Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{G7F37W86-E0Y4-NSX8-Y6G2-FPOO7524GYAL}] 'StubPath' = '"%APPDATA%\Install\svchost.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'microsoft' = '%APPDATA%\Install\svchost.exe'
- '%APPDATA%\Install\svchost.exe'
- %APPDATA%\Install\svchost.exe
- %TEMP%\nse4.tmp\melts.dll
- %APPDATA%\Install\.Identifier
- %TEMP%\melts.gea
- %TEMP%\nsj2.tmp\melts.dll
- <Текущая директория>\.Identifier
- %TEMP%\nse4.tmp\melts.dll
- %TEMP%\nsj2.tmp\melts.dll
- '80######sr.is-a-geek.net':8041
- DNS ASK 80######sr.is-a-geek.net
- ClassName: 'Indicator' WindowName: ''