Техническая информация
- '<SYSTEM32>\rundll32.exe'
- <SYSTEM32>\cscript.exe
- %APPDATA%\c734e
- %ALLUSERSPROFILE%\l3fj2h
- %TEMP%\y56f
- %ALLUSERSPROFILE%\16y12
- %TEMP%\oca.hfe
- %ALLUSERSPROFILE%\xis\easll.emi
- %TEMP%\2.tmp
- %TEMP%\1.tmp
- %APPDATA%\c734e
- %ALLUSERSPROFILE%\16y12
- %TEMP%\y56f
- %TEMP%\1.tmp
- %TEMP%\2.tmp
- %ALLUSERSPROFILE%\l3fj2h
- 'tf###avds.in':80
- http://tf###avds.in/luzgas/index.php
- DNS ASK tf###avds.in
- DNS ASK microsoft.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''