Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '45D8917979ED703C6CB62FC64D0E155C' = '%WINDIR%\45D8917979ED703C6CB62FC64D0E155C.exe'
- '%WINDIR%\45D8917979ED703C6CB62FC64D0E155C.exe'
- 'C:\45D8917979ED703C6CB62FC64D0E155C.exe'
- 'C:\ЖчАЇSetup.exe'
- '%WINDIR%\45D8917979ED703C6CB62FC64D0E155C.exe' (загружен из сети Интернет)
- %TEMP%\nsf3.tmp\InstallOptions.dll
- %TEMP%\nsf3.tmp\modern-wizard.bmp
- <SYSTEM32>\mswinsck.ocx
- %WINDIR%\45D8917979ED703C6CB62FC64D0E155C.exe
- %WINDIR%\decaptcher.dll
- %TEMP%\nsf3.tmp\ioSpecial.ini
- C:\45D8917979ED703C6CB62FC64D0E155C.exe
- C:\ЖчАЇSetup.exe
- %TEMP%\nsf3.tmp\System.dll
- %TEMP%\nsf3.tmp\FindProcDLL.dll
- %TEMP%\nsf3.tmp\KillProcDLL.dll
- '1.###.66.143':80
- 1.###.66.143/svchost.exe
- 1.###.66.143/decaptcher.dll
- 1.###.66.143/mswinsck.ocx
- ClassName: 'Shell_TrayWnd' WindowName: ''