Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'FlashPlayer' = '%HOMEPATH%\Documents\Adobe\FlashPlayer.exe'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = '<SYSTEM32>\userinit.exe,%HOMEPATH%\Documents\Adobe\FlashPlayer.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startupx\system.pif
- b.exe
- flashplayer.exe
- %TEMP%\ixp000.tmp\b.exe
- %TEMP%\ixp000.tmp\b.ex_
- %LOCALAPPDATA%\csidl_
- %LOCALAPPDATA%\csidl_x
- %HOMEPATH%\documents\adobe\flashplayer.exe
- %TEMP%\ecopayz_hatasi1.jpg
- %HOMEPATH%\documents\adobe\flashplayer.ex_
- %LOCALAPPDATA%\csidl_
- %LOCALAPPDATA%\csidl_x
- %HOMEPATH%\documents\adobe\flashplayer.ex_
- %TEMP%\ixp000.tmp\b.ex_
- %TEMP%\ixp000.tmp\b.exe
- %LOCALAPPDATA%\csidl_x
- DNS ASK se###m.ddns.net
- ClassName: 'NarratorUIClass' WindowName: ''
- '%TEMP%\ixp000.tmp\b.exe'
- '%HOMEPATH%\documents\adobe\flashplayer.exe'