Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'win32.exe' = '<SYSTEM32>\spool\win32.exe'
- <SYSTEM32>\spool\win32.exe
- %WINDIR%\explorer.exe
- %TEMP%\patcher.exe
- <SYSTEM32>\spool\win32.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\registration.reg
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- 'up##.#ervehttp.com':43567
- DNS ASK up##.#ervehttp.com
- ClassName: 'Shell_TrayWnd' WindowName: ''