Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\MedicaCentderikc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\MedicaCentderikc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- 'MedicaCentderikc' <SYSTEM32>\svchost.exe -k netsvcs
- %WINDIR%\myinformations.ini
- %WINDIR%\fuckyou.txt
- %WINDIR%\fuckyou.reg
- %TEMP%\wi790098nd.temp
- %WINDIR%\fuckyou.txt
- %WINDIR%\fuckyou.reg
- %WINDIR%\myinformations.ini
- %TEMP%\wi790098nd.temp в %WINDIR%\syswow64\rnetel.dll
- %WINDIR%\fuckyou.txt