Техническая информация
- '%TEMP%\iepv.exe' /stext %TEMP%\ie.txt
- '%TEMP%\passwordfox.exe' /stext %TEMP%\firefox.txt
- [<HKCU>\Software\Paltalk]
- [<HKCU>\Software\Microsoft\MSNMessenger]
- [<HKCU>\Software\Microsoft\MessengerService]
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new
- %TEMP%\iepv.exe
- %TEMP%\passwordfox.exe
- %TEMP%\firefox.txt
- %TEMP%\firefox.txt
- %TEMP%\passwordfox.exe
- %TEMP%\iepv.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
- '94.##2.53.144':80
- 'wp#d':80
- 94.##2.53.144//sl/logs.php?&p############################################
- wp#d/wpad.dat
- DNS ASK wp#d