Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zoloft' = '%APPDATA%\Roaming\zoloft.exe'
- '%APPDATA%\Roaming\zoloft.exe' /AutoIt3ExecuteScript "%TEMP%\i" "%APPDATA%\Roaming\zoloft.exe"
- '%APPDATA%\Roaming\zoloft.exe'
- '<SYSTEM32>\PING.EXE' -n 0127.0.0.1
- %TEMP%\83.bat
- %APPDATA%\Roaming\zoloft.exe
- %TEMP%\i
- %TEMP%\aut7A0.tmp
- %TEMP%\aut6D4.tmp
- %TEMP%\aut685.tmp
- %TEMP%\autF2C7.tmp
- %TEMP%\j
- %TEMP%\autF1DC.tmp
- %TEMP%\incl2
- %TEMP%\autF336.tmp
- %TEMP%\incl1
- %APPDATA%\Roaming\zoloft.exe
- %TEMP%\aut6D4.tmp
- %TEMP%\aut7A0.tmp
- %TEMP%\i
- %TEMP%\aut685.tmp
- %TEMP%\autF1DC.tmp
- %TEMP%\autF2C7.tmp
- %TEMP%\autF336.tmp
- DNS ASK dn#.##ftncsi.com
- DNS ASK pr####gy.no-ip.biz
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''