Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systral' = '<SYSTEM32>\systral.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'msiddll' = '<SYSTEM32>\msiddll.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '<SYSTEM32>\miceplor.exe'
- <SYSTEM32>\msiddll.exe
- <SYSTEM32>\systral.exe
- <SYSTEM32>\miceplor.exe
- ClassName: 'ComboBox' WindowName: ''
- ClassName: 'Edit' WindowName: ''
- ClassName: 'ComboBoxEx32' WindowName: ''
- ClassName: 'WorkerW' WindowName: ''
- ClassName: 'rebarwindow32' WindowName: ''