Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windovsbar' = '%PROGRAM_FILES%\Windovsbar_\Windovsbar_so513.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windovslight' = '%PROGRAM_FILES%\Internet Explorer\Nv75qj57as8.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windovstask' = '<SYSTEM32>\Jjxsavetube56.exe'
- %PROGRAM_FILES%\Windovsbar_\Casino_update_pro.exe
- %PROGRAM_FILES%\Internet Explorer\Casino_update_pro.exe
- <SYSTEM32>\Casino_update_pro.exe
- <SYSTEM32>\cmd.exe /c $$2028~1.BAT
- %PROGRAM_FILES%\Windovsbar_\Casino_update_pro.exe
- <Текущая директория>\$$202803s.bat
- <SYSTEM32>\Casino_update_pro.exe
- %PROGRAM_FILES%\Internet Explorer\Casino_update_pro.exe
- <Текущая директория>\$$202803s.bat
- '82.##2.33.69':21
- '88.##.103.134':21
- '80.##.112.131':21