Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ATEKQ' = '%HOMEPATH%\ATEKQ\start.vbs'
- '%HOMEPATH%\ATEKQ\AutoIt3.exe' ETLYMZFE.dat
- '%HOMEPATH%\ATEKQ\AutoIt3.exe' file2.dat
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe'
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\taskkill.exe' /IM mshta.exe
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\ATEKQ\run.vbs"
- '<SYSTEM32>\mshta.exe'
- <SYSTEM32>\notepad.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
- %TEMP%\gglrldy
- %HOMEPATH%\ATEKQ\run.vbs
- %HOMEPATH%\ATEKQ\file2.au3.tbl
- %HOMEPATH%\ATEKQ\ETLYMZFE.dat
- %HOMEPATH%\ATEKQ\start.vbs
- %HOMEPATH%\ATEKQ\start.cmd
- %TEMP%\erpkjfs
- %HOMEPATH%\ATEKQ\file.au3.tbl
- %HOMEPATH%\ATEKQ\file3.dat
- %HOMEPATH%\ATEKQ\file2.dat
- %HOMEPATH%\ATEKQ\file.dat
- %HOMEPATH%\ATEKQ\AutoIt3.exe
- %HOMEPATH%\ATEKQ\license.rtf
- %HOMEPATH%\ATEKQ\settings.ini
- %HOMEPATH%\ATEKQ\data.dat
- %HOMEPATH%\ATEKQ\file.au3.tbl
- %HOMEPATH%\ATEKQ\license.rtf
- %HOMEPATH%\ATEKQ\run.vbs
- %HOMEPATH%\ATEKQ\file2.au3.tbl
- %HOMEPATH%\ATEKQ\settings.ini
- %HOMEPATH%\ATEKQ\file2.dat
- %HOMEPATH%\ATEKQ\file.dat
- %HOMEPATH%\ATEKQ\data.dat
- %HOMEPATH%\ATEKQ\AutoIt3.exe
- %HOMEPATH%\ATEKQ\ETLYMZFE.dat
- %TEMP%\erpkjfs
- %TEMP%\gglrldy
- 'be#####chabbi.no-ip.biz':100
- DNS ASK be#####chabbi.no-ip.biz
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''