Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SMΔRT-Protection' = '%PROGRAM_FILES%\Smadav\SMΔRTP.exe rtp'
- '%PROGRAM_FILES%\Smadav\SMΔRTP.exe' rtc
- '%APPDATA%\Smadav\Upd94\Smadav94-Update.exe' slt
- %PROGRAM_FILES%\Smadav\SmadExtc.dll
- %PROGRAM_FILES%\Smadav\Smadav.loov
- %PROGRAM_FILES%\Smadav\SmadEngine.dll
- %ALLUSERSPROFILE%\Desktop\SMADΔV.lnk
- %TEMP%\Smadav.lnk
- %PROGRAM_FILES%\Smadav\Smadav-Updater.exe
- %APPDATA%\Smadav\Upd94\Smadav.loov
- %APPDATA%\Smadav\Upd94\SmadExtc.dll
- %APPDATA%\Smadav\Upd94\SmadEngine.dll
- %PROGRAM_FILES%\Smadav\SMΔRTP.exe
- %APPDATA%\Smadav\Upd94\Smadav-Updater.exe
- %APPDATA%\Smadav\Upd94\Smadav94-Update.exe
- %TEMP%\Smadav.lnk
- 'le##ar.com':80
- le##ar.com/smadstat.php?ma##############################################################################
- DNS ASK le##ar.com
- ClassName: '(null)' WindowName: 'SmaRTP'
- ClassName: 'ThunderRT6TextBox' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'