Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Project1' = '%APPDATA%\eiodmo\Project1.exe'
- '%TEMP%\Svchost.exe'
- '%TEMP%\RarSFX0\DTeroV.exe' "eioDMo"
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %APPDATA%\eiodmo\fxyOji.txt
- %APPDATA%\eiodmo\eioDMo
- %TEMP%\Svchost.exe
- %APPDATA%\eiodmo\DTeroV.exe
- %APPDATA%\eiodmo\1.txt
- %APPDATA%\eiodmo\2.txt
- %APPDATA%\eiodmo\skype.exe
- %APPDATA%\eiodmo\Project1.exe
- %TEMP%\RarSFX0\DTeroV.exe
- %TEMP%\RarSFX0\gNjZHC.exe
- %TEMP%\RarSFX0\eioDMo
- %TEMP%\RarSFX0\fxyOji.txt
- %TEMP%\gNjZHC.exe
- %TEMP%\eioDMo
- %TEMP%\fxyOji.txt
- %TEMP%\DTeroV.exe
- %TEMP%\RarSFX0\gNjZHC.exe
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\RarSFX0\DTeroV.exe
- %TEMP%\RarSFX0\eioDMo
- %TEMP%\RarSFX0\fxyOji.txt
- 'ha####w123.ddns.net':6299
- 'ha#######3.chickenkiller.com':6299
- DNS ASK ha####w123.ddns.net
- DNS ASK ha#######3.chickenkiller.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''