Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{76X1OF70-T77U-W05S-2221-85337QYLE6T8}] 'StubPath' = '%WINDIR%\install\explero.exe Restart'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Policies' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Policies' = ''
- '%WINDIR%\install\explero.exe'
- '%TEMP%\server no ip last.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %TEMP%\mmm.jpg
- %APPDATA%\%USERNAME%-wchelper.dll
- %APPDATA%\88E6680F\ak.tmp
- %TEMP%\%USERNAME%8
- %TEMP%\%USERNAME%7
- %TEMP%\mmm.jpg
- %TEMP%\server no ip last.exe
- %TEMP%\%USERNAME%2.txt
- %WINDIR%\install\explero.exe
- %APPDATA%\%USERNAME%-wchelper.dll
- %TEMP%\%USERNAME%7
- %TEMP%\%USERNAME%8
- %TEMP%\%USERNAME%2.txt
- %TEMP%\server no ip last.exe
- 'eg####.no-ip.org':81
- DNS ASK eg####.no-ip.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''