Техническая информация
- [<HKLM>\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command] '' = '"%PROGRAM_FILES%\Opera\Launcher.exe" www.jogostempo.com?oem=unknown&uid=97c09787-6498-4b10-8f65-9471d842c55e_7CA2641D&tm=1426979520'
- [<HKLM>\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] '' = '%PROGRAM_FILES%\Internet Explorer\iexplore.exe www.jogostempo.com?oem=unknown&uid=97c09787-6498-4b10-8f65-9471d842c55e_7CA2641D&tm=1426979520'
- [<HKLM>\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command] '' = '"%PROGRAM_FILES%\Google\Chrome\Application\chrome.exe" www.jogostempo.com?oem=unknown&uid=97c09787-6498-4b10-8f65-9471d842c55e_7CA2641D&tm=1426979520'
- '<SYSTEM32>\RAServer.exe' /offerraupdate
- '<SYSTEM32>\taskhost.exe' SYSTEM
- '<SYSTEM32>\svchost.exe' -k secsvcs
- C:\ProgramData\ntuser.pol
- <SYSTEM32>\GroupPolicy\Machine\Registry.pol
- <SYSTEM32>\GroupPolicy\gpt.ini