Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'surveylock' = 'C:\surveylock\lock.exe'
- '%WINDIR%\explorer.exe'
- %WINDIR%\Explorer.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\0s959H[1]
- C:\surveylock\lock.exe
- C:\surveylock\lock.exe
- 're####lefiles.com':80
- 'localhost':1037
- re####lefiles.com/file/0s959H
- DNS ASK re####lefiles.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'