Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '%LOCALAPPDATA%\RuntimeCache\updater.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'userini' = '%LOCALAPPDATA%\RuntimeCache\updater.exe'
- %WINDIR%\explorer.exe
- %LOCALAPPDATA%\runtimecache\updater.exe
- '<DNS_SERVER>':53
- ClassName: 'Progman' WindowName: ''
- ClassName: 'ÏðîâîäГГЁГЄ' WindowName: ''
- ClassName: 'explorer.exe ' WindowName: ''
- ClassName: '' WindowName: 'Ðåäà êòîð ðååñòðà '
- ClassName: '' WindowName: 'Íà ñòðîéêà ñèñòåìû'
- ClassName: '' WindowName: 'Äèñïåò÷åð çà äà ÷ Windows'
- ClassName: '' WindowName: 'Ðà áî÷èé ñòîë'
- ClassName: '' WindowName: 'ГЏГіГ±ГЄ'
- ClassName: '' WindowName: 'ÂûïîëГГЁГІГј'
- '%LOCALAPPDATA%\runtimecache\updater.exe'
- '%WINDIR%\explorer.exe'