Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'installer32' = '%TEMP%\pk\installer32.exe'
- Библиотека-обработчик для всех процессов: %TEMP%\pk\installer32hk.dll
- Библиотека-обработчик для всех процессов: %TEMP%\pk\installer32hk.dll
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\rarsfx0\pk.bin
- %TEMP%\rarsfx0\inst.dat
- %TEMP%\rarsfx0\installer32hk.dll
- %TEMP%\rarsfx0\installer32.exe
- %TEMP%\rarsfx0\keygen.exe
- %TEMP%\rarsfx0\rinst.exe
- %TEMP%\keygen.exe
- %TEMP%\pk\pk.bin
- %TEMP%\pk\installer32.exe
- %TEMP%\pk\installer32hk.dll
- %TEMP%\pk\inst.dat
- %TEMP%\pk\rinst.exe
- %TEMP%\pk\pk.bin_back
- %TEMP%\rarsfx0\pk.bin
- %TEMP%\rarsfx0\installer32.exe
- %TEMP%\rarsfx0\installer32hk.dll
- %TEMP%\rarsfx0\inst.dat
- %TEMP%\rarsfx0\rinst.exe
- %TEMP%\pk\pk.bin_back
- %TEMP%\pk\rinst.exe в %TEMP%\pk\installer32r.exe
- ClassName: '18467-41' WindowName: ''
- ClassName: '' WindowName: 'PKL Window'
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'
- '%TEMP%\rarsfx0\rinst.exe'
- '%TEMP%\keygen.exe'
- '%TEMP%\pk\installer32.exe'