Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'systeamst' = 'C:\Gollme.exe'
- [HKLM\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'Î񵀮ô¶¯Ïî' = 'Wallpaper64'
- C:\5.mp4
- C:\gollme.exe
- C:\5.mp4
- C:\gollme.exe
- 'redir.metaservices.microsoft.com':80
- 'onlinestores.metaservices.microsoft.com':80
- http://redir.metaservices.microsoft.com/redir/allservices/?sv################################################################################
- http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv################################################################################
- http://onlinestores.metaservices.microsoft.com/bing/bing.xml
- DNS ASK redir.metaservices.microsoft.com
- DNS ASK onlinestores.metaservices.microsoft.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'JFWUI2' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- 'C:\gollme.exe'
- '%ProgramFiles(x86)%\windows media player\wmplayer.exe' /Play -Embedding