Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'wemakeppop' = '%ProgramFiles(x86)%\wemakeppop\wemakeppop.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'wemakeppopmds' = '%ProgramFiles(x86)%\wemakeppop\wemakeppopmds.exe'
- %ProgramFiles(x86)%\wemakeppop\cns.dat
- %ProgramFiles(x86)%\wemakeppop\wemakeppop.exe
- %ProgramFiles(x86)%\wemakeppop\wemakeppopmds.exe
- %ProgramFiles(x86)%\wemakeppop\uninst.exe
- %TEMP%\nsj28e4.tmp\selfdelete.dll
- C:\delus.bat
- %TEMP%\nsj28e4.tmp\selfdelete.dll
- DNS ASK we####.adntop.com
- '%ProgramFiles(x86)%\wemakeppop\wemakeppopmds.exe' /S
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat (со скрытым окном)