Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, %LOCALAPPDATA%\ctYSbYxeo\WKtrtjZhY.exe'
- %WINDIR%\syswow64\resmon.exe
- %WINDIR%\syswow64\rasphone.exe
- %WINDIR%\syswow64\osk.exe
- %WINDIR%\syswow64\diantz.exe
- %WINDIR%\syswow64\diantz.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe
- %TEMP%\client.exe
- %TEMP%\1111.exe
- %LOCALAPPDATA%\ctysbyxeo\wktrtjzhy.exe
- '45.#32.1.14':38383
- '45.#32.1.14':38383
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '%TEMP%\client.exe'
- '%TEMP%\1111.exe'
- '%WINDIR%\syswow64\xpsrchvw.exe'
- '%WINDIR%\syswow64\resmon.exe'
- '%WINDIR%\explorer.exe'
- '%WINDIR%\syswow64\rasphone.exe'
- '<SYSTEM32>\ctfmon.exe'
- '%WINDIR%\syswow64\osk.exe'
- '%WINDIR%\syswow64\diantz.exe'