Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 've.exe' = '%WINDIR%\ve.exe'
- '%TEMP%\ventriloMIX.exe'
- '%TEMP%\ve.exe'
- ClassName: 'TibiaClient' WindowName: '(null)'
- %WINDIR%\ve.exe
- %TEMP%\ve.exe
- %TEMP%\ventriloMIX.exe
- 'zo##an.pl':80
- zo##an.pl/status.php?ip##################
- DNS ASK zo##an.pl
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'InstItClass' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'