Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '.exe' = '"%APPDATA%\.exe"'
- '%APPDATA%\.exe'
- '%TEMP%\tasteimg.jpg.exe'
- '<Текущая директория>\boazinha.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %APPDATA%\Dreams_of_Eternal_Harmony_by_StriderDen.jpg
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 3
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\boazinha.bat""
- '<SYSTEM32>\calc.exe'
- %HOMEPATH%\Recent\Dreams_of_Eternal_Harmony_by_StriderDen.lnk
- %HOMEPATH%\Recent\Application Data.lnk
- %APPDATA%\.exe
- %TEMP%\tasteimg.jpg.exe
- %TEMP%\1.tmp\boazinha.bat
- <Текущая директория>\boazinha.exe
- %APPDATA%\Dreams_of_Eternal_Harmony_by_StriderDen.jpg
- %TEMP%\tasteimg.jpg.exe
- %TEMP%\1.tmp\boazinha.bat
- <Текущая директория>\boazinha.exe
- 'ma#####ytu.no-ip.biz':4431
- DNS ASK ma#####ytu.no-ip.biz
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''