Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] '{24F4D477-9E57-416A-8519-16D8A9BA0BCC}' = 'OLE Object'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RepServ Manager' = '<SYSTEM32>\mpcsvc.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RepServ Manager' = '<SYSTEM32>\mpcsvc.exe'
- Центр обеспечения безопасности (Security Center)
- '<SYSTEM32>\mpcsvc.exe'
- '%TEMP%\189203.exe'
- '%TEMP%\178500.exe'
- '%TEMP%\179250.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\barseek.dll, load
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\p6hhr.bat" "%TEMP%\179250.exe""
- java.exe
- opera.exe
- %TEMP%\p6hhr.bat
- %TEMP%\189203.exe
- <SYSTEM32>\barseek.dll
- %TEMP%\178500.exe
- %TEMP%\179250.exe
- <SYSTEM32>\mpcsvc.exe
- %TEMP%\179250.exe
- ClassName: '' WindowName: 'Kaspersky Anti-Hacker'
- ClassName: 'JeticoPersonalFirewall' WindowName: ''
- ClassName: '' WindowName: 'UmxTray SysTray notification window'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'FireTray_Hidden_Window' WindowName: 'FireTray_Hidden_Window'
- ClassName: 'ZAFrameWnd' WindowName: 'ZoneAlarm Pro'
- ClassName: '' WindowName: 'Sygate Personal Firewall Pro'
- ClassName: '#32770' WindowName: ''
- ClassName: '' WindowName: 'KerioPersonalFirewallMainWindow'
- ClassName: '' WindowName: 'Look '
- ClassName: 'Symantec NAMApp Class' WindowName: ''
- ClassName: '' WindowName: 'BlackICE PC Protection'