Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7921FC5CC272327F4D677687DE4C7CB2' = '%WINDIR%\7921FC5CC272327F4D677687DE4C7CB2.exe'
- '%WINDIR%\7921FC5CC272327F4D677687DE4C7CB2.exe'
- 'C:\АМєкServer.LinALLSetupV63.exe'
- 'C:\7921FC5CC272327F4D677687DE4C7CB2.exe'
- '%WINDIR%\7921FC5CC272327F4D677687DE4C7CB2.exe' (загружен из сети Интернет)
- %WINDIR%\decaptcher.dll
- <SYSTEM32>\mswinsck.ocx
- %TEMP%\nsp3.tmp\System.dll
- %WINDIR%\7921FC5CC272327F4D677687DE4C7CB2.exe
- %TEMP%\nsp3.tmp\splash.dll
- C:\АМєкServer.LinALLSetupV63.exe
- C:\7921FC5CC272327F4D677687DE4C7CB2.exe
- %TEMP%\nsp3.tmp\splash.bmp
- %TEMP%\nsp3.tmp\UAC.dll
- '1.###.66.143':80
- 1.###.66.143/svchost.exe
- 1.###.66.143/decaptcher.dll
- 1.###.66.143/mswinsck.ocx
- ClassName: 'Shell_TrayWnd' WindowName: ''