Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\svupdate32.exe
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 280
- %TEMP%\pin
- %TEMP%\zin
- %TEMP%\googleofficechk.sct
- %LOCALAPPDATA%\virtualstore\msrvc32.exe
- %TEMP%\1217759.cvr
- 'fi###image.com':80
- http://fi###image.com/img/image.php
- DNS ASK fi###image.com