Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'f38b4a5s5lo2' = '%HOMEPATH%\f38b4a5s5lo2\53370.vbs'
- '%HOMEPATH%\f38b4a5s5lo2\cTNyfovoY.com' KjmAm
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %HOMEPATH%\f38b4a5s5lo2\pZPnWhbLyzK.AOH
- %HOMEPATH%\f38b4a5s5lo2\11437.cmd
- %HOMEPATH%\f38b4a5s5lo2\53370.vbs
- %HOMEPATH%\f38b4a5s5lo2\oANyt.DXJ
- %HOMEPATH%\f38b4a5s5lo2\cTNyfovoY.com
- %HOMEPATH%\f38b4a5s5lo2\KjmAm
- %HOMEPATH%\f38b4a5s5lo2\pZPnWhbLyzK.AOH
- %HOMEPATH%\f38b4a5s5lo2\53370.vbs
- %HOMEPATH%\f38b4a5s5lo2\11437.cmd
- %HOMEPATH%\f38b4a5s5lo2\oANyt.DXJ
- %HOMEPATH%\f38b4a5s5lo2\cTNyfovoY.com
- %HOMEPATH%\f38b4a5s5lo2\KjmAm
- 'an###king.net':3333
- DNS ASK an###king.net
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'