Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'internet' = '%WINDIR%\winlogon.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'PHIME2002ASync' = '<SYSTEM32>\narrat.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IMJPMIG8.1' = '<SYSTEM32>\ipsmvm.exe'
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\AUTOEXEC.BAT
- <SYSTEM32>\AUTOEXEC.BAT
- 'any':52911