Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'CTS' = '%WINDIR%\CTS.exe'
- <Имя диска съемного носителя>:\calc.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\delegate_execute.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\installer\setup.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\nacl64.exe
- %LOCALAPPDATA%\google\chrome\application\chrome.exe
- %APPDATA%\telegram desktop\telegram.exe
- %APPDATA%\telegram desktop\unins000.exe
- %APPDATA%\telegram desktop\updater.exe
- %HOMEPATH%\desktop\dotnetfx45_full_setup.exe
- %HOMEPATH%\desktop\winmine.exe
- %HOMEPATH%\desktop\wrar520.exe
- %TEMP%\yea07nxib6luxu0.exe
- %WINDIR%\cts.exe
- %TEMP%\jusched.log
- %TEMP%\jds659759.tmp\jds659899.tmp
- %TEMP%\jds659759.tmp\jds659899.tmp в %TEMP%\jds659759.tmp\yea07nxib6luxu0.exe
- 'ja#######d-secure.oracle.com':443
- 'ja#######d-secure.oracle.com':443
- DNS ASK ja#######d-secure.oracle.com
- '%TEMP%\yea07nxib6luxu0.exe'
- '%WINDIR%\cts.exe'
- '%TEMP%\jds659759.tmp\yea07nxib6luxu0.exe'