Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'navert.exe' = '%PROGRAM_FILES%\Internet Explorer\navert.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'iexpiore.exe' = '%PROGRAM_FILES%\Internet Explorer\iexpiore.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Internet Explorer\navert.exe' = '%PROGRAM_FILES%\Internet Explorer\navert.exe:*:Enabled:navert.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Internet Explorer\iexpiore.exe' = '%PROGRAM_FILES%\Internet Explorer\iexpiore.exe:*:Enabled:iexpiore.exe'
- %PROGRAM_FILES%\Internet Explorer\iexpiore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\iexpiore[1].exe
- %PROGRAM_FILES%\Internet Explorer\lexpiore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\lexpiore[1].exe
- %PROGRAM_FILES%\Internet Explorer\navert.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\navert[1].exe
- %PROGRAM_FILES%\Internet Explorer\systeme.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\systeme[1].dll
- 'gg##ol.com':80
- gg##ol.com/a/iexpiore.exe
- gg##ol.com/a/lexpiore.exe
- gg##ol.com/a/navert.exe
- gg##ol.com/a/systeme.dll
- DNS ASK gg##ol.com
- ClassName: 'Indicator' WindowName: ''