Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'csrs.exe' = '%WINDIR%\csrs.exe'
- ClassName: 'TibiaClient', WindowName: ''
- %TEMP%\lsass.exe
- %TEMP%\uosu.exe
- %WINDIR%\plik.exe
- %WINDIR%\algg.exe
- %WINDIR%\csrs.exe
- %WINDIR%\algg1.exe
- '18#.#65.245.114':80
- http://www.ua####eylogger.pl/version.txt
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\uosu.exe'
- '%TEMP%\lsass.exe'
- '%WINDIR%\plik.exe' -pasdasd
- '%WINDIR%\algg.exe'
- '%WINDIR%\algg1.exe'