Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Run' = ''
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\servico[1].pac
- <LS_APPDATA>\%USERNAME%.exe
- 'or#####apontevedra.es':80
- 'au#####ivesound.com.br':80
- 'ze.##salias.com':82
- or#####apontevedra.es/cont/lachita.php
- au#####ivesound.com.br/estoque/servico.pac
- DNS ASK or#####apontevedra.es
- DNS ASK au#####ivesound.com.br
- DNS ASK ze.##salias.com
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'