Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'ActiveSyncWatch' = '%ProgramFiles(x86)%\ActiveSyncWatch\pocketwatch.exe auto'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' "http://seostat.org/phonecnt.php?installed=1&mac=76-3C-8C-31-93-33&async=0&user=Microsoft&company=Microsoft&time=1737312454"
- %TEMP%\nsb3a62.tmp
- %ProgramFiles(x86)%\activesyncwatch\pocketwatch.exe
- %ProgramFiles(x86)%\searchtool\searchtool.dll
- %ProgramFiles(x86)%\activesyncwatch\remove.exe
- 'se##tat.org':80
- '34.##9.100.209':443
- DNS ASK se##tat.org
- ClassName: 'POCKETWATCH' WindowName: 'pocketwatch'
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%ProgramFiles(x86)%\activesyncwatch\pocketwatch.exe' register
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' "http://seostat.org/phonecnt.php?installed=1&mac=76-3C-8C-31-93-33&async=0&user=Microsoft&company=Microsoft&time=1737312454" (со скрытым окном)