Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'crashreporter' = '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BrokerInfrastructure' = '%APPDATA%\Microsoft\BrokerInfrastructure.exe'
- '%APPDATA%\Mozilla\crashreporter.exe'
- '%APPDATA%\Microsoft\AudioEndpointBuilder.exe'
- '%HOMEPATH%\Desktop\RecoverMyFiles.exe'
- '%APPDATA%\Microsoft\BrokerInfrastructure.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
- %APPDATA%\Mozilla\crashreporter.exe
- \Device\LanmanRedirector\127.0.0.1\pipe\svcctl
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\.Identifier
- %HOMEPATH%\Desktop\RecoverMyFiles.exe
- %APPDATA%\Microsoft\AudioEndpointBuilder.exe
- %APPDATA%\Microsoft\BrokerInfrastructure.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\.Identifier
- %APPDATA%\Microsoft\AudioEndpointBuilder.exe
- %APPDATA%\Mozilla\crashreporter.exe
- '37.##.80.173':36985
- '37.##.80.173':14253
- 'localhost':445
- ClassName: 'TfrmGetDataDebugger' WindowName: 'GetData Debugger'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''