Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'dtnt462av6' = '%HOMEPATH%\dtnt462av6\78506.vbs'
- '%HOMEPATH%\dtnt462av6\KFURGFydhPl.com' YnszvledCtk
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %HOMEPATH%\dtnt462av6\20141.cmd
- %HOMEPATH%\dtnt462av6\78506.vbs
- %HOMEPATH%\dtnt462av6\run.vbs
- %HOMEPATH%\dtnt462av6\tuXSpfiXAg.ZGS
- %HOMEPATH%\dtnt462av6\IXdnWiX.VGX
- %HOMEPATH%\dtnt462av6\KFURGFydhPl.com
- %HOMEPATH%\dtnt462av6\YnszvledCtk
- %HOMEPATH%\dtnt462av6\tuXSpfiXAg.ZGS
- %HOMEPATH%\dtnt462av6\78506.vbs
- %HOMEPATH%\dtnt462av6\20141.cmd
- %HOMEPATH%\dtnt462av6\IXdnWiX.VGX
- %HOMEPATH%\dtnt462av6\KFURGFydhPl.com
- %HOMEPATH%\dtnt462av6\YnszvledCtk
- 'ty####2.no-ip.org':1604
- DNS ASK ty####2.no-ip.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''