Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '*WQ9MSFF' = ''
- <SYSTEM32>\rundll32.exe "%HOMEPATH%\Local Settings\dJzNDAaa\AiTrHK--.8jM",HFF8
- <SYSTEM32>\cscript.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\ctfmon.exe
- <SYSTEM32>\rundll32.exe
- %HOMEPATH%\Local Settings\dJzNDAaa\l5krBcljzlclRppn0MBzR2n7zW2.bh3
- <LS_APPDATA>\PUTTY.RND
- %HOMEPATH%\Local Settings\dJzNDAaa\l5krcllzlcllllllllllllllll.bh3
- %HOMEPATH%\Local Settings\dJzNDAaa\l5krBc7676clRppn0MBzjznFR2j.bh3
- %HOMEPATH%\Local Settings\dJzNDAaa\l5krBcljzRclRppn0MBzjjzl0Rp.bh3
- %HOMEPATH%\Local Settings\dJzNDAaa\4ID68fBB.K5z
- %HOMEPATH%\Local Settings\dJzNDAaa\JEdc4iOO.XsU
- %HOMEPATH%\Local Settings\dJzNDAaa\AiTrHK--.8jM
- %HOMEPATH%\Local Settings\dJzNDAaa\SbkLaDCC.T0f
- %HOMEPATH%\Local Settings\dJzNDAaa\WrZ7Vbzz.dYI
- %HOMEPATH%\Local Settings\dJzNDAaa\uyfGkzww.M2A
- 'localhost':22
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''