Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'System' = '%WINDIR%\system\System.exe'
- '%WINDIR%\system\scrss.exe'
- '%WINDIR%\system\System.exe'
- '%TEMP%\Prog.exe'
- %TEMP%\Prog.exe
- %TEMP%\~DF6675.tmp
- %WINDIR%\system\UPDATE.dll
- <Служебный элемент>
- %WINDIR%\system\System.exe
- %WINDIR%\system\scrss.exe
- %WINDIR%\system\UPDATE.dll
- 'wi#########ofostoriginal.letnick.com':80
- http://wi#########ofostoriginal.letnick.com/pic/update.js
- DNS ASK wi#########ofostoriginal.letnick.com
- ClassName: 'Shell_TrayWnd' WindowName: ''