Техническая информация
- [HKLM\System\CurrentControlSet\Services\Windows Event Tclam] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Windows Event Tclam] 'ImagePath' = '%ALLUSERSPROFILE%\ARPvUWDHA@12\fKUUsDGDt.exe -nb'
- 'Windows Event Tclam' %ALLUSERSPROFILE%\ARPvUWDHA@12\fKUUsDGDt.exe -nb
- %TEMP%\maldevacad.tmp
- %LOCALAPPDATA%\microsoft\internet explorer\6.d
- %LOCALAPPDATA%\microsoft\internet explorer\7.d
- %ALLUSERSPROFILE%\wmaer\cnima.xml
- %ALLUSERSPROFILE%\cnima.xml
- %ALLUSERSPROFILE%\wmaer\broker.exe
- %ALLUSERSPROFILE%\wmaer\duilib-1.dll
- %ALLUSERSPROFILE%\wmaer\mzlib.dll
- %ALLUSERSPROFILE%\wmaer\zlib.dll
- %ALLUSERSPROFILE%\wmaer\casekqerl.exe
- %ALLUSERSPROFILE%\broker.exe
- %ALLUSERSPROFILE%\duilib-1.dll
- %ALLUSERSPROFILE%\mzlib.dll
- %ALLUSERSPROFILE%\zlib.dll
- %ALLUSERSPROFILE%\arpvuwdha@12\fkuusdgdt.exe
- %ALLUSERSPROFILE%\arpvuwdha@12\duilib-1.dll
- %ALLUSERSPROFILE%\arpvuwdha@12\cnima.xml
- %ALLUSERSPROFILE%\sys.key
- %ALLUSERSPROFILE%\mzlib.dll в %ALLUSERSPROFILE%\arpvuwdha@12\zlib.dll
- '45.##2.243.33':1536
- '38.##.126.91':5538
- http://45.###.243.33:1536/ttkugou/6.d via 45.##2.243.33
- http://45.###.243.33:1536/iii/7.d via 45.##2.243.33
- '38.##.126.91':5538
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- '%ALLUSERSPROFILE%\wmaer\casekqerl.exe'
- '%ALLUSERSPROFILE%\wmaer\casekqerl.exe' (со скрытым окном)