Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'd' = '%HOMEPATH%\Favorites\rom.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'e' = '%HOMEPATH%\Start Menu\rom.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'c' = '%HOMEPATH%\My Documents\rom.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'a' = '%HOMEPATH%\Desktop\rom.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'b' = '%HOMEPATH%\Start Menu\Programs\rom.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\rom.exe
- %HOMEPATH%\Favorites\rom.exe
- %HOMEPATH%\Start Menu\rom.exe
- %HOMEPATH%\My Documents\rom.exe
- %HOMEPATH%\Desktop\rom.exe
- %HOMEPATH%\Start Menu\Programs\rom.exe
- %HOMEPATH%\Favorites\rom.exe
- %HOMEPATH%\Start Menu\rom.exe
- %HOMEPATH%\My Documents\rom.exe
- %HOMEPATH%\Desktop\rom.exe
- %HOMEPATH%\Start Menu\Programs\rom.exe
- 'cm###.sytes.net':80
- DNS ASK cm###.sytes.net
- ClassName: 'Indicator' WindowName: ''