''