Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RemotePX' = '%APPDATA%\RemotePX\RemotePX Client.exe'
- '%APPDATA%\RemotePX\RemotePX Client.exe'
- '%APPDATA%\RemotePX\RemotePX Client.exe' (загружен из сети Интернет)
- %APPDATA%\RemotePX\Newtonsoft.Json.dll
- %APPDATA%\RemotePX\RemotePX Client.exe.config
- %APPDATA%\RemotePX\RemotePX Client.exe
- %APPDATA%\RemotePX\SocketIOClient.dll
- %APPDATA%\RemotePX\WebSocket4Net.dll
- %APPDATA%\RemotePX\Ionic.Zip.dll
- 'ms#.##motepx.com':80
- 'wp#d':80
- ms#.##motepx.com/temp_inst/Newtonsoft.Json.dll
- ms#.##motepx.com/temp_inst/RemotePX%20Client.exe.config
- ms#.##motepx.com/temp_inst/RemotePX%20Client.exe
- ms#.##motepx.com/temp_inst/Ionic.Zip.dll
- wp#d/wpad.dat
- ms#.##motepx.com/temp_inst/SocketIOClient.dll
- ms#.##motepx.com/temp_inst/WebSocket4Net.dll
- DNS ASK ms#.##motepx.com
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'