Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{FEF5C15B-D5C7-B216-47E1-EE3D261F4C32}' = '"%APPDATA%\Nowo\cuav.exe"'
- %APPDATA%\Nowo\cuav.exe
- <SYSTEM32>\ctfmon.exe
- %WINDIR%\Explorer.EXE
- AVGCC32.EXE
- avgcc.exe
- AVGCTRL.EXE
- AVP.EXE
- AVP.COM
- ashAvSrv.exe
- ageofconan.exe
- __cd75efb816b2cc__.exe
- aion.exe
- ashAvast.exe
- ash.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1406' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1406' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1406' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1609' = '00000000'
- %APPDATA%\Bydy\advug.ynz
- %TEMP%\tmp88d6fded.bat
- %APPDATA%\Nowo\cuav.exe
- '91.##6.11.86':443
- ClassName: 'Indicator' WindowName: ''