Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Adobe Updater Startup Utility' = '%HOMEPATH%\AdobeChecker.exe'
- '%HOMEPATH%\Rar.exe' e "%HOMEPATH%\pub.rar" -p1nterfer0n "%HOMEPATH%\"
- '%HOMEPATH%\CertMgr.exe' -add -c "%HOMEPATH%\sert.cer" -s -r localMachine root
- %HOMEPATH%\pub.rar
- %HOMEPATH%\Rar.exe
- %HOMEPATH%\CertMgr.exe
- %HOMEPATH%\Resume.pdf
- %HOMEPATH%\sert.cer
- %HOMEPATH%\Rar.exe
- %HOMEPATH%\CertMgr.exe
- %HOMEPATH%\sert.cer
- %HOMEPATH%\pub.rar
- %HOMEPATH%\Resume.pdf
- %HOMEPATH%\Rar.exe
- %HOMEPATH%\CertMgr.exe
- %HOMEPATH%\sert.cer
- 'no####lembro.com':80
- 'www.ad##e.com':80
- no####lembro.com/PHP/develop/sql_install.php?na###########
- no####lembro.com/PHP/develop/config_add.php?na###########
- www.ad##e.com/
- no####lembro.com/PHP/sucrot/pub.rar
- DNS ASK no####lembro.com
- DNS ASK www.ad##e.com
- ClassName: 'Indicator' WindowName: ''