Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '17bwy4nav' = '%HOMEPATH%\17bwy4nav\60509.vbs'
- %HOMEPATH%\Start Menu\Programs\Startup\start.lnk
- скрытых файлов
- '%HOMEPATH%\17bwy4nav\gYnUacVKmbgM.exe' yNmW.XUA
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- %HOMEPATH%\17bwy4nav\78478.cmd
- %HOMEPATH%\17bwy4nav\NewWinRARZIParchive.zip
- %HOMEPATH%\17bwy4nav\run.vbs
- %HOMEPATH%\17bwy4nav\60509.vbs
- %HOMEPATH%\17bwy4nav\gYnUacVKmbgM.exe
- %HOMEPATH%\17bwy4nav\CGGgGA.KRM
- %HOMEPATH%\17bwy4nav\JwIT.MZZ
- %HOMEPATH%\17bwy4nav\yNmW.XUA
- %HOMEPATH%\17bwy4nav\60509.vbs
- %HOMEPATH%\17bwy4nav\78478.cmd
- %HOMEPATH%\Start Menu\Programs\Startup\start.lnk
- %HOMEPATH%\17bwy4nav\JwIT.MZZ
- %HOMEPATH%\17bwy4nav\CGGgGA.KRM
- %HOMEPATH%\17bwy4nav\gYnUacVKmbgM.exe
- %HOMEPATH%\17bwy4nav\yNmW.XUA
- 'st#####ogic.no-ip.info':1234
- DNS ASK st#####ogic.no-ip.info
- ClassName: '' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'