Техническая информация
- [<HKLM>\SOFTWARE\Classes\HTTP\shell\open\command] '' = '"%TEMP%\GoogleChrome portatil.exe" -- "%1"'
- '%TEMP%\portatil.exe'
- '%TEMP%\portatil.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\phpmailer.lang-joomla[1].txt
- %TEMP%\portatil.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sfx[1].exe
- 'www.pm###ada.com':80
- '19#.#93.112.253':80
- www.pm###ada.com/libraries/phpmailer/language/phpmailer.lang-joomla.txt
- 19#.#93.112.253/sfx.exe
- DNS ASK www.pm###ada.com