Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'navert.exe' = '%PROGRAM_FILES%\Internet Explorer\navert.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%PROGRAM_FILES%\Internet Explorer\lexplore.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Internet Explorer\navert.exe' = '%PROGRAM_FILES%\Internet Explorer\navert.exe:*:Enabled:navert.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Internet Explorer\lexplore.exe' = '%PROGRAM_FILES%\Internet Explorer\lexplore.exe:*:Enabled:lexplore.exe'
- %PROGRAM_FILES%\Internet Explorer\lexplore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\lexplore[1].exe
- %PROGRAM_FILES%\Internet Explorer\greensys.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\greensys[1].exe
- %PROGRAM_FILES%\Internet Explorer\navert.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\navert[1].exe
- %PROGRAM_FILES%\Internet Explorer\systeme.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\systeme[1].dll
- 'gg##ol.com':80
- gg##ol.com/a/9300/lexplore.exe
- gg##ol.com/a/9300/greensys.exe
- gg##ol.com/a/navert.exe
- gg##ol.com/a/systeme.dll
- DNS ASK gg##ol.com
- ClassName: 'Indicator' WindowName: ''