Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'LauncherMon' = '%ALLUSERSPROFILE%\Application Data\Launcher\ctfmon.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LauncherMon' = '%ALLUSERSPROFILE%\Application Data\Launcher\ctfmon.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\generichost] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\Application Data\Launcher\ctfmon.exe'
- '%ALLUSERSPROFILE%\Application Data\GHost\svchost.exe' service
- '%ALLUSERSPROFILE%\Application Data\GHost\createservice.exe'
- %ALLUSERSPROFILE%\Application Data\GHost\svchost.exe
- %ALLUSERSPROFILE%\Application Data\GHost\createservice.exe
- %ALLUSERSPROFILE%\Application Data\CacheContext.db
- %ALLUSERSPROFILE%\Application Data\GHost\Lib-13.3.12.2.dll
- %ALLUSERSPROFILE%\Application Data\Section.db
- %ALLUSERSPROFILE%\Application Data\Launcher\Lib-13.3.12.2.dll
- %ALLUSERSPROFILE%\Application Data\Launcher\ctfmon.exe
- %ALLUSERSPROFILE%\Application Data\GHost\createservice.exe
- 'ko#######orpkfgrpo.dyndns.org':57845
- 'ko#######orpkfgrpo.dyndns.org':80
- ko#######orpkfgrpo.dyndns.org/gruf2/c.php?s=##############################################################################
- DNS ASK ko#######orpkfgrpo.dyndns.org
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'