Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svcdata' = '<SYSTEM32>\svcdata.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'drivers' = '%PROGRAM_FILES%\proc\drivers.exe'
- <SYSTEM32>\svcdata.exe
- %PROGRAM_FILES%\proc\drivers.exe
- <SYSTEM32>\cmd.exe /c <Текущая директория>\sro2009122610511405.bat
- <SYSTEM32>\svcdata.exe
- <Текущая директория>\sro2009122610511405.bat
- %WINDIR%\Driver.dll
- %PROGRAM_FILES%\proc\drivers.exe
- %TEMP%\~DFE131.tmp
- 'sm##.gmail.com':587
- DNS ASK sm##.gmail.com
- ClassName: 'Shell_TrayWnd' WindowName: ''