Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TFM0N' = 'c:\PTD1Q2ELQ2X7UEDL\Rbnsr.exe'
- 'C:\PTD1Q2ELQ2X7UEDL\Rbnsr.exe'
- 'C:\cache\Install.exe'
- C:\PTD1Q2ELQ2X7UEDL\setting.xml
- C:\1.txt
- C:\cache\Install.exe
- %TEMP%\nsh2.tmp\Banner.dll
- C:\cache\Config.ini
- %TEMP%\nsh2.tmp\Banner.dll
- C:\cache\Install.exe в C:\PTD1Q2ELQ2X7UEDL\Rbnsr.exe
- C:\cache\Config.ini в C:\PTD1Q2ELQ2X7UEDL\Config.ini
- '98.##6.220.101':23456
- '11#.#4.196.132':9963
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''